flow

Verified self-service on WhatsApp. Bankers approve what policy reserves for them.

Card questions, transfers, disputes, limits, loans, alerts. Agents handle them under policy cards written by your risk team, execute through the core-banking component, and hand to a banker — with the draft ready — when the amount, the risk score or the regulation says so.

Customer journeys

Three conversations a retail bank runs every minute.

Each one uses the same five stages: channel, identity, resolution, handover, close. The difference is the identity level and the policy card.

Autonomous. Card transactions and a transfer to a known payee — identity L2, within limits.
Approve. Credit limit above the agent's band — banker approves the prepared case in the same thread.
Outbound. A fraud alert becomes a block, a replacement card and a case — with provisional credit per policy.
Request catalog

A reference configuration for retail banking.

Every deployment adjusts these. The point is that each request has a mode, an identity level and a policy card — written down, versioned and auditable.

RequestModeIdentityAgent mayPerson when
Balance & recent transactionsAutonomousL2Read accounts, explain merchants and holdsNever (sampled by supervisor)
Card freeze / unfreeze / replaceAutonomousL2Execute in card system; issue virtual cardRepeated replacements in 30 days
Transfer to known payeeAutonomousL2Up to daily limit per segmentAbove limit or risk score ≥ 40
Transfer to new payeeApproveL3Verify, prepare, small amountsAbove small-amount band
Dispute a transactionAutonomousL2Open dispute, collect evidence, provisional credit per policyMerchant response conflicts
Credit limit changeApproveL2–L3Pull history, score, prepare caseAlways signs off above band A
Loan / mortgage inquiryAssistL2Retrieve products, pre-qualify, book bankerLeads the advice conversation
Hardship / arrearsAssistL2Recognize, prepare options within policyLeads; approves arrangements
Address / contact changeApproveL3Verify document, prepare changeApproves; cooling-off applies
Account closure, beneficiary changeHuman onlyL4Book the appointment, prepare the fileAlways
Control framework

Built to pass the review of the bank's second and third lines.

We designed the agent model around what risk, compliance and internal audit ask for: who allowed this, what did the agent see, what did it do, and can we replay it.

Policy cards as controlled documents

Owned by the business, versioned, approved through your change process. The audit log references the version that allowed each action.

Complete, replayable log

Every conversation turn, tool call, input, output, identity event and approval. Exportable to your SIEM and records systems with retention you set.

Segregation of duties

Build permission, policy ownership, approval rights and administration are separate roles. Customer-built capabilities go through the same review gate as ours.

Simulation before change

Replay last month's conversations against a new policy or model version; see containment, violations and the conversations to inspect — before anything goes live.

Human-in-the-loop by design

Handover isn't an exception path. Thresholds are the product's core mechanic, and the person always gets the prepared case, never a cold transfer.

Deployment where you need it

Private cloud region or dedicated infrastructure inside your boundary, including model inference. Data residency by tenant.

Fraud & risk

Risk components are agent tools — and they get a vote on every action.

Your fraud engine, device intelligence and behavioral signals plug in as components. The risk agent scores requests and sessions; the policy card says what a score means for each action. Alerts go out as conversations; confirmations, blocks, replacements and cases happen in the thread.

  • Session risk: device, SIM change, location, velocity, social-engineering patterns in the conversation itself
  • Step-up verification triggered by score, not by a fixed script
  • Outbound alerts with structured yes / no, then block, freeze, replace, case — automatically
  • Analyst handover with the full session and the agent's reasoning attached
Risk · session 7f2a · Dana Levi score 12policy v14
Device match · known iPhone · app session 2 days agodevice intelligence component · weight 0.35
No SIM change in 180 days · carrier checktelecom signal component · weight 0.2
Payee known · 6 prior transfers · amount within patterncore banking history · weight 0.3
!
Conversation pattern · “urgent” + third-party instruction · none detectedsocial-engineering classifier · weight 0.15
Decision · allow transfer $1,200 · L2 sufficientWould require L3 + analyst if score ≥ 40 or new payee
Early-stage collections: options within policy, a reschedule, and a person for hardship.
Collections

Early, polite, in the channel people actually answer.

The collections agent contacts customers at the right stage with options the policy allows — pay now, new date, spread installments — executes the arrangement, and recognizes hardship language to hand over to a person with the file prepared. Everything is logged for conduct review.

  • Stage-based journeys with consent, quiet hours and contact-frequency rules
  • Payment links and direct-debit changes executed through payment components
  • Arrangements within policy without a person; above it, prepared for approval
  • Vulnerability and hardship detection routed to trained staff
Rollout

Phased, with controls signed off before each step.

Most banks start with read-only self-service and inbound service, add transaction agents once the control framework is approved, and open outbound journeys last. Partners run the program; we support the first phases together.

Foundation

Channels, identity components, customer record sync, communication center for staff. Agents in shadow mode: they draft, people send.

Read-only self-service

Balances, transactions, card status, case status, FAQs from policy — autonomous with sampling. Handover with drafts live.

Transactions under policy

Card controls, transfers to known payees, disputes, limit requests in approve mode. Policy cards approved by risk; simulation on history.

Outbound & expansion

Fraud alerts, collections, renewals, onboarding. New request types added by the bank's own team with the build tooling.

How banking deployments are delivered

Solution partner, technology partners, and flow.

A bank rarely buys a platform alone. The solution partner owns the core-banking integration, the control framework and the program. Identity, fraud and telephony vendors deliver as components. flow provides the platform, the agent model, reference policy cards and the build tooling the bank's own team uses afterwards.

Partner programs

Solution partner

Core-banking and card-system integration, control framework, program management, first-line support.

Identity & fraud vendors

IDV, device intelligence, behavioral biometrics and fraud scoring packaged as components.

Telephony & BSPs

WhatsApp Business solution providers and carriers delivering channels and numbers.

flow

Platform, agents, policy model, build tooling, reference configurations, joint delivery on the first phases.

Bring your top ten request types.

We'll map each to a mode, an identity level and a policy card, connect a sandbox core, and show the agent, the handover and the log — in a session with your risk team in the room.