FlowSentry — Demo RunbookAML & transaction monitoring · goAML reporting · securities surveillance · for a ~10-minute walkthrough

0 · Before the client arrives do this first — 3 minutes

Almost everything that goes wrong in a demo goes wrong here. Tick these off.

  1. Start all three hosts (three terminals, repo root). Workers is not optional: without it alerts never appear and reports/dashboards stall.
    • dotnet run --project src/Hosts/FlowSentry.Web — the UI (check the console for the URL; typically https://localhost:7196)
    • dotnet run --project src/Hosts/FlowSentry.Workers
    • dotnet run --project src/Hosts/FlowSentry.Api — only needed if you will show live ingestion
    • or all at once: dotnet run --project src/Hosts/FlowSentry.AppHost (Aspire dashboard)
  2. Seed demo data once (safe to re-run; it skips if already seeded): dotnet run --project src/Hosts/FlowSentry.Workers -- --seed-e2e
  3. Step-up MFA is switched OFF for this demo (Mfa__DemoBypassStepUp=true on the Web host only). Confirming an STR, activating a rule or Run now work without an authenticator code. Check the Web console shows the warning "Step-up MFA BYPASSED" when you use one. To turn MFA back on, restart the Web host without that variable. If a client asks: "MFA and step-up are built and enforced by default; for this demo session step-up is disabled by configuration."
  4. Open the Reporting page once as the MLRO and confirm it loads. If it errors, check Workers is running and the database is reachable.
  5. Browser: one window, 100% zoom, bookmark /alerts, /approvals, /reporting, /dashboards. Use a private window per role so you can switch users fast.
The demo database is empty in three places. The seed does not create (a) a risk model — the Risk page is empty until you score a customer, (b) any securities trades — the Securities dashboard shows its empty state, (c) any filed reports — the Reporting registers and the Reporting KPIs dashboard start empty. Plan the story around what is seeded (section 3), and show those three as "here is how it fills".

1 · What FlowSentry is — the whole system on one page

An AI-native, multi-tenant AML and transaction-monitoring platform for banks, SACCOs, digital lenders, PSPs, fintechs and investment banks. Human accountable, AI accelerated: AI drafts and recommends; people approve anything with regulatory consequence.

📥 Ingestion & data

  • REST API (HMAC-signed, idempotent, rate-limited) for transactions, parties, accounts, instruments
  • Batch files (CSV / XLSX / JSON / XML) with quarantine + reconciliation
  • ISO 20022 (pain.001 / pacs.008 / camt.053), M-Pesa Daraja, FIX drop-copy for securities
  • Mapping Studio — map any source layout to the canonical model, no code
  • Source health: heartbeats, silent-feed alerts, historical bulk load

📡 Monitoring & rules

  • Real-time rule engine; rules are versioned JSON with tenant-tunable parameters
  • 32 built-in scenarios: structuring, layering, mule, cash, velocity, fraud and 7 securities scenarios (wash trading, spoofing, order-to-trade…)
  • Visual Rule Builder + plain-English authoring (AI draft, auto-backtest)
  • Backtest on history: projected alert volume + false-positive estimate before activation
  • Maker-checker activation; rule performance & noisy-rule detection; network features (fan-in hubs)

🔎 Screening

  • Sanctions / PEP / adverse-media list matching with fuzzy name matching
  • Four-eyes dispositions (proposer ≠ confirmer); reason codes, suppression
  • Full-book periodic re-screen job; watchlist staleness alerts

🧮 Risk rating & EDD

  • Customer risk rating: Customer · Geography · Product · Channel · Behavior — deterministic and reproducible
  • Securities factors (instrument + venue risk)
  • Enhanced due diligence cases auto-open for high band; EWRA; peer segmentation

🗂️ Cases

  • Alert → case workflow, SLA timers with breach alerts, evidence, timeline
  • Link analysis graph (Cytoscape) — e.g. a mule fan-in ring
  • Customer 360: profile, accounts, history, prior alerts, screening, risk
  • STR-linked cases hidden from non-privileged users (tipping-off control)

