0 · Before the client arrives do this first — 3 minutes
Almost everything that goes wrong in a demo goes wrong here. Tick these off.
- Start all three hosts (three terminals, repo root). Workers is not optional: without it alerts never appear and reports/dashboards stall.
dotnet run --project src/Hosts/FlowSentry.Web— the UI (check the console for the URL; typicallyhttps://localhost:7196)dotnet run --project src/Hosts/FlowSentry.Workersdotnet run --project src/Hosts/FlowSentry.Api— only needed if you will show live ingestion- or all at once:
dotnet run --project src/Hosts/FlowSentry.AppHost(Aspire dashboard)
- Seed demo data once (safe to re-run; it skips if already seeded):
dotnet run --project src/Hosts/FlowSentry.Workers -- --seed-e2e - Step-up MFA is switched OFF for this demo (
Mfa__DemoBypassStepUp=trueon the Web host only). Confirming an STR, activating a rule or Run now work without an authenticator code. Check the Web console shows the warning "Step-up MFA BYPASSED" when you use one. To turn MFA back on, restart the Web host without that variable. If a client asks: "MFA and step-up are built and enforced by default; for this demo session step-up is disabled by configuration." - Open the Reporting page once as the MLRO and confirm it loads. If it errors, check Workers is running and the database is reachable.
- Browser: one window, 100% zoom, bookmark
/alerts,/approvals,/reporting,/dashboards. Use a private window per role so you can switch users fast.
1 · What FlowSentry is — the whole system on one page
An AI-native, multi-tenant AML and transaction-monitoring platform for banks, SACCOs, digital lenders, PSPs, fintechs and investment banks. Human accountable, AI accelerated: AI drafts and recommends; people approve anything with regulatory consequence.
📥 Ingestion & data
- REST API (HMAC-signed, idempotent, rate-limited) for transactions, parties, accounts, instruments
- Batch files (CSV / XLSX / JSON / XML) with quarantine + reconciliation
- ISO 20022 (pain.001 / pacs.008 / camt.053), M-Pesa Daraja, FIX drop-copy for securities
- Mapping Studio — map any source layout to the canonical model, no code
- Source health: heartbeats, silent-feed alerts, historical bulk load
📡 Monitoring & rules
- Real-time rule engine; rules are versioned JSON with tenant-tunable parameters
- 32 built-in scenarios: structuring, layering, mule, cash, velocity, fraud and 7 securities scenarios (wash trading, spoofing, order-to-trade…)
- Visual Rule Builder + plain-English authoring (AI draft, auto-backtest)
- Backtest on history: projected alert volume + false-positive estimate before activation
- Maker-checker activation; rule performance & noisy-rule detection; network features (fan-in hubs)
🔎 Screening
- Sanctions / PEP / adverse-media list matching with fuzzy name matching
- Four-eyes dispositions (proposer ≠ confirmer); reason codes, suppression
- Full-book periodic re-screen job; watchlist staleness alerts
🧮 Risk rating & EDD
- Customer risk rating: Customer · Geography · Product · Channel · Behavior — deterministic and reproducible
- Securities factors (instrument + venue risk)
- Enhanced due diligence cases auto-open for high band; EWRA; peer segmentation
🗂️ Cases
- Alert → case workflow, SLA timers with breach alerts, evidence, timeline
- Link analysis graph (Cytoscape) — e.g. a mule fan-in ring
- Customer 360: profile, accounts, history, prior alerts, screening, risk
- STR-linked cases hidden from non-privileged users (tipping-off control)
🤖 Sentry Agent (AI)
- Investigation memo with cited evidence, typology assessment, recommendation, confidence
- Read-only tools; PII pseudonymised before any cloud call; every call logged
- 3-tier model router (cloud reasoning / default / self-hosted for zero-egress); per-feature kill switch
- ML alert scorer (ONNX) with promotion gate and drift monitoring
📄 Regulatory reporting (goAML)
- STR, SAR, CTR — built from the customer/account/transaction records with field-by-field provenance
- 3-layer validation: data completeness → business rules → XSD, errors pinpointed to field + XML line
- XML viewer, watermarked download, hand-off package with checksums
- FIU rejection loop: record response → correct → different MLRO approves → resubmit
- Filing deadlines + overdue tracking; automatic daily CTR; statutory registers; board packs
- Versioned schema packs — a new FRC schema is a content drop, not a rewrite
📊 Analytics & dashboards
- Executive dashboards, pivot analytics (Excel export), Metric Designer with RAG + webhook alerts
- Typology Radar (emerging-pattern detection), period-over-period comparisons
- Securities surveillance dashboard and Regulatory-reporting KPIs (STR-privileged)
📈 Securities module (investment banks)
- Orders, trades, free-of-payment transfers as first-class events; instrument master
- Wash-trade / layering / venue-fragmentation / concentration surveillance
- Instrument & venue risk in the customer rating
🔐 Security & governance
- Default-deny authorisation, role + policy based; separation of duties on every maker-checker pair
- MFA (TOTP, passkeys), step-up for sensitive actions; SSO-ready
- Hash-chained audit trail; DB-level immutability script; every XML view/download logged
- Multi-tenant isolation on every table; no PII in logs
⚙️ Administration & operations
- Tenants, users, reference data (country risk, currencies, reason codes), jurisdiction packs (KE, UG…)
- Ops console: scheduled jobs with run history, Run now / Disable (step-up), platform health
- Webhooks (HMAC-signed, retry + dead-letter), egress APIs with field-level scoping, signed embeds
- Retention with signed deletion certificates; scheduled report distribution
🏛️ Regulator / auditor portal
- Read-only sample review: reproducible sampling, findings recorded, regulated records untouched
- Examiner-ready exports (STR / CTR / declined-business / training registers)
2 · User roles & logins
All demo users share one password. Sign in at /login.
