SENTINEL AI
Airiam Confidential — Internal Use
Embezzlement & Fraud Detection Platform

Sentinel AI

Deterministic controls · Adaptive baselining · Human-in-the-loop

Sentinel watches every financial event, scores it against 18 deterministic rules and each actor's own learned statistical baseline, and never moves money without a human at the irreversibility points. It learns what "normal" is for every employee, vendor and customer — and adjusts when a reviewer tells it so.

18
Deterministic rules
50ms
Synchronous budget
6
Stage agentic loop
0
Auto fraud verdicts
The Architecture

One event, six stages, four agents

Every detection — from a tiny write-off anomaly to a full ghost-vendor scheme — runs the same loop. Four bounded agents own it end to end. Hover a stage.

STAGE 1
Observe
Ingest the event, normalize to canonical schema, persist.
Observer
STAGE 2
Score
Run all applicable rules + baseline deviation, synchronously.
Observer
STAGE 3
Decide
Combine scores into a verdict at the Verdict Gate.
Investigator
STAGE 4
Act
Execute the verdict — or hold the workflow at the host.
Guardian
STAGE 5
Verify
Assemble the evidence package; seal it into the audit chain.
Investigator
STAGE 6
Learn
Capture the human disposition and feed it back into the baseline.
Educator

Observer

The eyes · Observe + Score

Watches everything, scores everything. Never writes alerts, never speaks. Full autonomy — no human in the loop.

Investigator

The brain · Decide + Verify

Composes scores into verdicts and packages evidence. Bounded by the Verdict Gate ceiling on every alert.

Guardian

The muscle · Act

The only agent that touches host systems or can halt money movement. Most legal weight, tightest authority.

Educator

The voice & memory · Verify + Learn

Speaks to the owner under the Graded Language Protocol and records every outcome back into the baseline.

The Verdict Gate

— the hard ceiling on autonomy. Sentinel never executes an irreversible action above AUTO_EXECUTE.
AUTO_EXECUTE

Logs & scores; updates the profile; surfaces in the next briefing. Fully reversible — no action taken.

PROPOSE_&_CONFIRM

Surfaces as a proposal and pauses the workflow. Owner confirms or rejects. Nothing irreversible yet.

REQUIRE_APPROVAL

Holds the workflow; routes to a second actor in the approval chain who approves or denies.

BLOCK

Halts the workflow, opens a case, alerts the owner. Reversible only with explicit human override.

Demonstration 01 · How it detects

The deviation is the explanation

No black box. Sentinel compares a transaction to the actor's own history with one robust statistic. Drag the write-off amount and watch the math, the severity, and the plain-language verdict update live.

Baseline shown is the design-doc worked example: employee E-481, a stable history of $50–$300 discretionary write-offs. Try sliding to $847.

sentinel · observer · deviation engine
Employee E-481metric · discretionary_writeoff_amount
$180
median
$310
p95
$95
MAD
142
obs
$40$620$1,200
deviation methodMODIFIED_Z (Iglewicz–Hoaglin)
modified Z = 0.6745·(x−median)/MAD4.7
percentile rank0.998
ratio vs median4.7×
gate · |modZ|≥3.5 & p≥0.95 → WARNINGMET
gate · |modZ|≥5.0 & p≥0.99 → HIGH—
WARNING
PROPOSE & CONFIRM
Graded language band · OBSERVATION
This alert identifies unusual activity requiring human review. No fraud determination has been made.
Demonstration 02 · How it learns

You are the human reviewer

Sentinel keeps two baselines. The LEARNING baseline drives detection and only absorbs events a human has cleared. The SHADOW baseline absorbs everything — its job is to reveal drift the alerts are holding back. This is the defense against a fraudster slowly normalising their own behaviour.

Feed E-481 events. Normal ones are absorbed automatically. A flagged one is quarantined and waits for your call — clear it as normal and watch Sentinel learn, or confirm fraud and watch it refuse to.

sentinel · educator · baseline quarantine & replay-on-release
Learning baseline · median$180
Shadow baseline · median$180
divergence · $0 — baselines aligned
Learning medianShadow medianEvent

Mechanism shown: HIGH/CRITICAL alerts are held from the LEARNING baseline (QUARANTINE_HELD) until a case is dispositioned. RESOLVED_LEGITIMATE → replay-on-release inserts the event into the learning baseline in canonical order. RESOLVED_FRAUD_CONFIRMED → LEARNING_EXCLUSION, permanently kept out. The SHADOW baseline takes every event regardless, so the gap between the two surfaces systematic drift.

The Rule Registry

The 18 deterministic rules

Tier 1. Every rule runs synchronously on every event inside a 50 ms budget, is replay-testable, and is never subject to warm-up suppression — they fire from Day 1. Click any rule.

Composite Patterns

Real schemes fire several rules in sequence. The orchestrator recognises these and escalates.

Ghost Vendor
DET-006 + DET-017 + DET-003

An actor creates & self-approves a fake vendor whose address matches their own, then changes its banking. Two+ firing within 30 days → CRITICAL.

BEC Payment Redirect
DET-003 + DET-014

A banking-change at the vendor plus a payment landing on the wrong destination. Both on one chain → CRITICAL + SMS.

Lapping
DET-002 + DET-001 + Tier-2

Same-actor SoD violations on each roll-forward plus the lapping detector. 3+ within 90 days → auto UNDER_REVIEW.