🤖 Sentry Agent (AI)

  • Investigation memo with cited evidence, typology assessment, recommendation, confidence
  • Read-only tools; PII pseudonymised before any cloud call; every call logged
  • 3-tier model router (cloud reasoning / default / self-hosted for zero-egress); per-feature kill switch
  • ML alert scorer (ONNX) with promotion gate and drift monitoring

📄 Regulatory reporting (goAML)

  • STR, SAR, CTR — built from the customer/account/transaction records with field-by-field provenance
  • 3-layer validation: data completeness → business rules → XSD, errors pinpointed to field + XML line
  • XML viewer, watermarked download, hand-off package with checksums
  • FIU rejection loop: record response → correct → different MLRO approves → resubmit
  • Filing deadlines + overdue tracking; automatic daily CTR; statutory registers; board packs
  • Versioned schema packs — a new FRC schema is a content drop, not a rewrite

📊 Analytics & dashboards

  • Executive dashboards, pivot analytics (Excel export), Metric Designer with RAG + webhook alerts
  • Typology Radar (emerging-pattern detection), period-over-period comparisons
  • Securities surveillance dashboard and Regulatory-reporting KPIs (STR-privileged)

📈 Securities module (investment banks)

  • Orders, trades, free-of-payment transfers as first-class events; instrument master
  • Wash-trade / layering / venue-fragmentation / concentration surveillance
  • Instrument & venue risk in the customer rating

🔐 Security & governance

  • Default-deny authorisation, role + policy based; separation of duties on every maker-checker pair
  • MFA (TOTP, passkeys), step-up for sensitive actions; SSO-ready
  • Hash-chained audit trail; DB-level immutability script; every XML view/download logged
  • Multi-tenant isolation on every table; no PII in logs

⚙️ Administration & operations

  • Tenants, users, reference data (country risk, currencies, reason codes), jurisdiction packs (KE, UG…)
  • Ops console: scheduled jobs with run history, Run now / Disable (step-up), platform health
  • Webhooks (HMAC-signed, retry + dead-letter), egress APIs with field-level scoping, signed embeds
  • Retention with signed deletion certificates; scheduled report distribution

🏛️ Regulator / auditor portal

  • Read-only sample review: reproducible sampling, findings recorded, regulated records untouched
  • Examiner-ready exports (STR / CTR / declined-business / training registers)

2 · User roles & logins

All demo users share one password. Sign in at /login.

Password for every demo user: Demo!Passw0rd#2026
WhoLogin (email)Role(s)What they can do — and what they cannot
Alex Analystanalyst@demo.flowsentry Analyst + SeniorAnalyst Works the alert queue, builds cases, Customer 360, link analysis, screening dispositions, rules/backtest, proposes an STR. Cannot approve STRs or see restricted STR data.
Maria MLROmlro@demo.flowsentry MLRO step-up off in demo Release authority: confirm STRs on /approvals, generate/submit/acknowledge reports, record FIU rejections, approve corrections, release CTR batches, STR-restricted views and the Reporting KPIs dashboard. Normally sensitive actions need a fresh second factor; this demo has step-up disabled by configuration.
Avery Adminadmin@demo.flowsentry Administrator step-up off in demo Everything operational: /admin, tenants, reference data, Ops Console (jobs, health), mapping studio. Configures — does not file reports.
Aisha Auditorauditor@demo.flowsentry Auditor Read-only: Audit Trail, Regulator Review (sample reviews). Sees registers, but every action button is disabled.
Riley Riskrisk@demo.flowsentry RiskManager Risk screens: score customers, EDD queue, risk dashboards.
The golden rule to say out loud: maker-checker everywhere it matters — the person who prepares something can never be the one who approves it, and the system enforces that, not policy documents.

3 · The walkthrough ≈ 10 minutes

Eight stops. Each says who to log in as, where to go, what to click, what to say, and what you should see. Timings are a guide; drop stops 6–7 if you are short.

