Skip to content
UVS

Transaction & Risk Monitoring

Run

An alert nobody worked is worse than no alert at all.

Staffed alert review, account investigations and back-office risk operations — worked to an SLA, with the reasoning recorded on every disposition.

Typical stack

  • Unit21
  • Sardine
  • Hawk
  • PostgreSQL
  • Claude
  • Looker Studio
  • Jira

Written for: A risk or ops lead whose alert queue generates more volume than the team can work, most of it false positives.

Who it is for

Is this built for a business like mine?

Built for businesses whose monitoring generates more alerts than people.

Every monitoring system is tuned to over-fire, because the alternative is worse. That tuning decision creates an operational problem, and the operational problem is the one we take.

What we see

The monitoring system fires thousands of alerts a month, the overwhelming majority are false positives, and the queue is worked by whoever on the ops team has an afternoon.

What we build

A trained analyst pool working alerts to an SLA, with triage separating the obvious from the genuine and every disposition carrying its reasoning.

The detail that matters

We report which rules generate the most cleared alerts — so your tuning improves instead of the queue just being absorbed.

What we see

Periodic account reviews are scheduled, then postponed, because the people who can do them are doing something more urgent.

What we build

Scheduled review cycles worked to completion by a dedicated pool, with findings escalated on written conditions.

The detail that matters

Scheduled work actually happens when it is somebody’s only job rather than everybody’s second one.

What we see

Chargebacks and fraud flags arrive constantly and are handled reactively, usually after the goods have shipped.

What we build

Order and chargeback review against your rules, with representment packs assembled and filed inside the deadline.

The detail that matters

Chargeback windows are hard deadlines. Missing one is a loss that no amount of evidence recovers.

What we see

Carrier onboarding and ongoing checks are paperwork that someone experienced has to read, and it competes with dispatch.

What we build

Carrier verification and periodic re-checks worked as a standing queue rather than as an interruption.

The detail that matters

Taken off the dispatchers, who are the most expensive people to interrupt.

And who it is not for

We work alerts against your rules and escalate on your conditions. We do not tune your monitoring thresholds, file your regulatory reports, or make the decision to exit a customer — those sit with your compliance function and we will not pretend otherwise.

The problem

Do they understand what is actually going wrong?

The queue is mostly noise, and that is exactly why it gets neglected.

Monitoring is deliberately tuned to over-fire, so the overwhelming majority of alerts clear. A team that works them all day learns, correctly, that almost nothing is real — and that learned expectation is what makes the one that is real easy to miss. The backlog is not a resourcing failure so much as a predictable consequence of the tuning.

  • Alert volume exceeds what the team can work, so the oldest are cleared in batches to make the number look better.

  • Dispositions are recorded as a status with no reasoning, so nobody can audit the decision later.

  • The same rule generates the same false positive every week and nobody feeds that back into tuning.

  • Periodic reviews are scheduled and postponed indefinitely because something more urgent always exists.

What we build

What exactly would I be buying?

Work every alert, and make the queue smaller over time.

Absorbing the volume is table stakes. The part that compounds is reporting which rules produce cleared alerts, so your tuning improves and next quarter’s queue is smaller — a vendor paid by the alert has no reason to tell you that.

Triage before investigation

Alerts are classified on arrival so obvious clears and genuine concerns get different depth and different SLAs. Uniform treatment is what creates backlogs.

Reasoning, not a status code

Every disposition carries what was checked and why it was concluded. A status field with no narrative is unauditable, which means it is worthless later.

Escalation on written conditions

What reaches your compliance team is defined in advance. We surface and escalate; the regulatory decision stays with you.

Feedback into tuning

We report which rules generate the most cleared alerts. Your monitoring team gets the evidence to tune, and the queue shrinks.

How it works

How does this actually function?

Triage first, or the queue wins.

Treating every alert with equal depth is what turns a monitoring system into a backlog. Separation happens on arrival, before anyone is waiting.

  1. Alert

  2. Triage

  3. Investigate

  4. Disposition

    → your compliance team
  5. Escalate or close

Triage sets depth and SLA on arrival, so a routine clear does not consume the attention a genuine concern needs.

Every disposition records what was checked and why — the narrative is the audit artefact, not the status field.

Escalations go to your compliance function on written conditions. We do not file reports or make exit decisions.

