/risk needs risk:read to view and risk:write to change. Three tabs: Risk Rules, Thresholds, Velocity.
Risk Rules
A rule is a name, description, Category, Severity (Low, Medium, High, Critical), an enabled switch and Conditions (one per line); all conditions must match. Rules that fire appear under Triggered rules in the analyst’s Risk assessment card. The row menu offers Edit Rule, Duplicate and Delete.Write conditions
Conditions use the same namespaces as flows:input.*, subject.*, metadata.*, caseType, vars.*, entity.* and agg.*. For example input.amount > 50000 or subject.transaction.type == "international_transfer".
Thresholds
Risk Level Behaviors decides what happens when a case is classified Low, Medium, High or Critical: Run Workflow, Manual Review (to the Standard or Escalated queue) or Auto-Decline. Save Behaviors applies the change.Velocity metrics
A metric counts or sums transactions over time windows, optionally grouped by a dimension (direction, type, external transaction id, counterparty, PIX key, wallet). Give it a Metric Key, choose Count or Sum (with the amount field and an optional currency filter), add Windows and Group By.Reference agg.* in flows and rules
Each metric is inserted into the case asagg.<key>.<fn>_<window>, where fn is count or sum: for example agg.pix_out_count.count_24h > 10. A grouped metric is a map keyed by the group value instead of a single number.
Not available
Not available today. appears in the interface but does nothing yet. The guides only document controls that work; this note marks the gap so you do not wait on it.