Stopwatch: 00:00
1

Open with the home dashboard 1 min

Login: analyst@demo.flowsentry · Go to: / then /dashboards
  • Live KPIs, alert trend, severity mix, top of the work queue.
  • Click Dashboards: the widget workspace (typology treemap, severity heatmap).
"Everything you will see is tenant-isolated and audited. We have 14 days of seeded activity across four typologies."
2

Work an alert → case 2 min

Login: analyst · Go to: /alerts → open one → /customer-360
  • Open the structuring alert. Show the score, the rule that fired and why (the aggregate values behind it).
  • Open the case: timeline, evidence, SLA clock.
  • Show Customer 360 (profile, prior alerts, screening, PEP flag).
  • If the Sentry Agent is configured, request a memo: cited evidence + recommendation, marked as a draft.
"The AI never decides. It drafts a memo with citations; the analyst owns the disposition."
3

Link analysis — the money-mule ring 1 min

Login: analyst · Go to: /cases/link-analysis
  • Paste the seeded hub id c0570000-0000-0000-0000-0000000000a1 (Acme Traders Ltd) → the fan-in ring appears.
"Rules see transactions; the graph shows the network. Same data, different question."
4

Screening with four-eyes 1 min

Login: analyst · Go to: /screening
  • The seeded OFAC match: show the fuzzy-match score and candidate. Propose "true match"; point out that a second person must confirm.
"The proposer cannot confirm their own decision — enforced by the system."
5

Monitoring: rules, backtest, securities scenarios 1.5 min

Login: analyst · Go to: /monitoring → /monitoring/rule-builder → /monitoring/backtest
  • The rule list shows 32 scenarios — scroll to the SEC-* rules (wash trading, spoofing, order-to-trade…).
  • Rule Builder: type a plain-English rule or show the visual builder; run a backtest — projected volume and false-positive estimate before anything goes live.
  • Activation is maker-checker + step-up.
"Thresholds are tenant parameters, never hard-coded. You tune to your own book, with evidence."
6

The regulatory report: STR end to end 2.5 min — the centrepiece

Login: mlro@demo.flowsentry (step-up is off for this demo) · Go to: /approvals → /reporting
  1. Open the case with the Proposed STR. Press Check goAML readiness.
  2. The validation panel shows a verdict and every finding with the field to fix; the Data mapping panel shows what came from the customer/account/transaction records and what is Missing. (The seeded subject has no loaded profile, so expect Blocked — that is the point: errors are identified, not buried.)
  3. If you have a case that is ready: Confirm (step-up) → report generated → /reporting → View XML (error lines highlighted), Download watermarked XML, hand-off package.
  4. Show Filing deadlines (on track / due soon / overdue) and the status actions.
  5. Describe the FIU rejection loop: record the response → parsed reasons → Correct & resubmit → a different MLRO approves.
Say this clearly: output is built on a generic demo schema and is labelled so on screen. The FRC-published schema is installed as a content pack once the client provides it. Filing with the FIU is a manual portal upload unless an API/SFTP channel is confirmed — FlowSentry prepares, validates and tracks it.
"One place builds the report from your records, tells you exactly what is wrong, and proves who approved what."
7

Analytics & the new dashboards 1 min

Login: mlro or analyst · Go to: /analytics, /analytics/pivot, /dashboards/securities, /dashboards/reporting (MLRO only)
  • Analytics: typology radar, period-over-period; Pivot: drag-and-drop + Excel export.
  • Securities: the widgets and the empty state — explain it fills from FIX/API/blotter trades.
  • Reporting KPIs (MLRO): open / overdue filings, FIU rejection rate, rejection reasons. Empty until reports exist; run job reporting.status-backfill to include existing ones.
"Dashboards read a purpose-built analytics store, never the live transaction tables."
8

Prove it: audit trail, auditor view, admin & ops 1.5 min

Login: auditor@demo.flowsentry → /audit, /regulator/reviews; then admin@demo.flowsentry → /admin, /ops/jobs, /ops/health
  • Auditor: hash-chained audit trail; Regulator Review sample; open /reporting — every action is disabled.
  • Admin: Ops Console (scheduled jobs, run history, Run now), Platform Health, reference data, tenants, Mapping Studio (/ingestion/mapping-studio).
"An examiner can reproduce who did what, when — and the Auditor literally cannot change anything."

