FenoriTechnologies
Selected Builds

Shadow Case

Build the context before the alert exists.

We built Shadow Case: a system that maintains investigative context continuously (entity state, relationships, history and prior institutional actions) as information changes, so that when a signal requires attention, the institution is not starting from zero.

StatusReference architecture
Institutional problemCase preparation begins only when an alert fires
Technical foundationBitemporal entity state, continuous context maintenance, entity resolution
Existing systems retainedExisting monitoring and screening, unchanged
Human authorityJudgment engages only when a signal requires attention
Evaluated onContext completeness at alert time, time to understanding
DemonstrationArchitecture walkthrough on request
DataSynthetic
DeploymentInstitution-governed AWS environment
TypeContext assembly systemDomainFinancial servicesStatusReference architectureComponents6

The institutional problem: preparation begins only when the alert fires.

Most case workflows begin at the moment something crosses a threshold. Only then does the institution begin assembling the picture around the customer: even though customers, entities and relationships never stopped changing between investigations.

The first minutes of an investigation are spent asking questions the institution may already hold enough data to answer: who is this, what happened before, who are they connected to, what did we decide last time, what has changed.

Inputs and source systems.

Existing monitoring and screening systems continue to generate signals exactly as they do today. Shadow Case operates around them.

  • Transactions as they occur
  • Ownership and control changes
  • Counterparty changes
  • New and resolved alerts and cases
  • External information as it lands

How the system is composed.

What happens when an event enters.

Institutional activity changesTransactionsOwnershipCounterpartiesAlertsPrevious casesExternal information
Context maintained in the backgroundEntity stateRelationshipsRelevant historyPrior actionsRelated cases
Alert or trigger
Existing context becomes the starting point
Human investigation

Core technical components.

  • Bitemporal entity state
  • Continuous context maintenance
  • Entity resolution
  • Relationship tracking
  • State-at-alert-time handoff
  • Human authority layer

State model: bitemporal by construction

Entity state is recorded bitemporally: what was true of the entity, and when the institution knew it. As signals accumulate, the system maintains the context required to understand the entity (historical state, relevant counterparties and relationships, previous institutional actions and associated cases), with each change preserved rather than overwritten.

When an alert arrives, the handoff carries the state as of alert time. The investigation therefore begins from the picture that existed at the moment the signal fired, not from a reconstruction attempted afterwards.

Example: context accumulating before a signal.

Over four months, ordinary events accumulate around Norsk Komponent AS: an ownership change, two new counterparties, one low-priority alert closed without action. None crosses a threshold. Entities and figures in this walkthrough are synthetic.

  1. Each event updates the entity’s background state as it lands (the ownership change on 4 March, the counterparties in April, the closed alert in May), each preserved with the time it became known.
  2. No investigator is engaged. Nothing about the customer has yet required a decision.
  3. In month five, transaction monitoring raises an alert on an unusual payment pattern.
  4. The alert joins the picture that already exists. The handoff contains the ownership change, both counterparties, the prior alert and the entity’s state as of the moment the alert fired.
  5. The investigation begins at analysis. The questions that normally consume its first hour were answered in the background, months earlier.

How it sits inside the institution.

Evidence and audit behavior

Because state changes are preserved rather than overwritten, the context handed to an investigator is itself examinable: what the picture contained, and when each element entered it.

Where human authority remains

A continuously maintained case picture is not a continuously made decision. Human authority remains at the point where the institution determines what the information means and what action is justified. Preparation is continuous; consequential judgment is not.

Working with what already exists

Shadow Case does not need to become the system that generates alerts. Monitoring and screening continue to do what they do well; the system makes their signals more useful when they arrive.

What the system outputs.

  • Continuously maintained entity context, timestamped bitemporally
  • A prepared handoff at alert time: state, relationships, history, prior actions
  • An examinable record of when each element of context became known

What it deliberately does not do.

  • It does not need to become the system that generates every alert: existing monitoring and screening continue to do what they do well.
  • A continuously maintained picture is not a continuously made decision; consequential judgment happens only when a human engages.
  • It does not act on the context it maintains. Preparation is continuous; action is not.

The case should not begin the moment the alert does.

Related builds

Built around your problem, not this one.

An institution may need this build, part of it, or something entirely different. The institution determines the outcome. The technology follows.

Discuss this outcome