What changes

What is different afterwards?

What is different afterwards.

The backlog stops being structural

Capacity is matched to alert volume rather than to a headcount someone approved last year, so the queue is worked rather than batch-cleared.

Queue age distribution, and alerts worked within SLA.

Dispositions become auditable

Reasoning captured at the point of decision means a review months later is a query rather than an archaeology exercise.

Dispositions carrying a written rationale — all of them.

The queue gets smaller

False positive patterns reported back by rule, so your monitoring team can tune with evidence instead of intuition.

Cleared-alert volume by rule, reported monthly.

How we deliver

How does this start, and what do I get at each step?

Six stages, and every one has an exit.

You can stop after any stage with something useful in hand. That is the point of naming the artefacts rather than the activities.

  1. 01

    Queue audit

    Alert volume by rule, clear rate, current SLA and where the backlog actually sits. The clear rate per rule is usually the most useful number nobody is looking at.

    • Volume and clear rate by rule
    • Backlog age profile
    • Current disposition quality assessed
  2. 02

    Triage design

    How alerts are classified on arrival, what depth each class gets, and the SLA per class.

    • Triage classification
    • Investigation depth per class
    • SLA per class
  3. 03

    Standard and escalation

    What a sufficient investigation looks like, and the written conditions that send a case to your compliance team.

    • Investigation standard, versioned
    • Escalation conditions agreed with your compliance function
    • Disposition template
  4. 04

    Analyst training

    Your product, your typologies, your customer base. Assessed on historical alerts before touching the live queue.

    • Trained analyst pool
    • Assessment against historical dispositions
    • QA rubric
  5. 05

    Parallel run

    Our dispositions compared against yours on the same alerts, with disagreements analysed rather than averaged.

    • Agreement rate
    • Disagreements analysed by cause
    • Standard corrected where ambiguous
  6. 06

    Run

    Full queue with daily SLA reporting, sampled QA, and a monthly false-positive report by rule.

    • Daily SLA report
    • Weekly QA sampling
    • Monthly tuning report by rule

Who runs the desk

How does this start, and what do I get at each step?

Every desk ships with a lead and a QA function.

A pool of agents with no accountable owner is how outsourced quality degrades — slowly, invisibly, and then all at once. Four roles exist on every account, and the smallest engagement gets all four.

  • 01

    Agents

    Trained on your product, your tone and your escalation boundaries, and assessed before they touch live work. Named and consistent on dedicated plans.

  • 02

    Team Lead

    Accountable for the queue rather than working in it — coverage, SLA, escalations and the shift handover. One person you can name when something goes wrong.

  • 03

    QA

    Samples completed work against a written rubric, independently of the lead. Disagreements between agents are treated as a defect in the knowledge base, not in the agent.

  • 04

    Account lead

    Runs the weekly report and the standing review where the knowledge base actually changes. The person who tells you the number went the wrong way.

QA sampling rate and the review cadence are agreed during onboarding and reported weekly against target — including the weeks it was missed.

Questions

But what about the thing that worries me?

The questions people actually ask.

Do you file regulatory reports for us?

No. We investigate, document and escalate on the conditions you set; filing decisions and regulatory submissions stay with your compliance function. Any vendor offering to make that call on your behalf is offering you a risk, not a service.

Will you tune our monitoring rules?

We report the evidence — which rules generate the most cleared alerts, and the patterns behind them — and your monitoring team tunes. We are careful about that line, because we are the party that benefits from a larger queue and should not be the one deciding its size.

How do you handle a genuine hit?

It escalates immediately on the written conditions agreed during onboarding, with the investigation documented so your compliance team receives a case rather than a notification.

What SLA can we expect?

Set per triage class against the baseline from your queue audit rather than quoted as a universal number. Reported daily, including the cases that missed it — a report that only shows successes is not a report.

Can analysts work inside our systems?

Yes, and that is the arrangement we prefer — your case management, your record store, your access controls. The audit trail then lives where your auditor already looks.

The other half

Triage is a classification problem before it is a staffing one.

A meaningful share of this queue can be classified before a person sees it — separating the obvious clear from the case that needs an analyst. That is engineering we build, and building it is only honest when the same company works the queue underneath: a threshold set too aggressively costs us the investigation, so our incentive and yours point the same way.

AI Agents