> ## Documentation Index
> Fetch the complete documentation index at: https://docs.frayme.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Risk Management

> Rules that fire on every case, what happens at each risk level, and velocity metrics for workflows and rules.

export const props_0 = undefined

export const Shot = ({id, alt, caption}) => <Frame caption={caption}>
    <img className="block dark:hidden rounded-lg" src={`/images/guides/${id}.light.png`} alt={alt} loading="lazy" decoding="async" />
    <img className="hidden dark:block rounded-lg" src={`/images/guides/${id}.dark.png`} alt={alt} loading="lazy" decoding="async" />
  </Frame>;

**Risk Management** at [`/risk`](https://console.us.frayme.io/risk) needs `risk:read` to view and `risk:write` to change. Three tabs: **Risk Rules**, **Thresholds**, **Velocity**.

<Shot id="engineer/risk-01-rules" alt="Risk Rules tab" caption="Rules with severity and category." />

## Risk Rules

A rule is a name, description, **Category**, **Severity** (**Low**, **Medium**, **High**, **Critical**), an enabled switch and **Conditions (one per line)**; all conditions must match. Rules that fire appear under **Triggered rules** in the analyst's Risk assessment card. The row menu offers **Edit Rule**, **Duplicate** and **Delete**.

<Shot id="engineer/risk-02-create-rule" alt="Create New Rule dialog" caption="Conditions use the workflow namespaces." />

<Shot id="engineer/risk-03-rule-menu" alt="Rule menu" caption="Edit, duplicate, delete." />

## Write conditions

Conditions use the same namespaces as flows: `input.*`, `subject.*`, `metadata.*`, `caseType`, `vars.*`, `entity.*` and `agg.*`. For example `input.amount > 50000` or `subject.transaction.type == "international_transfer"`.

## Thresholds

**Risk Level Behaviors** decides what happens when a case is classified **Low**, **Medium**, **High** or **Critical**: **Run Workflow**, **Manual Review** (to the **Standard** or **Escalated** queue) or **Auto-Decline**. **Save Behaviors** applies the change.

<Shot id="engineer/risk-04-thresholds" alt="Thresholds tab" caption="Behaviour per risk level." />

## Velocity metrics

A metric counts or sums transactions over time windows, optionally grouped by a dimension (direction, type, external transaction id, counterparty, PIX key, wallet). Give it a **Metric Key**, choose **Count** or **Sum** (with the amount field and an optional currency filter), add **Windows** and **Group By**.

<Shot id="engineer/risk-05-velocity" alt="Velocity tab" caption="Metrics and their windows." />

<Shot id="engineer/risk-06-velocity-create" alt="Create New Velocity Metric dialog" caption="The preview shows what a case will carry." />

## Reference agg.\* in flows and rules

Each metric is inserted into the case as `agg.<key>.<fn>_<window>`, where `fn` is `count` or `sum`: for example `agg.pix_out_count.count_24h > 10`. A grouped metric is a map keyed by the group value instead of a single number.

## Not available

<Note>
  **Not available today.** {props_0.what} appears in the interface but does nothing yet. The guides only document controls that work; this note marks the gap so you do not wait on it.
</Note>

There are no allow or block lists in Frayme; use tags, rules and workflow logic instead.
