Alerts
Every time a rule matches a transaction, an alert is created. Alerts can also be created manually by analysts or by external providers.Alert sources
| Source | Description |
|---|---|
| Rule | Automatically created when a transaction rule matches |
| Provider | Created by an external AML or blockchain analytics provider |
| Manual | Created manually by an analyst from the console |
Alert statuses
| Status | Description |
|---|---|
OPEN | New alert, not yet reviewed |
INVESTIGATING | An analyst is actively working on this alert |
AWAITING_USER | Additional information is needed from the user |
PENDING_SAR | Under review for a Suspicious Activity Report filing |
SAR_FILED | A Suspicious Activity Report has been filed |
RESOLVED | Investigation complete — no further action needed |
DISMISSED | Alert reviewed and determined to be a false positive |
Cases
A case is an investigation container that links together related alerts and transactions for a structured review workflow.Case workflow
Triage
Review incoming alerts in the Transactions section of the console. Group related alerts into a new case or add them to an existing case.
Assign
Assign the case to an analyst for investigation. Track assignment and response times for SLA monitoring.
Investigate
Analysts review the linked transactions, user verification history, AML screening results, and any attached evidence. Add internal notes and document findings.
Creating a case
Cases are created from the Business Console:- Navigate to Transactions and select one or more flagged transactions
- Click Create Case and provide a title and description
- Set the severity and priority
- Link the relevant alerts and transactions
- Assign to an analyst
Case properties
| Property | Description |
|---|---|
| Title | Short description of the investigation |
| Severity | LOW, MEDIUM, HIGH, CRITICAL |
| Status | OPEN, IN_PROGRESS, RESOLVED, ESCALATED |
| Assigned to | Analyst responsible for the investigation |
| Linked alerts | Alerts included in the case |
| Linked transactions | Transactions associated with the investigation |
| Notes | Internal comments and findings from the investigation |
Transaction notes
Analysts can add notes to individual transactions at any time. Notes include:- The note text
- The analyst who wrote it (name and email)
- Timestamp
- Optional metadata
Analytics
The Transactions overview in the console tracks analyst performance including:- Average alert resolution time
- Alerts resolved per analyst
- Alert-to-case conversion rate
- Open alert backlog by status