Skip to main content

Video Guide

The video above demonstrates how to navigate to the Activities tab for an entity, filter by date range, and open the activity detail drawer to review transaction details and triggered rules.

Viewing all activities

To view all recorded activities and transactions for a given entity or alert, select View all activities from the Workflow events tab. This will show you a history of all activities recorded for the entity.
Link to All activities page

Link to all activities page

Screenshot showing all activities view

This view is limited by default to the last 3 months of activities. You can extend this by changing the filters at the top of the table.

Viewing the activity that caused an alert

View the primary activity
From any alert that includes an Activity ID, you can:
  • Select the Activity ID to open the Activities page for the relevant entity.
  • See the selected activity in the Activities table.
  • View the activity details drawer automatically expanded for that activity.
  • Review all activities that occurred in the 30 days before the selected activity.
  • If needed, you can adjust the date range filters on the Activities page to look further back in time, or narrow down to a shorter investigation window.
Activity data and entity dataThe party details shown in the activity details drawer reflect the data that was present at the time the activity was evaluated. If the entity’s profile has been updated since the activity was submitted, the activity record retains the original snapshot.The most relevant contact data point is selected from the entity’s profile using the following logic.For individuals:
  • Address: Residential addresses are preferred, then postal, then any other type. Within each type, the most recently updated address is selected.
  • Email address and phone number: The entry marked as preferred (isPreferred: true) is selected. If no preferred entry exists, the most recently updated entry is selected.
For organizations:
  • Address: Place of Business is preferred, then Registered Office, then any other type. Within each type, the most recently updated address is selected.
  • Email address and phone number: Only registry-provided contact data is used. The most recently updated entry is selected.
This selection determines what is used for the analysis at the time of evaluation.

Associated activities

What is an associated activity?

You may receive routine-based or batch alerts from your provider, where a single routine run often flags a set of activities (for example, a velocity pattern, a cluster of withdrawals) rather than a single transaction. In this case, the latest activity in that set will be flagged as a “Routine” alert, and all activities in that set will be considered “associated activities” to such an alert.

Reviewing associated activities

Alert details drawer with associated activities
In the workflow tab, you may see an alert that might be a routine-based alert. When you select that alert, you will see a link under the Rules triggered section showing the number of activities associated with that alert. Select this link, and you will be redirected to the list of activities associated with this routine alert.
Expanded activity details in side drawer
To find the original alert, open any associated activity and you will see a link to the original alert in the activity detail drawer. This will appear in the All activities table as well if an activity has been associated with another.

Viewing alerts linked to an activity

When you open an activity in the activity details drawer, you can see any alerts that are directly associated with that activity. This is available on both the All activities page and the Associated activities page.

Rules triggered by this activity

Image

Shows the Rules triggered by this activity section, listing all rules this specific activity triggered, grouped by alert type.

This section shows you all the rules triggered by this specific activity, grouped by alert type. These may show up as separate alerts or a single alert in the workflow tab view. This area will be empty if this activity did not trigger any alerts.

Associated alerts involving other activities

Image

Shows the Associated alerts involving other activities section, listing alerts this activity is linked to through a routine alert.

This section shows you alerts this activity is associated with because of a routine alert. This means that this activity is part of a group of activities found from a routine check. Select the alert to view more details and the full list of activities from that routine. This section will be empty if the activity is not associated with other activities from routine alerts.

Classifying an activity

Reviewing an activity may lead you to classify it. In the Portal, you classify an activity by applying one or more Reasons to it from the activity details drawer.
Activity details drawer showing Reasons applied to the activity

Activity details drawer showing Reasons applied to the activity.


Selecting Reasons to classify an activity

Selecting Reasons to classify an activity. The available Reasons are filtered to True Positive outcomes only.

  • Activities take true-positive Reasons only. False positive and In review are alert outcomes and are not applied directly to an activity.
  • An activity can receive Reasons two ways: applied directly here, or cascaded automatically when you resolve an alert that the activity raised. See Resolving alerts.
  • To remove a classification, remove the Reason from the activity. When an activity has all of its true-positive reasons removed, the Portal shows it as Not suspicious.
  • Reasons applied directly to an activity stay on the activity. They do not cascade up to any alert — this is the reverse of resolving an alert, where the alert’s Reasons cascade down to the activity. Reason changes on an activity are captured in the audit trail with the actor, timestamp, and outcome.