Triage

Alert Queue

High-confidence typology matches flagged by the automated cluster scanner. Triage, confirm or dismiss alerts and drill into match reasoning.

What the Alert Queue delivers

The Alert Queue is your triage workbench. It gathers every high-confidence flag generated by the platform's automated scanners in one place, so you can quickly review, confirm or dismiss each one — with all the reasoning behind every match at your fingertips.

What you get
Automated alert feed

Alerts are generated automatically by the scanners — high-confidence typology matches, composite risk thresholds and outflows to sanctioned counterparties.

Status & severity filters

Slice the queue by triage status (new, reviewing, confirmed, dismissed) and by severity (critical → low) to focus on what matters.

One-click triage

Confirm, mark reviewing or dismiss each alert directly from the row or the detail panel — status updates instantly.

Glass-box reasoning

Open any alert to see the match score, likely threat actor, observed indicators and the engine's reasoning behind the flag.

How to use it — step by step
  1. 1

    Each row is an alert: it shows the cluster/typology, the likely threat actor, the match score (% for typology matches, /100 for risk-score alerts), the severity and the current status.

  2. 2

    Use the Status and Severity dropdowns up top to filter the queue. The count next to them shows how many alerts match.

  3. 3

    Triage quickly from the row: 'Confirm' escalates it, 'Dismiss' clears it. The buttons disable once that status is set.

  4. 4

    Click anywhere on a row to open the full detail panel and dig deeper before deciding.

  5. 5

    In the detail panel, read the match bar, observed indicators and reasoning, then Confirm, Mark Reviewing or Dismiss.

  6. 6

    When an alert is tied to an actor, use 'Open Actor' in the panel to jump straight to that actor's full profile and investigate.

Alerts are generated automatically by the typology and risk scanners — an empty queue just means nothing has passed the threshold yet. Set the status to "new" to see only un-triaged alerts.
10 alerts
Cluster / TypologyMatchSeverityStatusTriage
Ransomware Cash-Out detected on cluster
Ransomware Cash-Out
75%
high
new
Sanctions Evasion Route detected on cluster
Rapid Dispersion Smurfing
82%
critical
confirmed
Rapid Dispersion Smurfing detected on cluster
Mixer Layering
92%
high
confirmed
Mixer Layering detected on cluster
Sanctions Evasion Route
65%
medium
new
Rapid Dispersion Smurfing detected on cluster
Pig-Butchering Funnel
80%
critical
dismissed
Sanctions Evasion Route detected on cluster
Sanctions Evasion Route
87%
high
reviewing
Mixer Layering detected on cluster
Peel Chain Laundering
97%
medium
new
Sanctions Evasion Route detected on cluster
Mixer Layering
94%
critical
reviewing
Darknet Settlement detected on cluster
Darknet Settlement
65%
medium
reviewing
Sanctions Evasion Route detected on cluster
Pig-Butchering Funnel
81%
high
new