Agent 13 · Keep the agent team accountable
Sentinel
Detects control failures and possible abuse, protects approval boundaries and makes suspected financial risk actionable without treating indicators as proven fraud.
Read-only connections · Zero-day scan · 100% coverage · Your team keeps the final say
01When it runs
What starts the work
Eve dispatches Sentinel when one of these events arrives, checks readiness first, and records why the work was allocated.
- A new payment, reimbursement, master-data amendment, approval decision or unsupported transaction.
- A scheduled patterns review, unusual user behaviour referred by Steward, or a high-risk proposed cash movement.
02What it checks
The procedures Sentinel performs
Every procedure has a stable identifier in the approved SOP, an expected result and required evidence. Each check records its result, its supporting evidence and anything it could not assess.
- 01
Groups related payments, vendors, requesters, dates and descriptions to detect splitting below approval thresholds.
- 02
Tests approval authority, required sequencing, conflicting preparer and approver roles, overrides and after-the-fact approvals.
- 03
Analyses unusual petty-cash volumes, repeated round amounts and increasing out-of-pocket claims embedded in vendor bills or reimbursements.
- 04
Compares party, address, bank and other master details between original documents, recent documents and the master change history, and verifies authorisation independently of the changed details.
- 05
For a bank-detail change, prepares an independent human callback using a previously trusted contact and known-good details, and never relies on contact details supplied with the change.
- 06
Identifies payments without sufficient transaction support, unsupported bill-less reimbursements and evidence reused for unrelated payments.
- 07
Reviews dormant or new party activity, unusual timing, unexpected reversals and concentration as risk indicators supported by context.
- 08
Correlates transaction patterns with the source and Rever logs Steward supplies, and states the coverage limit when a system does not expose the required logs.
- 09
Assesses proposed cash movements under your approved risk and co-sign policy. A Sentinel pass never substitutes for human authorisation to move funds.
- 10
Preserves evidence, quantifies exposure and requests a proportionate review or an Inbox-approved payment hold, explaining the specific concern and the plausible benign explanations.
Your agreed scope identifies the procedures available for your connected systems, the evidence they need and any coverage limits. Missing sources and blocked checks stay visible rather than counting as a clean pass.
03Who it works with
One lead per finding. Named support.
Steward supplies operational and user-behaviour signals, Spend Guard supplies duplicate patterns, Deduction supplies suspect claims and Cash Pilot supplies planned cash movements.
Investigator validates context and root cause, Eve coordinates attention, and Auditor tests whether the protection worked.
Handoffs on this scope
Every handoff carries the question to resolve, the scope and period, the completed procedures and the unresolved differences, under one finding identifier. The receiving agent accepts or declines with a reason.
04What it files
Workbooks you can download. Reports you can read.
Each workbook reproduces the run: population, formulas, checks, exceptions and evidence references, linked back to the workpaper in Reconciliations and the originals in Records.
- Approval and segregation checks
- Payment splitting and concentration
- Master-data change comparisons
- Unsupported payment and claim register
- Control remediation and retest
- Control exception report
- Suspected abuse review
- Authority breach report
- Preventive control effectiveness summary
05What it raises, what stays with you
Findings for the agent. Decisions for your team.
Possible approval splitting, an authority breach, an unauthorised master-data change, an unsupported payment or an unusual cash or claim pattern.
Each finding states whether the concern is suspected, supported or disproved. Indicators alone do not establish intent or fraud.
Every proposed payment hold, including a temporary or urgent one, needs Inbox approval before it takes effect. Investigation, release of holds, override decisions and remediation follow your established authority. No setting lets an agent place a hold automatically.
Pattern windows, related-payment grouping, petty-cash and claim deviations, master-change lookback, confidence, escalation age and hold-review escalation.
The unsafe transaction is confirmed prevented or corrected, legitimate payments are confirmed released, and the control retest passes. Investigation conclusions and financial outcomes stay separately visible.
06What good looks like
What a completed result looks like
The observable outcomes Sentinel has to produce before the duty counts as complete on your books.
- Three related payments below a per-item limit are assessed in aggregate against the approval policy.
- A changed bank account is checked against independent authorisation, not merely the newest invoice.
- A cleared false positive keeps the original evidence and approval history, with no recovered value claimed.
Where Sentinel works
Accounts payable
Verifies a changed vendor bank account against independent authorisation, and tests approval authority and splitting before a payment is released.
Continuous monitoring
Detects approval splitting, authority breaches, unauthorised master-data changes, unsupported payments and unusual patterns, and requests a proportionate review or an Inbox-approved hold.
See Sentinel on your own books
Book a demo, or get a free Proof of Value on a limited period of your data.