| Who | Login (email) | Role(s) | What they can do — and what they cannot |
|---|---|---|---|
| Alex Analyst | analyst@demo.flowsentry | Analyst + SeniorAnalyst | Works the alert queue, builds cases, Customer 360, link analysis, screening dispositions, rules/backtest, proposes an STR. Cannot approve STRs or see restricted STR data. |
| Maria MLRO | mlro@demo.flowsentry | MLRO step-up off in demo | Release authority: confirm STRs on /approvals, generate/submit/acknowledge reports, record FIU rejections, approve corrections, release CTR batches, STR-restricted views and the Reporting KPIs dashboard. Normally sensitive actions need a fresh second factor; this demo has step-up disabled by configuration. |
| Avery Admin | admin@demo.flowsentry | Administrator step-up off in demo | Everything operational: /admin, tenants, reference data, Ops Console (jobs, health), mapping studio. Configures — does not file reports. |
| Aisha Auditor | auditor@demo.flowsentry | Auditor | Read-only: Audit Trail, Regulator Review (sample reviews). Sees registers, but every action button is disabled. |
| Riley Risk | risk@demo.flowsentry | RiskManager | Risk screens: score customers, EDD queue, risk dashboards. |
3 · The walkthrough ≈ 10 minutes
Eight stops. Each says who to log in as, where to go, what to click, what to say, and what you should see. Timings are a guide; drop stops 6–7 if you are short.
Open with the home dashboard 1 min
- Live KPIs, alert trend, severity mix, top of the work queue.
- Click Dashboards: the widget workspace (typology treemap, severity heatmap).
Work an alert → case 2 min
- Open the structuring alert. Show the score, the rule that fired and why (the aggregate values behind it).
- Open the case: timeline, evidence, SLA clock.
- Show Customer 360 (profile, prior alerts, screening, PEP flag).
- If the Sentry Agent is configured, request a memo: cited evidence + recommendation, marked as a draft.
Link analysis — the money-mule ring 1 min
- Paste the seeded hub id c0570000-0000-0000-0000-0000000000a1 (Acme Traders Ltd) → the fan-in ring appears.
Screening with four-eyes 1 min
- The seeded OFAC match: show the fuzzy-match score and candidate. Propose "true match"; point out that a second person must confirm.
Monitoring: rules, backtest, securities scenarios 1.5 min
- The rule list shows 32 scenarios — scroll to the
SEC-*rules (wash trading, spoofing, order-to-trade…). - Rule Builder: type a plain-English rule or show the visual builder; run a backtest — projected volume and false-positive estimate before anything goes live.
- Activation is maker-checker + step-up.
The regulatory report: STR end to end 2.5 min — the centrepiece
- Open the case with the Proposed STR. Press Check goAML readiness.
- The validation panel shows a verdict and every finding with the field to fix; the Data mapping panel shows what came from the customer/account/transaction records and what is Missing. (The seeded subject has no loaded profile, so expect Blocked — that is the point: errors are identified, not buried.)
- If you have a case that is ready: Confirm (step-up) → report generated →
/reporting→ View XML (error lines highlighted), Download watermarked XML, hand-off package. - Show Filing deadlines (on track / due soon / overdue) and the status actions.
