{
  "model": "grayson-1",
  "context": {
    "review": {
      "as_of": "2026-10-07T15:10:00Z",
      "trigger": "Incoming ACH credit over $10,000 to a consumer account, more than 10 times the account's largest prior credit"
    },
    "account": {
      "account": "Personal checking x7302",
      "institution": "Harbor Federal Credit Union",
      "owners": [
        "Dana R. Whitfield"
      ],
      "opened": "2026-04-18",
      "opening_channel": "Online application",
      "identity_verification": "Passed (government ID and selfie match), 2026-04-18",
      "stated_occupation": "Rideshare and delivery driver",
      "stated_expected_monthly_deposits_usd": 3000,
      "average_balance_90d_usd": 412.37,
      "largest_prior_credit_usd": 1184.2,
      "usual_credits": "Weekly rideshare platform payouts of $550 to $1,200; occasional P2P payments from 2 recurring senders",
      "business_relationships_on_file": "None",
      "prior_alerts": "None",
      "daily_p2p_limit_usd": 2500
    },
    "events_before_credit": [
      {
        "ts": "2026-10-01T23:13:44Z",
        "type": "login",
        "device": "iPhone, known since 2026-04-18",
        "ip": "198.51.100.23",
        "ip_location": "Columbus, OH"
      },
      {
        "ts": "2026-10-04T18:02:10Z",
        "type": "login",
        "device": "Windows PC, Chrome, first seen",
        "ip": "203.0.113.77",
        "ip_location": "Dallas, TX",
        "ip_type": "Hosting provider",
        "mfa": "One-time code sent to the phone on file, entered correctly"
      },
      {
        "ts": "2026-10-04T18:06:51Z",
        "type": "external_account_linked",
        "device": "Windows PC, first seen 2026-10-04",
        "detail": "Account at a cryptocurrency exchange, verified by instant account verification"
      },
      {
        "ts": "2026-10-05T16:40:22Z",
        "type": "secure_message_from_member",
        "device": "iPhone, known",
        "text": "Hi, I'm expecting a big payment this week from a client for my consulting side job, around $38k. How fast will it be available? I need to pay their supplier right away. Can you also raise my P2P limit?"
      },
      {
        "ts": "2026-10-05T19:15:03Z",
        "type": "staff_action",
        "detail": "Daily P2P limit raised from $1,000 to $2,500 at the member's request. Member told that large ACH credits may be reviewed before funds are available."
      }
    ],
    "credit_under_review": {
      "posted": "2026-10-07T14:02:00Z",
      "rail": "Same-day ACH",
      "sec_code": "CCD (corporate credit)",
      "amount_usd": 38400,
      "originator_company_name": "TARROW CREEK HVAC SVCS",
      "company_entry_description": "VENDOR PAY",
      "receiver_name_in_entry": "SALTMARSH SUPPLY PARTNERS",
      "addenda": "INV 20417 20431",
      "sending_bank": "Prairie Gate Commerce Bank",
      "funds_status": "Available, no hold placed at posting"
    },
    "events_after_credit": [
      {
        "ts": "2026-10-07T14:09:31Z",
        "type": "login",
        "device": "iPhone, known",
        "ip": "198.51.100.23",
        "ip_location": "Columbus, OH"
      },
      {
        "ts": "2026-10-07T14:11:40Z",
        "type": "p2p_payee_added",
        "device": "iPhone, known",
        "payee": "Individual, never paid before"
      },
      {
        "ts": "2026-10-07T14:12:05Z",
        "type": "p2p_out",
        "device": "iPhone, known",
        "amount_usd": 2500,
        "payee": "Payee added 2026-10-07T14:11:40Z",
        "status": "Sent"
      },
      {
        "ts": "2026-10-07T14:47:18Z",
        "type": "login",
        "device": "Windows PC, first seen 2026-10-04",
        "ip": "203.0.113.77",
        "ip_location": "Dallas, TX"
      },
      {
        "ts": "2026-10-07T14:49:02Z",
        "type": "transfer_to_external_account",
        "device": "Windows PC, first seen 2026-10-04",
        "amount_usd": 9500,
        "destination": "Cryptocurrency exchange account linked 2026-10-04",
        "status": "Pending"
      },
      {
        "ts": "2026-10-07T15:03:55Z",
        "type": "wire_request",
        "device": "Windows PC, first seen 2026-10-04",
        "amount_usd": 24000,
        "beneficiary": "Business account at another US bank, never paid before",
        "status": "Pending review"
      }
    ],
    "balances": {
      "available_before_credit_usd": 286.14,
      "available_now_usd": 26686.14
    }
  },
  "questions": {
    "proceeds_of_fraud": {
      "type": "noul",
      "instructions": "Is the credit under review the proceeds of fraud against the sender or someone else, such as business email compromise, account takeover, payroll diversion or a scam?"
    },
    "mule_likelihood": {
      "type": "score",
      "instructions": "How likely is it that the account holder is acting as a money mule, knowingly or unknowingly, by receiving the credit under review and moving it on for someone else?",
      "levels": [
        "Very unlikely (under 10%)",
        "Unlikely (10-40%)",
        "Uncertain (40-60%)",
        "Likely (60-90%)",
        "Very likely (over 90%)"
      ]
    },
    "action": {
      "type": "choice",
      "instructions": "What should the receiving institution do with the credit under review?",
      "options": {
        "release": "Release the funds and allow normal account activity",
        "hold_and_contact": "Hold the funds, restrict outbound transfers and contact the sending bank to confirm the payment",
        "return": "Return the credit to the sending bank as suspected fraud and restrict outbound transfers"
      }
    }
  }
}
