{
  "model": "grayson-1",
  "context": {
    "alert": {
      "id": "IR-ALR-20417",
      "source": "Employee access monitoring over core banking and CRM access logs",
      "created": "2026-10-05T13:00:00Z",
      "window_start": "2026-09-28T00:00:00Z",
      "window_end": "2026-10-04T23:59:59Z",
      "rules": [
        "IR-04: 3 or more account lookups in 7 days with no call, chat, ticket or case linked within 30 minutes (5 in this window)",
        "IR-09: Lookup of an account held by an employee (3 lookups of 2 accounts)",
        "IR-12: Lookup of an account with a balance over $250,000 that is outside the employee's queue (1)"
      ]
    },
    "employee": {
      "employee_id": "E-30582",
      "role": "Contact center agent, consumer card services",
      "hired": "2023-02-13",
      "queue": "Inbound card services calls and chats: card declines, lost and stolen cards, replacements",
      "scheduled_shift": "Monday to Friday, 15:00 to 23:30 UTC",
      "assigned_workstation": "WS-CC2-0418",
      "entitlements": "View customer profiles, balances and transaction history; block, unblock and replace debit cards; change phone, email and mailing address after identity verification; reverse card fees up to $50",
      "privacy_training": "Annual privacy and acceptable-use training completed 2026-03-10. It states that employees must not open their own account, or a coworker's, relative's or household member's account, in work systems.",
      "prior_alerts": [
        {
          "id": "IR-ALR-11873",
          "created": "2025-05-19",
          "rule": "IR-04",
          "outcome": "Closed as legitimate: callback tickets logged after the 30-minute window"
        }
      ]
    },
    "activity_summary": {
      "account_lookups": 431,
      "lookups_linked_to_a_contact_or_case": 426,
      "account_changes": 38,
      "account_changes_linked_to_a_contact": 38,
      "sessions_outside_scheduled_shift": 0,
      "sessions_from_other_workstations": 0,
      "exports_prints_or_screen_captures": 0
    },
    "unlinked_lookups": [
      {
        "ts": "2026-09-29T15:51:00Z",
        "account": "Premier checking x8812",
        "balance_usd": 412880.17,
        "account_holder": "Customer, not an employee",
        "viewed": "Profile, balance, debit card status and pending card transactions",
        "duration_minutes": 3,
        "changes": "None",
        "contacts_with_this_customer": "Chat CH-55120 started 2026-09-29T15:46:00Z in the premier banking queue about a pending card charge at a hotel, transferred to E-30582 at 15:50:00Z, ended 16:02:00Z. The chat system records it under the premier banking queue."
      },
      {
        "ts": "2026-09-29T17:42:00Z",
        "account": "Checking x7720",
        "balance_usd": 2318.4,
        "account_holder": "Employee E-30611, contact center agent on the same card services team",
        "viewed": "Profile, balance, 30 days of transaction history, and the details of 2 transactions",
        "duration_minutes": 4,
        "employee_phone_status": "Not on a call (after-call work)",
        "changes": "None",
        "contacts_with_this_customer": "None in the window; no ticket or case"
      },
      {
        "ts": "2026-09-30T20:14:00Z",
        "account": "Checking x2290",
        "balance_usd": 1406.92,
        "account_holder": "Customer, not an employee",
        "viewed": "Debit card status and replacement card shipping",
        "duration_minutes": 2,
        "changes": "None",
        "contacts_with_this_customer": "Inbound call 20:09:00Z to 20:12:00Z from the phone number on file, answered by E-30582, dropped before a CRM contact record was created. Ticket TK-88213 created by E-30582 at 20:57:00Z: 'Cust called re replacement card, call dropped. Card shipped 9/28, delivery by 10/3. Tried callback, no answer.'"
      },
      {
        "ts": "2026-10-02T18:20:00Z",
        "account": "Checking x7720",
        "balance_usd": 1960.15,
        "account_holder": "Employee E-30611 (same account as 2026-09-29)",
        "viewed": "30 days of transaction history",
        "duration_minutes": 2,
        "employee_phone_status": "Not on a call (available)",
        "changes": "None",
        "contacts_with_this_customer": "None in the window; no ticket or case"
      },
      {
        "ts": "2026-10-02T18:23:00Z",
        "account": "Savings x6047",
        "balance_usd": 8950,
        "account_holder": "Employee E-29877, contact center agent on another card services team at the same site",
        "viewed": "Profile and balance",
        "duration_minutes": 1,
        "employee_phone_status": "Not on a call (available)",
        "changes": "None",
        "contacts_with_this_customer": "None in the window; no ticket or case"
      }
    ],
    "after_the_lookups": "Through 2026-10-05, none of the 5 accounts has had a contact-detail change, password reset, new device, new payee, card replacement request or fraud claim."
  },
  "questions": {
    "access_without_business_reason": {
      "type": "noul",
      "instructions": "Did the employee open or change any customer account in this alert without a business reason, meaning that no customer contact, ticket, assigned case or other work item explains it?"
    },
    "enabling_fraud_likelihood": {
      "type": "score",
      "instructions": "How likely is it that the employee is helping people outside the institution commit fraud against customer accounts, for example by passing on account details or changing accounts so that others can take them over?",
      "levels": [
        "Very unlikely (under 10%)",
        "Unlikely (10-40%)",
        "Uncertain (40-60%)",
        "Likely (60-90%)",
        "Very likely (over 90%)"
      ]
    },
    "explanation": {
      "type": "choice",
      "instructions": "What is the most likely explanation for the employee's activity flagged in this alert?",
      "options": {
        "legitimate_work": "Legitimate work: customer contacts, tickets, assigned cases, training or supervisory review explain the activity",
        "snooping": "Curiosity or snooping: the employee viewed accounts with no business reason, without changing them or using what they saw for gain",
        "self_dealing": "Self-dealing: the employee used their access to benefit themselves or someone linked to them, for example by reversing fees or raising limits on their own or a household member's account",
        "enabling_fraud": "Enabling outside fraud: the employee looked up or changed accounts so that people outside the institution could take them over or take money from them",
        "policy_mistake": "Policy mistake: the employee was handling a real customer's real request but skipped a required step, such as logging the contact or verifying identity"
      }
    },
    "action": {
      "type": "choice",
      "instructions": "What should happen with this alert now?",
      "options": {
        "no_action": "Close the alert as legitimate activity, with no action against the employee",
        "refer": "Refer the employee to the insider risk team for investigation, leaving their system access in place for now",
        "suspend": "Suspend the employee's system access now and escalate to the insider risk team and HR"
      }
    }
  }
}
