Biometry · Fraud Decision
Lloyds Phase 1
Status as of 2026-10-08 (night run). Repo: Namadgi/biometry-fraud-decision
What it is
SOW v3.0 — Voice Intelligence for Genesys
Fuse precomputed Auraya voice results with phone-number and network intelligence and call metadata into one explainable fraud score and a recommended action (allow / step-up / escalate / block). Three parts: A Fraud Score API, B fraud-ops console, D analytics, data API and EventBridge feed. Out of scope: watchlists, case management, face/doc biometrics, production hardening.
Built
- A · Score API —
POST /v1/decidewith numeric voice scores and call metadata; SIM-swap 7d, reachability; group-weighted score (voice/number/network/metadata 45/20/20/15) on a monotonic ladder (>45 step-up, >65 escalate, >80 block) with tunable policy. - B · Console — JWT-guarded
/internal/*; live decisions with group breakdown; per-call override with mandatory reason and audit trail; thresholds editor with change history. - D · Analytics — metrics with M/M and Y/Y, drill-down, call search, Score Threshold Review (backtest by replaying the pure scoring core), demo seeder.
- D · Data —
/v1/metrics,/v1/callswith scoped API keys; EventBridge feed via Mongo outbox + worker. - Docs —
docs/lloyds-phase1.md: architecture, Auraya input contract, ops notes.
Open pull requests
open#10 Lloyds Phase 1: fraud score model, console, analytics, data API, eventbridge feed
feat/lloyds-phase1 → main · 9 commits · mergeable · CodeRabbit left 8 comments · Snyk code check failing
feat/lloyds-phase1 → main · 9 commits · mergeable · CodeRabbit left 8 comments · Snyk code check failing
open#11 docs: lloyds phase 1 gap analysis and plan
docs/lloyds-phase1-plan.md — versioned home for the plan
docs/lloyds-phase1-plan.md — versioned home for the plan
No other repo needs changes and no new repos are required — the plan puts all of A, B, D in this service.
Left
- Triage CodeRabbit's 8 comments on #10 (e.g. stale partner-facing OpenAPI action mapping / error text / auth section) and the Snyk finding.
- Auraya pull pattern and final numeric field names — need Auraya's docs.
- Real number-age / ownership-change mapping (XConnect / SmartNumbers); reachability pending Sekura spec.
- Real AWS bus and permissions (feed only tested against a fake endpoint).
- Decisions: console auth (biometry-auth JWT chosen in code), deploy target / per-tenant config, seeded demo history accepted for backtest.
- Deploy config for production:
JWT_SECRET,CONSOLE_EMAILS,EVENTBRIDGE_*,VITE_AUTH_URL.