Behavioral Profiling
How WatchTower builds a behavioral baseline for each customer or account, and uses it to spot activity that does not fit their normal pattern.
Per-customer baseline
Judge a transaction against that specific customer or account, not a flat threshold applied to everyone.
Honest confidence
Cold, warming, and mature maturity levels travel with every behavioral signal so it is never overweighted.
Feedback loop
Case outcomes are recorded as feedback so behavioral performance can be reviewed over time.
Why a fixed rule is not enough
A fixed rule, such as flag any transfer over a set amount, treats every customer the same way. A transfer that is completely normal for one customer can be genuinely unusual for another. Behavioral profiling gives WatchTower a way to judge a transaction against that specific customer or account, not just a flat threshold.
WatchTower builds a rolling profile for each sender as their transaction history grows, tracking volume, transaction count, typical amount, active days, and the channels, devices, and locations they normally use.
What a profile tracks over time
- total volume and transaction count
- typical transaction amount
- how many distinct days the account has been active
- commonly used channels, devices, and locations
Profile maturity
A brand-new account has no history to compare against, so WatchTower is honest about how much confidence a profile deserves. A profile matures over time as more transaction history builds up, and its maturity level is shown wherever the profile is used so analysts and downstream logic know how much weight to give it.
Maturity levels
- cold: little or no history, treat behavioral signals from this profile cautiously
- warming: enough history to start noticing patterns, but still building confidence
- mature: enough history for behavioral deviation to be a meaningful signal
A behavioral signal on a cold profile means something different from the same signal on a mature profile. WatchTower surfaces the maturity level alongside the signal so this distinction is never lost.
How behavioral signals reach a decision
When a transaction is evaluated, WatchTower compares it against the sender's current profile and produces behavioral signals, such as an unusual amount for this sender, a new device, or a new location. These signals feed into the same decision engine as monitoring rules and watchlist checks, alongside a data-completeness note when the incoming transaction is missing fields the profile would normally use.
- behavioral signals are combined with rule and watchlist evidence, not treated as a standalone decision
- each signal carries a plain-language explanation an analyst can read directly
- the profile maturity level travels with the signal so it can be weighed appropriately
Learning from case outcomes
When an analyst resolves a case, that outcome is recorded as feedback linked to the transaction and the reason given. Over time, this feedback record is what lets an institution and Remllo review how well behavioral signals are performing in practice, rather than assuming a model is correct indefinitely.
Where profiles are visible
Profile maturity and baseline confidence are surfaced directly in the alert and transaction views an analyst already uses, so behavioral context never requires a separate lookup.