Detect insider threats in employee account access

Grayson triages insider risk alerts: whether an employee opened customer accounts without a business reason, why, and whether to close, refer or suspend.

Grayson triages alerts on employee access to customer accounts: whether the employee opened or changed accounts without a business reason, how likely they are to be helping outside fraudsters, what best explains the activity, and whether to close the alert, refer it to your insider risk team or suspend the employee's access now. It reads your access logs, the calls, chats and tickets around each lookup, and what happened to the accounts afterward, and costs about $0.06 per 1,000 alerts.

  • Decides: Decide whether an employee's account access is work, snooping or insider fraud, and close, refer or suspend.
  • Call it: When access monitoring flags an employee's activity on customer accounts
  • Questions: 1 yes/no, 1 score, 2 choice
  • Cost: $0.000060 per decision, $0.06 per 1,000, for this example's 1,691 input tokens
  • Latency: 181 ms for this example, the median of 5 calls through api.finic.ai from US-West

Example

A card services agent opened two coworkers' accounts three times in one week with no call, chat or ticket; two other unlinked lookups, including a $412,880 premier account, line up with a chat transferred from another queue and a dropped call that was written up late.

Open in PlaygroundEdit and run this request in the Finic portal.
QuestionGrayson's answer
access_without_business_reasonYes, P(yes) 75%
enabling_fraud_likelihoodVery unlikely (under 10%), 93%
explanationsnooping, 87%
actionrefer, 54%

Each percentage is Grayson's probability for the answer shown; for a yes/no question it's the probability of yes. A multiple-choice answer lists the options at 50% or more.

  • access_without_business_reason: below a threshold chosen on your past alerts, close the alert and keep the answers with it; most alerts should end here.
  • enabling_fraud_likelihood: when "Likely" plus "Very likely" is high, protect the customers first by restoring changed contact details and ending the accounts' sessions.
  • explanation and action: send snooping and policy mistakes to the manager and HR, self-dealing and enabling fraud to an investigator; a person confirms every suspension.

Call it from your code

Save request.json and send it with your API key in GRAYSON_API_KEY:

curl https://api.finic.ai/v1/decide \
  -H "Authorization: Bearer $GRAYSON_API_KEY" \
  -H "Content-Type: application/json" \
  --data @request.json

The problem

Contact-center, branch and operations staff need wide access to do their jobs, so a lookup that passes an account's details to a fraud ring looks like hundreds of ordinary ones. Access rules fire mostly on legitimate work, such as transferred chats and late tickets, and can't see that two accounts a contractor opened overnight were taken over the next day.

What to send

Send the alert with the records an insider risk analyst would pull, identifying the employee by ID, role and access rather than by name:

  • The employee's job. Role, queue, shift and entitlements; an out-of-queue lookup means something only against these.
  • Each flagged lookup and change. Reading a coworker's transactions is a different act from changing a stranger's phone number.
  • The contacts around each event, from every channel. Most unlinked lookups are explained by a transferred chat, dropped call or late ticket.
  • Who holds each account. Coworkers' and restricted accounts, and the high-balance or dormant ones fraud rings ask insiders to find.
  • What happened to the accounts afterward. A takeover a day after an unrequested phone number change is the strongest evidence.
  • Data leaving the workstation. Screen captures during an unlinked session suggest the information is being passed on.

Add your own criteria

Each institution decides in advance where referral ends and same-day suspension begins, and many treat accounts held by employees and directors as restricted records, so put your standard in the context in your team's words. This one makes any unlinked lookup of an employee's account a Category 1 violation with same-day suspension, whatever reason the employee gives and however briefly the record was open.

Your restricted-records rule adds this to the context:

{
  "insider_risk_standard": "Insider Risk Standard IR-1, section 5 (restricted records), revised 2026-04-01. Accounts held by employees, contractors and directors are restricted records. Opening a restricted record with no linked call, chat, ticket or assigned case is a Category 1 access violation, whatever reason the employee gives, however briefly the record was open and whether or not anything was changed. For a Category 1 violation, suspend the employee's system access the same day and escalate to Insider Risk and HR; access stays suspended until the investigation closes. Unlinked lookups of other customers' accounts are Category 2: refer them to Insider Risk without suspending access."
}
QuestionWithoutWith your restricted-records rule
access_without_business_reasonYes, P(yes) 75%Yes, P(yes) 73%
enabling_fraud_likelihoodVery unlikely (under 10%), 93%Very unlikely (under 10%), 89%
explanationsnooping, 87%snooping, 82%
actionrefer, 54%suspend, 96%

The coworkers' accounts are restricted records under this standard, so the action should move from referring the employee to suspending their access now, while the explanation and the fraud likelihood stay the same.

Where to call it

  • On each access-monitoring alert, before it reaches an analyst, and again when a fraud claim, takeover or DLP event hits an account they touched.
  • Before a sensitive change takes effect, such as a phone number or email change with no linked contact.
  • When the answer is uncertain, send the alert to an analyst, and don't contact the employee before you decide on their access.

Cost and latency

This example is 1,691 input tokens, so a decision costs $0.000060: $0.06 per 1,000 decisions, or $60.00 per million. You pay only for input tokens, at $0.035 per million, and each request is rounded up to the next millionth of a dollar. A larger context costs proportionally more; every response reports its size in usage.input_tokens.

Grayson answered this example in 181 ms, the median of 5 calls through api.finic.ai from US-West. Latency grows with the number of input tokens. Add your own network time to api.finic.ai.

Evaluate on your own data

Score Grayson on your own past cases before you use it: a CSV with one row per case and a column with the right answer to each question. Every other column is sent as the case.

pipx install https://docs.finic.ai/downloads/grayson_cli-0.2.2-py3-none-any.whl
grayson eval my-cases.csv --questions https://docs.finic.ai/recipes/insider-threat-detection/questions.json --label access_without_business_reason=<column> --label enabling_fraud_likelihood=<column> --label explanation=<column> --label action=<column>

Each --label names the column with that question's right answer:

  • access_without_business_reason: true or false
  • enabling_fraud_likelihood: a level, such as "Very likely (over 90%)"
  • explanation: legitimate_work, snooping, self_dealing, enabling_fraud, policy_mistake
  • action: no_action, refer, suspend

Or run grayson on its own to set up your questions step by step. You get each question's accuracy and a CSV with Grayson's answer next to yours for every case.

FAQ

Can Grayson tell snooping from an employee working with fraudsters?

It can when the evidence is in the context. Snooping usually looks like brief views of accounts the employee has a personal interest in, during their shift, with no changes and nothing exported; insiders working with fraud rings look up high-balance or dormant accounts they have no connection to, change contact details without a request, capture screens and work outside their shift, and the accounts are taken over soon after. explanation returns a probability for each, so you can see when the evidence is mixed.

Most don't, which is why most unlinked-access alerts turn out to be legitimate. Send the raw contact records near each lookup and any IT incidents that affected linking, and Grayson matches them itself, as with the transferred chat and late ticket in the example. If you can only send the link check's result, expect more alerts to come back uncertain.

Should we include HR data or personal details about the employee?

No. Send conduct and access records, and leave out personal characteristics and circumstances such as age, nationality, health, union activity or personal finances: they say nothing about what the employee did, and using them to decide who to investigate can be discriminatory or unlawful. Identify the employee by ID and role, and keep the link to their name in your case system.

On this page