Runtime as featured inForbesRead the article

Runtime and Sift

Runtime vs Sift: Sift scores fraud and decides in real time. Runtime agents work the review queue Sift creates, investigating across ledger, processor, and tickets, then write the decision back.

Updated October 7, 20265 min read

TL;DR: Sift and Runtime do different jobs. Sift scores events and automates fraud decisions using its global data network. Runtime agents investigate the cases Sift sends to manual review, across your ledger, processor, and tickets, and write the decision back to Sift with a person approving.

Feature
RuntimeRuntime
SiftSift
Core jobInvestigate and act on casesScore and decide on events
Fraud scoringUses your Sift scoreReal-time ML risk scores
Network dataYour systems and shared org memory1 trillion+ events a year
Rules and automated decisionsApprovals before money movesDecisioning engine and workflows
Manual reviewAgents draft decisions with evidenceConsole, queues, ActivityIQ summaries
Data it readsLedger, processor, bank files, tickets, SiftEvents you send to Sift
Teams coveredRisk, payment ops, finance, support, moreFraud and trust and safety
Where it runsYour cloud, or self-hostedSift-hosted
PricingFree, Teams from $99/seat/monthNot published

Sift and Runtime get compared because both use AI on fraud. They do different jobs, and a team running Sift does not need to replace it to use Runtime. Sift decides whether an event is risky. Runtime agents do the investigation and follow-up that a person would otherwise do after Sift flags it.

What each does

Sift is a fraud decisioning platform. Its products are Payment Protection and Account Defense, with the Sift Score API for teams that bring Sift's signals into their own models. Sift scores events in real time using a network it says processes more than 1 trillion events a year, and its decisioning engine lets teams set thresholds, workflows, and friction. Cases that need judgment go to analysts in the Sift Console, where ActivityIQ summarizes user activity and the newer Attack Detection Agent groups attacks into investigations. Sift lists fintech customers such as Remitly and CoinJar.

Runtime is the AI agent harness for payment and fintech teams. Anyone on risk, payment ops, finance, compliance, or support builds agents from their SOPs. Agents work on their own isolated computers in your cloud and reach your tools through APIs, databases, CLIs, MCP servers, and a browser for portals with no API. They start read-only, stop for approval before anything moves money, and record every run end to end.

Where they overlap

Be honest about the overlap: both help a fraud team spend less time on manual review.

  • Sift reduces how many cases need review. Better scores and rules mean more events are accepted or blocked automatically.
  • Sift helps analysts review faster. ActivityIQ summaries and attack grouping speed up work inside the console.
  • Runtime does the review work itself. An agent gathers the evidence, applies your SOP, and drafts the decision.

If every case can be decided from what Sift already sees, Sift's own tools may be enough. The gap opens when the answer sits in systems Sift never receives: the ledger, the processor, bank files, the support history, or a sponsor bank's request.

How they work together

A typical flow for a payment or account case that Sift sends to review:

  1. Sift scores the event. Low-risk events pass, high-risk events are blocked, and the rest go to a review queue.
  2. A Runtime agent picks up the case. A Sift webhook or the queue itself triggers the agent, which pulls the user, the score, and the event history from Sift.
  3. The agent investigates outside Sift. It checks the transaction in the processor, the balance and prior entries in the ledger, open support tickets, past chargebacks, and anything the company already learned about similar cases.
  4. It drafts a decision with evidence. Accept, block, or hold, with the reasoning and the data behind it, written the way your SOP asks.
  5. A person approves in Slack or Teams. Anything that moves money, such as releasing a held payout or applying a reserve, waits for sign-off.
  6. The agent writes back. It applies the decision in Sift through the Decisions API, updates the ticket, and notifies the team that needs to know.
  7. The full record is kept. The trigger, every query and tool call, the approval, the cost, and the result are stored and exportable for your sponsor bank or an auditor.

The same case often touches more than fraud. If the blocked payment was a customer's payout, support has a ticket and finance has a break. On Runtime that is one investigation with one record, not three separate ones.

What changes for the fraud team

  • Sift stays the source of truth for risk. Scores, rules, and decisions still live in Sift. The agent reads them and writes back to them.
  • Analysts review drafts, not raw cases. Each case arrives with the evidence already gathered from systems Sift does not see, and the analyst approves, edits, or rejects.
  • Your SOP sets the rules. The agent follows your written procedure, starts read-only, and only takes the actions you allow. Once a pattern is solved, it can become a deterministic script that lives in your repo.
  • The memory compounds. Every resolved case, including the false positives, becomes context the next agent run can use, for fraud and for the other teams on Runtime.

When you need both

  • Your Sift review queue keeps growing and you are about to hire more analysts
  • Reviewers routinely leave the Sift Console to check the ledger, processor, or help desk
  • Fraud cases spill into support, payment ops, or finance work
  • You need approvals and a full run record before any payout is released or reserve applied
  • Case data has to stay in your cloud, with your choice of models

When Sift alone is enough

  • Most decisions are automated by Sift's scores and rules
  • Manual review volume is small and stable
  • Reviewers can decide a case from what Sift already sees
  • Fraud is the only team you want to change right now

Put an agent on your Sift review queue

Bring one SOP. A forward-deployed AI engineer builds the first agent with your team, inside your cloud.

Frequently asked questions

Is Runtime an alternative to Sift?

No. Sift scores events for fraud risk and automates decisions using data from its global network. Runtime does not score fraud. Runtime agents work the cases Sift routes to manual review and the follow-up work across other teams.

How does Runtime connect to Sift?

Through Sift's APIs. Sift can notify your systems of decisions with webhooks, and decisions can be applied to users and orders through its Decisions API, so a Runtime agent can pick up a case, investigate it, and write the approved decision back.

Does Sift have AI agents?

Sift has added AI to its console, including ActivityIQ, which summarizes user activity for investigators, and the Attack Detection Agent, the first part of its Fraud Attack Defense Suite, which detects and groups fraud attacks into investigations.

When is Sift alone enough?

When most decisions are automated by Sift's scores and rules, manual review volume is manageable, and reviewers rarely need data outside Sift's console to decide a case.

Is Sift pricing public?

No. Sift does not publish pricing; it is sold through sales. Runtime publishes its tiers: Free for one session, Teams from $99 per seat per month, and custom Enterprise pricing.

Related comparisons