Skip to main content
Risk Management at /risk needs risk:read to view and risk:write to change. Three tabs: Risk Rules, Thresholds, Velocity.

Risk Rules

A rule is a name, description, Category, Severity (Low, Medium, High, Critical), an enabled switch and Conditions (one per line); all conditions must match. Rules that fire appear under Triggered rules in the analyst’s Risk assessment card. The row menu offers Edit Rule, Duplicate and Delete.

Write conditions

Conditions use the same namespaces as flows: input.*, subject.*, metadata.*, caseType, vars.*, entity.* and agg.*. For example input.amount > 50000 or subject.transaction.type == "international_transfer".

Thresholds

Risk Level Behaviors decides what happens when a case is classified Low, Medium, High or Critical: Run Workflow, Manual Review (to the Standard or Escalated queue) or Auto-Decline. Save Behaviors applies the change.

Velocity metrics

A metric counts or sums transactions over time windows, optionally grouped by a dimension (direction, type, external transaction id, counterparty, PIX key, wallet). Give it a Metric Key, choose Count or Sum (with the amount field and an optional currency filter), add Windows and Group By.

Reference agg.* in flows and rules

Each metric is inserted into the case as agg.<key>.<fn>_<window>, where fn is count or sum: for example agg.pix_out_count.count_24h > 10. A grouped metric is a map keyed by the group value instead of a single number.

Not available

Not available today. appears in the interface but does nothing yet. The guides only document controls that work; this note marks the gap so you do not wait on it.
There are no allow or block lists in Frayme; use tags, rules and workflow logic instead.