Every alert investigated.
Every finding traceable.
Trusted by teams running mission-critical operations.




Prepare the case behind each decision.
Agents handle the research and documentation steps you define, while authorized analysts own the disposition.
Collect the relevant evidence
Gather the alert, account activity, screening records, and earlier reviews required by your checklist.
Surface the open questions
Separate supported findings from missing records and conflicting information that need analyst attention.
Keep the review record
Link source references, queries, and available screenshots to the investigation and reviewer outcome.
An investigation your analyst can inspect.
Follow the evidence across systems
Read the alert, trace the relevant transactions, and compare counterparties with approved screening sources.
Human judgment at the decision point
Prepare the case narrative and unresolved questions. Alert closure, escalation, and filings stay with authorized reviewers.
Alert case ready for analyst review
A-2291 · New corridor and possible name match
Bring alert and screening evidence together.
Connect approved case-management, monitoring, and account-data sources to the investigation procedure. Systems shown are examples; connector availability, API access, and permissions are confirmed during setup.
The investigation workspace
Start from a monitoring alert or case and gather the signals relevant to the analyst’s questions.
The records behind the finding
Check authorized screening results, identity records, account history, and supporting correspondence.
How Runtime works
Configure a bounded research workflow with your compliance team and validate the evidence before expanding it.
Create an investigation agent
Add the alert checklist, evidence requirements, and escalation conditions.
Scope the research
Connect approved case systems, screening sources, and account records.
Build the case file
Gather evidence, document queries, and distinguish findings from unresolved questions.
Review the disposition
An authorized analyst decides, with the evidence and activity record available for inspection.
Controls for sensitive investigations.
Read about our securityRestricted case access
Limit which cases, accounts, and screening sources an agent can read. Apply PII and output restrictions.
Reviewer authority
Keep alert closure, escalation, and external submissions behind your organization’s approval process.
Recorded evidence
Retain tool activity and source references under your policies, with deployment in your VPC or self-hosted environment.
Compliance: common questions
01What part of an alert investigation can an agent do?
02Does the agent make regulatory or filing decisions?
03What happens if screening results are ambiguous?
04What evidence is recorded?
05Can we use our existing monitoring and case-management tools?
06How should we evaluate the first workflow?
Explore more financial operations
See an alert become a reviewable case.
Explore how an agent gathers evidence, documents its research, and prepares the investigation for your analysts.