The SENTR closed loop

A score is a start.
Close the loop.

Catch the pattern. Make the call. Understand why. SENTR connects the whole fraud operation—so your team can act on the evidence and improve the controls behind it.

One platform. SENTR.Citadel and SENTR.Tower.
Rules, machine learning and AI explanations—with your team in control.

Evidence stays connected.
Your operation keeps moving.

Follow the logic

One bonus claim.
The bigger picture.

An iGaming bonus claim is our example. The same operating loop can connect payment attempts, account activity and your own event types—using the signals and controls relevant to each.

Illustrative workflow, not a measured customer result. The real product views below use demo data from separate sessions; they are not a recording of this example.

Explore SENTR for iGaming

01 Ingest

A new event. Not a blank slate.

Fraud hides in the gaps between systems. Bring events and their history together so a new claim is not judged in isolation.

  • Map APIs, webhooks, files, databases or streams to the context your checks need.
  • Backfill history with a defined scope and processing mode. Validate the mapping before relying on it.
Explore ingestion and history
SENTR Product viewDemo data
SENTR history-backfill configuration showing import type Events, State Only mode, Payment Attempt event type, and source, period, schedule, safety and effects tabs. Enlarge view
Give the next event a history

History-backfill setup. Scope the activity and processing mode before starting the import.

Historical activity gives first-seen, reuse and velocity checks the context they need.

Give the next event a history

History-backfill setup. Scope the activity and processing mode before starting the import. Product demonstration · synthetic data.

In our example

A bonus_claim arrives. Map account and device identifiers, then connect the relevant account activity and previous claims.

An event with usable context—not just another payload.

Ingest: the controls in detail

Custom event types are supported. Browser signals still need collection: a REST integration cannot manufacture device interactions it never received.

02 Detect

Your fraud patterns. Your controls.

Turn the patterns you know into precise rules. Use customer-specific anomaly detection to surface activity that deserves a closer look.

  • Combine conditions, lists and score contributions—or give a matching rule a direct decision.
  • Inspect rule findings alongside the customer anomaly-model signal. They are distinct inputs, not one unexplained score.
Explore detection and scoring

Open the rule workbench

SENTR Product viewDemo data
SENTR rule outcome editor with score contribution, direct decision and outcome preview controls. Enlarge view
Choose what a matching rule does

The rule outcome editor separates a score contribution from a direct decision.

Watch the controls 16 seconds · silent

A silent tour of rule configuration: open comparison, data-match and velocity options; inspect the score contribution; select a direct Review decision; open expiration settings.

Define the condition. Choose its effect. Inspect the outcome before publishing.

Choose what a matching rule does

The rule outcome editor separates a score contribution from a direct decision. Product demonstration · synthetic data.

In our example

Check the claim against bonus-abuse rules and linked activity. Look for suspicious repetition—not simply the fact that two people share a device.

Findings you can inspect, test and challenge.

Detect: the controls in detail

Drafts, versions, previews and backtests help operators assess a change. Monitor lets a rule run without affecting decisions. A scoring profile changes sensitivity inside rules; it is not the same as a decision-policy cutoff.

03 Decide

Make your risk appetite actionable.

A finding needs a response. Set the policies that turn risk into an approval, a block or a deliberate request for human review.

  • Keep rule and model thresholds explicit, with policies scoped to the activity you protect.
  • Return the decision to your application. Your integration controls what actually proceeds or stops.
Explore actions and review workflows
SENTR Product viewDemo data
SENTR policy-group editor with separate model-score review and block threshold fields. Enlarge view
Set the point where attention becomes action

Review and block cutoffs are configured separately. Displayed values are demo settings, not recommended thresholds.

Rule sensitivity, decision cutoffs and list influence answer different questions.

Set the point where attention becomes action

Review and block cutoffs are configured separately. Displayed values are demo settings, not recommended thresholds. Product demonstration · synthetic data.

In our example

For this example, the configured policy returns Review. An action policy can route the work and notify the responsible team.

A clear decision and an accountable next step.

Decide: the controls in detail

Approve and Block do not require a manual investigation for every event. Review is a branch, not a mandatory stop. An external fraud report can also start a case later.

04 Explain

No “because the score said so.”

Give the person answering for a decision something better than a number. Keep the contributing findings attached to the event.

  • Follow the evidence behind a finding instead of reconstructing it across tools.
  • AI translates relevant findings into natural language. It explains the decision; it does not make it.
Explore explanations and decision evidence
SENTR Product viewDemo data
SENTR matched-signal detail: Disposable Email Domain, matched default rule, high impact and a score contribution of plus 18. Enlarge view
See the contribution behind the score

The matched rule, its impact and the recorded reason—together on the event.

