What decision does this actually settle?
Rutherford Advisory Group is a fictional $285M professional-services firm generating 18,600 card and expense transactions a month. A four-person audit team can inspect about 5% of them after the quarter closes — enough to find a bad receipt, not enough to connect three sub-$1,000 charges made eleven minutes apart. The model doesn't decide that anyone committed fraud. It screens all 18,600, links the transactions that only look separate, and holds the high-confidence ones before the card settles.
From a live feed to a held transaction
Compare the two modes first
Traditional 5% sample (post-quarter, ~45-day lag) versus 100% continuous screening (pre-authorization, human review) — the toggle above the workbench is the whole argument in one control.
Inject the next event
Feeds a new transaction into the stream, scored against policy, timing, merchant, and behavioral context as it arrives.
Filter by status
All / Held / Review / Cleared, or jump straight to the two patterns the case brief walks through: Split purchase and Duplicate.
Open a flagged transaction, e.g. MetroTech Store TXN-88214
Shows the linked events — same amount, same eleven-minute window, or a receipt hash matching one already on file.
Send to reviewer or keep the simulated hold
A hold pauses settlement, it doesn't accuse anyone. Fraud determination and any employee action stay with a person.
What each part of the workbench is for
| Area | What it shows | Where the decision happens |
|---|---|---|
| Mode bar | 5% quarterly sample vs. 100% continuous screening, side by side. | Sets the frame for everything below — this is the case's core argument, not a filter. |
| Feed panel | The live transaction stream with status and pattern filters. | Pick which flagged event to open. |
| Detail panel | The linked transactions behind one flag, with amounts, timestamps, and receipt evidence. | Send to reviewer or keep the hold — nothing here is a fraud finding. |
| Download audit packet | Exports held and reviewed items with their linked evidence. | Hand this to the person who makes the fraud determination. |
Three numbers, in order of usefulness
| Metric | What it means | What to do about it |
|---|---|---|
| Transactions reviewed | 5% under quarterly sampling — the baseline this case exists to change. | Compare it against 100% continuous screening in the mode bar, not against an assumed "good enough" rate. |
| Monthly spend | $2.85M across 620 cardholders and 18,600 transactions. | Use it to size the audit team's actual coverage gap, not just the transaction count. |
| Confidence score | How strongly linked events match a known pattern — split purchase, duplicate receipt, prohibited merchant. | High confidence is a reason to hold before settlement; it is not a verdict. |
Three questions this actually settles
Individually each charge looks ordinary. The model links them by cardholder, amount pattern, and an eleven-minute window — which a quarterly sample would never see together.
The receipt image hash matches even when the filename doesn't — that's what the Duplicate filter is built to catch.
Compare the held-before-settlement flow against the post-quarter, ~45-day-lag baseline in the mode bar — that gap is the actual cost of sampling.
Where this breaks if you push it too far
What goes in, what comes out
| Detail | |
|---|---|
| Input | A pre-loaded illustrative transaction stream for 620 cardholders — no payment system connection. |
| Agent output | Pattern grouping, anomaly score, a temporary-hold recommendation. |
| Stays with a person | Fraud determination, employee action, recovery, card suspension. |