If you have 2 spare minutes: show live ingestion

Run the simulator against the Api (needs the one-time source setup in the project's CLAUDE.md): dotnet run --project tools/TransactionSimulator -- --source <guid> --secret <secret>. Press 1 / 2 / 3 to fire a structuring / mule fan-in / velocity burst; alerts appear in /alerts within seconds (and in /monitoring/live-feed). Requires Api + Web + Workers all running. Skip it if you have not set the source up before.

4 · Be honest about… protects your credibility

TopicThe truth to state
FRC / goAML schemaToday's output is a generic goAML-style demo schema, clearly labelled non-conformant. The official FRC schema and code tables come from the client and install as a pack after contract — no rewrite. Structural differences are pinpointed by a compatibility check and scoped as a change.
Submission to the FIUFlowSentry prepares, validates, and tracks. The upload to the FIU portal is a manual step unless the client has an API/SFTP channel (to confirm in discovery).
Report typesSTR, SAR and CTR are built. EFT / IFT and other transaction reports need the official schema and are not built yet.
SecuritiesWash trading, spoofing, order-to-trade, concentration, venue fragmentation, FoP and custody pass-through are covered. Insider dealing, front-running and marking-the-close are not (they need announcement and market-close data we don't have).
AIDrafts and recommends only; never files, dispositions, activates rules or edits lists. Needs a model endpoint configured; has a kill switch.
MFA / SSOTOTP and passkeys with step-up are built; SSO (Entra ID / Okta / Google) is on the roadmap — say "ready for", not "live".
Demo dataSeeded and synthetic. Risk, securities and filed-report views start empty by design.
PerformanceDon't quote throughput numbers — the benchmark gates haven't been met on this laptop; they need the reference environment.
Support SLAsDraft only; commercial terms are a business decision.

5 · Likely questions — short answers

"Can we use our own thresholds?"

Yes. Every threshold is a named, tenant-overridable parameter; you backtest on your own history before activating, with maker-checker.

"What if the FRC changes the schema?"

A new schema version is installed as a pack and mapped to a profile; old reports keep the schema they were filed under. A structural change is a scoped builder change, not a surprise.

"Does the AI see our customer data?"

Names, IDs, phones and accounts are pseudonymised before any external call. A self-hosted tier exists for zero-egress. Every call is logged for examiners.

"How do you stop one person approving their own work?"

Separation-of-duties is enforced in the handlers, not just the screens. Try it: as the MLRO who prepared a correction, attempt to approve it.

"Is our data separate from other clients'?"

Every tenant-owned table carries a tenant id with a query filter, tested for isolation; one shared database, not per-tenant databases.

"How long to go live?"

Indicatively 10–16 weeks from signature, dominated by data loading and tuning — see docs/implementation/implementation-plan-and-support-model.md.

"Investment banks?"

Yes — orders, trades and transfers, FIX drop-copy, instrument master, seven surveillance scenarios, a surveillance dashboard. Be clear about the three typologies not covered.

"Where is the paperwork?"

Admin and analyst guides, API reference, UAT pack, training curricula, goAML runbooks: all under docs/.

If something breaks mid-demo

  • No alerts / empty pages after a minute: Workers isn't running — start it.
  • "Step-up required" on a sensitive action: go to /step-up (or /account/mfa), enter the authenticator code, retry within 5 minutes.
  • A page errors: go back, move to the next stop — every stop stands alone. Say "let me show you that one from a different angle."
  • Need a clean slate: drop and recreate the dev database, restart hosts (auto-migrates), re-run the seed.

FlowSentry demo runbook · for the demo tenant only. Contains demo credentials — remove wwwroot/runbook.html and the login-page link before any real deployment.