- Describe the FIU rejection loop: record the response → parsed reasons → Correct & resubmit → a different MLRO approves.
Analytics & the new dashboards 1 min
- Analytics: typology radar, period-over-period; Pivot: drag-and-drop + Excel export.
- Securities: the widgets and the empty state — explain it fills from FIX/API/blotter trades.
- Reporting KPIs (MLRO): open / overdue filings, FIU rejection rate, rejection reasons. Empty until reports exist; run job
reporting.status-backfillto include existing ones.
Prove it: audit trail, auditor view, admin & ops 1.5 min
- Auditor: hash-chained audit trail; Regulator Review sample; open
/reporting— every action is disabled. - Admin: Ops Console (scheduled jobs, run history, Run now), Platform Health, reference data, tenants, Mapping Studio (
/ingestion/mapping-studio).
If you have 2 spare minutes: show live ingestion
dotnet run --project tools/TransactionSimulator -- --source <guid> --secret <secret>.
Press 1 / 2 / 3 to fire a structuring / mule fan-in / velocity burst; alerts appear in /alerts within seconds
(and in /monitoring/live-feed). Requires Api + Web + Workers all running. Skip it if you have not set the source up before.
4 · Be honest about… protects your credibility
| Topic | The truth to state |
|---|---|
| FRC / goAML schema | Today's output is a generic goAML-style demo schema, clearly labelled non-conformant. The official FRC schema and code tables come from the client and install as a pack after contract — no rewrite. Structural differences are pinpointed by a compatibility check and scoped as a change. |
| Submission to the FIU | FlowSentry prepares, validates, and tracks. The upload to the FIU portal is a manual step unless the client has an API/SFTP channel (to confirm in discovery). |
| Report types | STR, SAR and CTR are built. EFT / IFT and other transaction reports need the official schema and are not built yet. |
| Securities | Wash trading, spoofing, order-to-trade, concentration, venue fragmentation, FoP and custody pass-through are covered. Insider dealing, front-running and marking-the-close are not (they need announcement and market-close data we don't have). |
| AI | Drafts and recommends only; never files, dispositions, activates rules or edits lists. Needs a model endpoint configured; has a kill switch. |
| MFA / SSO | TOTP and passkeys with step-up are built; SSO (Entra ID / Okta / Google) is on the roadmap — say "ready for", not "live". |
| Demo data | Seeded and synthetic. Risk, securities and filed-report views start empty by design. |
| Performance | Don't quote throughput numbers — the benchmark gates haven't been met on this laptop; they need the reference environment. |
| Support SLAs | Draft only; commercial terms are a business decision. |
5 · Likely questions — short answers
"Can we use our own thresholds?"
Yes. Every threshold is a named, tenant-overridable parameter; you backtest on your own history before activating, with maker-checker.
"What if the FRC changes the schema?"
A new schema version is installed as a pack and mapped to a profile; old reports keep the schema they were filed under. A structural change is a scoped builder change, not a surprise.
"Does the AI see our customer data?"
Names, IDs, phones and accounts are pseudonymised before any external call. A self-hosted tier exists for zero-egress. Every call is logged for examiners.
"How do you stop one person approving their own work?"
Separation-of-duties is enforced in the handlers, not just the screens. Try it: as the MLRO who prepared a correction, attempt to approve it.
"Is our data separate from other clients'?"
Every tenant-owned table carries a tenant id with a query filter, tested for isolation; one shared database, not per-tenant databases.
"How long to go live?"
Indicatively 10–16 weeks from signature, dominated by data loading and tuning — see docs/implementation/implementation-plan-and-support-model.md.
"Investment banks?"
Yes — orders, trades and transfers, FIX drop-copy, instrument master, seven surveillance scenarios, a surveillance dashboard. Be clear about the three typologies not covered.
"Where is the paperwork?"
Admin and analyst guides, API reference, UAT pack, training curricula, goAML runbooks: all under docs/.
If something breaks mid-demo
- No alerts / empty pages after a minute: Workers isn't running — start it.
- "Step-up required" on a sensitive action: go to
/step-up(or/account/mfa), enter the authenticator code, retry within 5 minutes. - A page errors: go back, move to the next stop — every stop stands alone. Say "let me show you that one from a different angle."
- Need a clean slate: drop and recreate the dev database, restart hosts (auto-migrates), re-run the seed.
FlowSentry demo runbook · for the demo tenant only. Contains demo credentials — remove wwwroot/runbook.html and the login-page link before any real deployment.