The two measurements
Both are taken over the same sliding 60 minutes of outbound calls, per organisation.
Volume is the more useful of the two early on. A destination with no rate is
refused before it connects, so a fraudster still hunting for a route that
works makes a great many calls and spends almost nothing — which the call
count sees and the spend does not.
An alert is critical when the figure is at least twice the threshold, and
a warning otherwise.
One known blind spot, stated rather than hidden. A call record is
written when the call hangs up, so a single three-hour call to a premium
number is invisible until it ends. Fraud is normally many calls rather than
one, so in practice the sweep fires early — but “in practice” is the honest
phrasing.
The thresholds, and why they ship switched on
One set of thresholds applies to every organisation, edited at the bottom of this screen:
Type an exact decimal for spend — it is kept as you typed it, never rounded
through a number, because the figure is quoted back to whoever decides
whether to cut a tenant off. 0 switches that check off. The next sweep
uses whatever is saved, with no restart.
An organisation that legitimately runs hot can be given its own pair through
the API,
PUT /alert-thresholds/{organisation}: a value there overrides the
default, and 0 disables that check for that tenant alone. Overrides are not
drawn on this screen, because the default is the policy nearly every
deployment runs on.
Who is told, and where
When an alert opens, three things happen at once:- It appears on this screen, for the operator and for that organisation’s own admins. The money is at least partly theirs.
- Two emails go out, not one with everybody on it: one to the organisation’s admins and one to the operator’s, so neither side is handed the other’s addresses. See email.
- A text message goes to the numbers in Text alerts to on the organisation, if any are set and the organisation has an SMS account. See SMS.
Acknowledging
Acknowledging means “I have seen this”, not “stop watching”. An alert is never deleted — the row is the record that the platform noticed, and it stays. Acknowledging closes it and records who did it and when; the first acknowledger is the one kept, so a second click cannot overwrite who actually saw it first. While an alert of one kind is open for an organisation, the sweep will not open another: that is what makes a check every minute livable. Acknowledge it while the overrun is still running and the next sweep opens a fresh one, one minute later. That is deliberate. Acknowledging must not be a way of not watching. Only an operator can acknowledge, and only an operator can edit the thresholds. They are the platform’s fraud policy, and an acknowledgement silences an alarm the operator may still be liable for. An organisation admin reads their own alerts and cannot close them.Reading the screen
Filters for state (open or acknowledged), kind (spend or call volume) and severity. The default view is newest first. Nothing is firing is the good state. Each row carries the measured figure and the threshold it passed, inside the message, so the row answers “how far over” without opening anything.What to do when one fires
First question, and it is usually the whole answer: is somebody there running a campaign? A broadcast or a dialler starting up looks exactly like this, because it is the same thing minus the theft. If nobody is, treat the credentials as compromised:- Open the organisation’s call history, filtered to outbound, and read where the calls are going and which extension is placing them.
- Change that extension’s SIP password. The new one is shown once, and every handset on it must be given it again. See extensions.
- Block the address the registrations are coming from, on Bans.