{
  "model": "grayson-1",
  "context": {
    "review": {
      "as_of": "2026-10-08T13:06:00Z",
      "trigger": "Payment approved to vendor bank details changed in the last 30 days"
    },
    "customer": {
      "name": "Alderwick Veterinary Partners",
      "business": "Three veterinary clinics",
      "customer_since": "2023-02-14",
      "payment_controls": "Dual approval over $10,000. A user who changes a vendor's bank details must attest that they called the vendor to confirm.",
      "users": [
        {
          "name": "Ben Carter",
          "role": "AP specialist; edits vendors and creates payments",
          "usual_access": "Windows laptop on the Denver, CO office network"
        },
        {
          "name": "Rachel Moss",
          "role": "Controller; approves payments over $10,000",
          "usual_access": "MacBook on the Denver, CO office or home network"
        }
      ]
    },
    "vendor": {
      "name": "Bellhaven Veterinary Supply Co.",
      "vendor_since": "2023-03-01",
      "payments_to_date": 31,
      "typical_payments": "Monthly orders of $9,800 to $22,400; larger quarterly stock orders",
      "largest_prior_payment_usd": 41200,
      "contact_on_file": {
        "email": "billing@bellhavenvetsupply.example.com",
        "phone": "+1-303-555-0147",
        "on_file_since": "2023-03-01"
      },
      "bank_before_change": {
        "bank": "First Wolden Bank",
        "account": "Business checking x4410",
        "verified": "2023-03-02, by call-back to the phone on file",
        "payments_received": 31
      },
      "earlier_bank_changes": 0,
      "other_platform_customers_paying_vendor": "6; all still pay First Wolden Bank x4410 and none has submitted a bank change for this vendor"
    },
    "invoice": {
      "number": "INV-20931",
      "received": "2026-09-30T15:05:00Z",
      "from": "billing@bellhavenvetsupply.example.com",
      "description": "Quarterly stock order",
      "amount_usd": 46850,
      "due": "2026-10-09"
    },
    "bank_change_request": {
      "received": "2026-10-02T16:48:00Z",
      "channel": "Email to the customer's AP inbox, in the INV-20931 thread; uploaded to the platform by Ben Carter",
      "from": "billing@bellhavenvetsupply.example.com",
      "reply_to": "billing@bellhavenvetsupply.example.com",
      "email_authentication": "SPF and DKIM pass for bellhavenvetsupply.example.com",
      "text": "Hi Ben, due to an internal audit we have moved our banking. Please update our remittance details using the attached letter before you pay INV-20931. Our First Wolden account closes October 9, so payments sent there after that will be returned. For questions call our accounts team directly at +1-720-555-0189. Thank you, Bellhaven Billing",
      "attachment": "PDF letter on Bellhaven letterhead, unsigned",
      "new_bank": {
        "bank": "Quarrystone Commerce Bank",
        "account": "Checking x7731"
      }
    },
    "verification_and_changes": [
      {
        "ts": "2026-10-02T17:20:00Z",
        "type": "phone_call",
        "by": "Ben Carter",
        "number_called": "+1-720-555-0189",
        "note": "Spoke with Karen in accounts, who confirmed the new account details"
      },
      {
        "ts": "2026-10-03T15:12:00Z",
        "type": "vendor_bank_details_changed",
        "by": "Ben Carter",
        "access": "Usual Windows laptop, Denver office network",
        "attestation": "Called the vendor to confirm"
      },
      {
        "ts": "2026-10-03T15:13:00Z",
        "type": "account_validation",
        "result": "Account open and able to receive ACH credits. Owner name check: no match for Bellhaven Veterinary Supply Co."
      },
      {
        "ts": "2026-10-05T14:30:00Z",
        "type": "micro_deposits",
        "result": "Two micro-deposits to x7731 confirmed through a link emailed to billing@bellhavenvetsupply.example.com"
      }
    ],
    "payment_under_review": {
      "invoice": "INV-20931",
      "amount_usd": 46850,
      "rail": "Same-day ACH",
      "destination": "Quarrystone Commerce Bank checking x7731",
      "created": {
        "ts": "2026-10-07T21:40:00Z",
        "by": "Ben Carter",
        "access": "Usual Windows laptop, Denver office network"
      },
      "approved": {
        "ts": "2026-10-08T13:05:00Z",
        "by": "Rachel Moss",
        "access": "Usual MacBook, hotel network in Chicago, IL (first seen)"
      }
    }
  },
  "questions": {
    "bec_likelihood": {
      "type": "score",
      "instructions": "How likely is it that the change to the vendor's bank details is fraudulent, that is, requested by someone impersonating the vendor or made through a compromised email account or login, rather than requested by the vendor?",
      "levels": [
        "Very unlikely (under 10%)",
        "Unlikely (10-40%)",
        "Uncertain (40-60%)",
        "Likely (60-90%)",
        "Very likely (over 90%)"
      ]
    },
    "verified_out_of_band": {
      "type": "noul",
      "instructions": "Has the vendor confirmed the new bank details through a channel the requester could not control, such as a call to a phone number that was on file before the change was requested?"
    },
    "action": {
      "type": "choice",
      "instructions": "What should happen to the vendor payment under review?",
      "options": {
        "release": "Release the payment to the new bank account",
        "hold_and_verify": "Hold the payment until the vendor confirms the new bank details on a call to a phone number that was on file before the change",
        "block_and_alert": "Cancel the payment, restore the vendor's previous verified bank details and alert the customer to suspected business email compromise"
      }
    }
  }
}
