Capability 03Compliance

Monitor

A merchant is approved on the day it is read and changes the next. Monitoring is the part that keeps reading — surfaces, products, buyers and transactions — and records what it found in a form that survives being questioned.

11

Transaction monitoring

Threshold and pattern breaks raised as alerts for review. Alerts never auto-approve and never auto-clear.

12

Behavioral analytics

Velocity, reuse and clustering signals surfaced against a baseline, with the baseline shown alongside.

13

Alerts and investigations

Every alert resolves to the rule, the capture and the policy version behind it, so it can be examined.

14

Case management

Findings, remediation and rescan tracked to a deadline, with escalation past it automatic.

15

Dashboards and insights

Portfolio state as it is, including what is unconfigured, failing closed or awaiting approval.

What is actually watched

Monitoring that stops at the public homepage misses the case the rule exists for. Merchants routinely keep the storefront clean and put the prohibited claim on a blog, in an email campaign, or on an affiliate's page.

Domains, subdomains and redirect chains
Gated areas behind credentials, where the program requires it
Social surfaces and email campaigns
Affiliate and third-party pages making claims about the product
Product pages, and changes to the items behind them
Transaction pattern and threshold behaviour
Licences, registrations and their expiry
Chain of custody at every hop

What a finding carries

A finding is only useful if it survives someone disagreeing with it six months later. Every one records the captured evidence and the machinery that produced it, so a disputed finding can be re-examined rather than argued about.

Timestamp, screenshot and raw capture
Content hash of what was captured
Policy version and classifier version
Merchant, product, surface and reviewer
The full remediation history against it

Findings have no close operation

There is no dismiss button, no severity override and no administrative resolve — not on the screen, and not held by any role including the ones that can halt a program.

A finding changes state because a rescan passed. The merchant submits what it changed, the same classifier re-reads the same surface, and a pass moves the state while a fail restarts the clock. The absence of the button is the control, and adding one for convenience would quietly undo the product.

Recording the work is not endorsing it

Remediation tracking records what a merchant says it did and what the rescan found. It never records an opinion that the remediation was adequate. That judgement belongs to the rescan result and to the institution, not to an operator sitting between them.

What monitor does not do

A control layer is only useful to an institution if its limits are as clear as its capabilities.

It does not decide a claim is lawful

The classifier matches against wording the institution and its counsel wrote. It never invents the category it is matching against.

It does not resolve findings

No role can close one. Only a passing rescan changes state.

It is not a substitute for the institution's own obligations

Card-brand monitoring duties and supervisory expectations stay with the institution. This is instrumentation for meeting them.

See it running

Monitor runs in the control plane alongside the other three capabilities, on representative data.

Or start a pilot conversation
Walk the control plane

Thirty-three screens. Nothing in it is a real merchant or a real transaction.