The explanation has something concrete behind it: the matched check and its contribution.

See the contribution behind the score

The matched rule, its impact and the recorded reason—together on the event. Product demonstration · synthetic data.

In our example

The reviewer can inspect the checks that matched and their recorded contributions before deciding whether the bonus claim is abuse.

A decision your team can understand and question.

Explain: the controls in detail

Explanation is available with the decision—not unlocked only after investigation. Recorded attribution and generated prose are different: not every quiet event needs an AI narrative.

05 Investigate

Follow the pattern beyond the alert.

One suspicious event rarely tells the whole story. Explore connected activity, bring the evidence into a case and give the work an owner.

  • Explore links across accounts, devices, sessions, IPs and payment methods.
  • Work through queues, priorities and case workflows. Record a written reason when changing a decision.
Explore connected investigations
SENTR Product viewDemo data
SENTR Connection Ring linking a payment-attempt event to a device and payment method, with a selected-node detail panel. Enlarge view
Follow the connection, not another spreadsheet

A payment event and its linked device and instrument in Connection Ring. A connection is an investigation lead, not a verdict.

Inspect the relationship and keep the underlying event in view.

Follow the connection, not another spreadsheet

A payment event and its linked device and instrument in Connection Ring. A connection is an investigation lead, not a verdict. Product demonstration · synthetic data.

In our example

Inspect related accounts, the device and claim history. Coordinated repeat claims may support abuse; a legitimate shared household may explain the connection.

An evidenced outcome—not an unsupported hunch.

Investigate: the controls in detail

A shared device or IP is an investigation lead, not proof of fraud. Human changes preserve the person, time, previous decision and new decision so system findings and human judgement remain distinguishable.

06 Improve

Make the next change an informed one.

An outcome should do more than close a case. Use it to find the noisy rule, missing context or policy that needs attention.

  • Use rule analytics and operational reports to decide where improvement work belongs.
  • Feed quality-controlled outcomes into eligible model-training processes. Test control changes before putting them to work.
Explore reporting and feedback
SENTR Product viewDemo data
SENTR custom report builder with Events, Rules, Cases, Profiles, Integrations and Audit Logs as data sources, plus criteria, columns, grouping, output and schedule tabs. Enlarge view
Build the report around the question

SENTR.Citadel’s custom report builder: choose a data source, then shape criteria, columns, grouping and schedule.

Start with the operational question—not the spreadsheet export you happen to have.

Build the report around the question

SENTR.Citadel’s custom report builder: choose a data source, then shape criteria, columns, grouping and schedule. Product demonstration · synthetic data.

In our example

If legitimate claims were caught, inspect why. Repair a missing field, test a narrower rule or adjust the relevant policy—then check the effect.

A loop back to better inputs and better-informed controls.

How the feedback loop works

One corrected decision does not instantly retrain the model or guarantee a better next decision. Customer-model training depends on sufficient clean data and its scheduled process. Custom report building, shown here, is a SENTR.Citadel control.

Same intelligence. Different operating depth.

Choose how much you want to control.

You have seen the full platform workflow. SENTR.Tower keeps the engine, explanations and case work, with presets and simpler configuration. SENTR.Citadel opens up the deeper controls.

SENTR.Tower

For teams that need protection without a full-time fraud operation. Start with guided presets, respond to alerts and investigate decisions that need attention.

Explore the guided operating model ↗

SENTR.Citadel

For operators who want to shape rules, policies, workflows and custom reporting around their market, event types and risk appetite.

Explore the complete product ↗

Put the claim to the test

Your events.
Your current controls.
Our proof.

For qualified SENTR.Citadel evaluations, free 50-day Shadow Mode runs read-only beside your current controls. Compare findings and investigate disagreements before deciding what should change.

Explore Shadow Mode ↗

An optional proof route—not a condition for every customer. SENTR.Citadel starts with a conversation and infrastructure discovery. SENTR.Tower has a guided 14-day start, subject to fit and readiness.

Bring the workflow your current stack struggles with.

A recurring fraud pattern. A noisy rule. A case that takes too long. Let’s walk through the relevant controls together and agree the right next step.

Your privacy choices

Choose how you use SENTR. Your enquiry, chat and booking do not depend on accepting analytics.

Essential functionality Always active

Delivers and secures the site, remembers this choice and supports the chat or booking you request.

Measures page visits, feature use and enquiry journeys, including recognised campaign sources. Uses analytics cookies. Form answers and chat messages are not sent to Google Analytics.

Advertising trackers are disabled. The same choices apply to UK and EU visitors.

We remember this choice on this browser for up to six months. Changing an active analytics choice reloads the page to stop tracking scripts. Save any unfinished enquiry first.

Website data information