Triage before investigation
Alerts are classified on arrival so obvious clears and genuine concerns get different depth and different SLAs. Uniform treatment is what creates backlogs.
Transaction & Risk Monitoring
RunStaffed alert review, account investigations and back-office risk operations — worked to an SLA, with the reasoning recorded on every disposition.
Typical stack
Written for: A risk or ops lead whose alert queue generates more volume than the team can work, most of it false positives.
Who it is for
Is this built for a business like mine?Every monitoring system is tuned to over-fire, because the alternative is worse. That tuning decision creates an operational problem, and the operational problem is the one we take.
What we see
The monitoring system fires thousands of alerts a month, the overwhelming majority are false positives, and the queue is worked by whoever on the ops team has an afternoon.
What we build
A trained analyst pool working alerts to an SLA, with triage separating the obvious from the genuine and every disposition carrying its reasoning.
The detail that matters
We report which rules generate the most cleared alerts — so your tuning improves instead of the queue just being absorbed.
What we see
Periodic account reviews are scheduled, then postponed, because the people who can do them are doing something more urgent.
What we build
Scheduled review cycles worked to completion by a dedicated pool, with findings escalated on written conditions.
The detail that matters
Scheduled work actually happens when it is somebody’s only job rather than everybody’s second one.
What we see
Chargebacks and fraud flags arrive constantly and are handled reactively, usually after the goods have shipped.
What we build
Order and chargeback review against your rules, with representment packs assembled and filed inside the deadline.
The detail that matters
Chargeback windows are hard deadlines. Missing one is a loss that no amount of evidence recovers.
What we see
Carrier onboarding and ongoing checks are paperwork that someone experienced has to read, and it competes with dispatch.
What we build
Carrier verification and periodic re-checks worked as a standing queue rather than as an interruption.
The detail that matters
Taken off the dispatchers, who are the most expensive people to interrupt.
And who it is not for
We work alerts against your rules and escalate on your conditions. We do not tune your monitoring thresholds, file your regulatory reports, or make the decision to exit a customer — those sit with your compliance function and we will not pretend otherwise.
The problem
Do they understand what is actually going wrong?Monitoring is deliberately tuned to over-fire, so the overwhelming majority of alerts clear. A team that works them all day learns, correctly, that almost nothing is real — and that learned expectation is what makes the one that is real easy to miss. The backlog is not a resourcing failure so much as a predictable consequence of the tuning.
Alert volume exceeds what the team can work, so the oldest are cleared in batches to make the number look better.
Dispositions are recorded as a status with no reasoning, so nobody can audit the decision later.
The same rule generates the same false positive every week and nobody feeds that back into tuning.
Periodic reviews are scheduled and postponed indefinitely because something more urgent always exists.
What we build
What exactly would I be buying?Absorbing the volume is table stakes. The part that compounds is reporting which rules produce cleared alerts, so your tuning improves and next quarter’s queue is smaller — a vendor paid by the alert has no reason to tell you that.
Alerts are classified on arrival so obvious clears and genuine concerns get different depth and different SLAs. Uniform treatment is what creates backlogs.
Every disposition carries what was checked and why it was concluded. A status field with no narrative is unauditable, which means it is worthless later.
What reaches your compliance team is defined in advance. We surface and escalate; the regulatory decision stays with you.
We report which rules generate the most cleared alerts. Your monitoring team gets the evidence to tune, and the queue shrinks.
How it works
How does this actually function?Treating every alert with equal depth is what turns a monitoring system into a backlog. Separation happens on arrival, before anyone is waiting.
Alert
Triage
Investigate
Disposition
Escalate or close
Triage sets depth and SLA on arrival, so a routine clear does not consume the attention a genuine concern needs.
Every disposition records what was checked and why — the narrative is the audit artefact, not the status field.
Escalations go to your compliance function on written conditions. We do not file reports or make exit decisions.
What changes
What is different afterwards?Capacity is matched to alert volume rather than to a headcount someone approved last year, so the queue is worked rather than batch-cleared.
Queue age distribution, and alerts worked within SLA.
Reasoning captured at the point of decision means a review months later is a query rather than an archaeology exercise.
Dispositions carrying a written rationale — all of them.
False positive patterns reported back by rule, so your monitoring team can tune with evidence instead of intuition.
Cleared-alert volume by rule, reported monthly.
How we deliver
How does this start, and what do I get at each step?You can stop after any stage with something useful in hand. That is the point of naming the artefacts rather than the activities.
Alert volume by rule, clear rate, current SLA and where the backlog actually sits. The clear rate per rule is usually the most useful number nobody is looking at.
How alerts are classified on arrival, what depth each class gets, and the SLA per class.
What a sufficient investigation looks like, and the written conditions that send a case to your compliance team.
Your product, your typologies, your customer base. Assessed on historical alerts before touching the live queue.
Our dispositions compared against yours on the same alerts, with disagreements analysed rather than averaged.
Full queue with daily SLA reporting, sampled QA, and a monthly false-positive report by rule.
Who runs the desk
How does this start, and what do I get at each step?A pool of agents with no accountable owner is how outsourced quality degrades — slowly, invisibly, and then all at once. Four roles exist on every account, and the smallest engagement gets all four.
Trained on your product, your tone and your escalation boundaries, and assessed before they touch live work. Named and consistent on dedicated plans.
Accountable for the queue rather than working in it — coverage, SLA, escalations and the shift handover. One person you can name when something goes wrong.
Samples completed work against a written rubric, independently of the lead. Disagreements between agents are treated as a defect in the knowledge base, not in the agent.
Runs the weekly report and the standing review where the knowledge base actually changes. The person who tells you the number went the wrong way.
QA sampling rate and the review cadence are agreed during onboarding and reported weekly against target — including the weeks it was missed.
Questions
But what about the thing that worries me?No. We investigate, document and escalate on the conditions you set; filing decisions and regulatory submissions stay with your compliance function. Any vendor offering to make that call on your behalf is offering you a risk, not a service.
We report the evidence — which rules generate the most cleared alerts, and the patterns behind them — and your monitoring team tunes. We are careful about that line, because we are the party that benefits from a larger queue and should not be the one deciding its size.
It escalates immediately on the written conditions agreed during onboarding, with the investigation documented so your compliance team receives a case rather than a notification.
Set per triage class against the baseline from your queue audit rather than quoted as a universal number. Reported daily, including the cases that missed it — a report that only shows successes is not a report.
Yes, and that is the arrangement we prefer — your case management, your record store, your access controls. The audit trail then lives where your auditor already looks.
The other half
A meaningful share of this queue can be classified before a person sees it — separating the obvious clear from the case that needs an analyst. That is engineering we build, and building it is only honest when the same company works the queue underneath: a threshold set too aggressively costs us the investigation, so our incentive and yours point the same way.
AI AgentsStart
What is the next step?Send us a week of real numbers — calls, chats, tickets, documents — and we will come back with a coverage model and what it would cost.
Related desks