# False Positive Triage Agent

*/Opportunities/False_Positive_Triage_Agent*

## Opportunity Overview

**Wedge**: The initial beachhead targets ACH and wire transfer fraud alerts at mid-sized US-based B2B fintechs. This niche experiences massive transaction volumes with highly predictable false positive patterns, allowing the agent to achieve high confidence scores quickly. Once established in domestic transfers, the agent expands into cross-border transaction monitoring and finally into full KYC onboarding document verification.
**Timing**: Large language models now possess the contextual reasoning required to parse complex transaction narratives and unstructured KYC documents, a capability missing from earlier deterministic machine learning models, allowing for explainable and audit-ready triage decisions.
**Why This I C P**: Mid-market fintechs and regional banks face the same regulatory scrutiny as tier-one banks but lack the massive internal engineering resources to build custom AI triage layers, making them highly receptive to a turnkey agentic solution.
**Size Of Prize**: ~5,000 mid-to-large financial institutions and fintechs globally × ~$250,000 annual spend on Level 1 compliance analyst labor and business process outsourcing = ~$1.25B annual prize.
**Gap Narrative**: Financial compliance teams drown in false positive alerts generated by legacy rule-based transaction monitoring systems. They need an automated triage agent that accurately dismisses obvious false positives and documents the reasoning, leaving only high-risk alerts for human investigators to review without requiring a complete rip-and-replace of the core banking ledger.
**Defensibility**: The moat relies on workflow lock-in and the accumulation of domain-specific decision history. As the agent processes alerts, it builds a proprietary graph of institutional risk appetite and approved entities, meaning replacing the agent requires throwing away thousands of hours of customized and auditor-approved decision-making logic.
**Why This Thesis**: An Agent approach fits perfectly because alert triage is fundamentally an operational labor bottleneck rather than a software tooling problem; buyers want to pay for resolved alerts instead of another dashboard their human analysts have to click through.

## Opportunity Linked Thesis

**Thesis**: [Agent](/Theses/Agent)

## Opportunity Linked I C P

**Icp**: [Managed Security Provider](/CompanyTypes/Managed_Security_Provider)

## Opportunity Market Sizing

_Illustrative — target and order-of-magnitude estimate figures, not an achieved track record (this Thing is concept-stage)._

**S A M**: ~$500M to ~$800M, targeting specifically the ~10,000 mid-market and enterprise MSSPs in North America and Europe
**S O M**: ~$15M to ~$30M achievable within 3 years via direct sales to mid-tier MSSPs
**T A M**: ~50,000 global managed security providers and enterprise SOCs × ~$50,000 to ~$80,000/yr allocated for tier-1 alert triage software or equivalent labor offset ≈ ~$2.5B to ~$4B
**Growth Rate**: ~15-20%/yr, driven by compounding alert volumes from expanding cloud perimeters and chronic shortages of available tier-1 security personnel
**Paid Comparable Spend**: ~$60,000 to ~$90,000/yr per Level 1 SOC analyst, alongside ~$20,000 to ~$50,000/yr for legacy SOAR (Security Orchestration, Automation, and Response) platform licenses

## Opportunity Incumbents

- [Cortex XSOAR](/Products/Cortex_XSOAR) — Tool
- [Splunk SOAR](/Products/Splunk_SOAR) — Tool
- [MSSP Triage Teams](/Products/MSSP_Triage_Teams) — Service
- [Custom Python Scripts](/Products/Custom_Python_Scripts) — DIY
- [Tines Security Automation](/Products/Tines_Security_Automation) — Tool
- [Excel Alert Trackers](/Products/Excel_Alert_Trackers) — Spreadsheet
- [Manual Alert Review](/Products/Manual_Alert_Review) — Service

## Opportunity Win Conditions

**Kill Thresholds**:
- Auto-close rate < 20% after 30 days of live ingestion
- Human override rate > 10% on agent-closed alerts
- Time-to-first-value > 21 days for standard Splunk or Cortex integrations
- Greater than 0.1% false negative rate (missed true threats) during a 30-day pilot
**Leading Metrics**:
- Days to first automated alert closure
- Percentage of total alert volume automatically closed
- Human override rate on agent-assigned false positives
- Percentage of alerts requiring escalation to tier-2 analysts
- Time saved per analyst per week
**What Proves Right**: MSSPs route a minimum of 10,000 live SIEM alerts to the agent within the first 14 days of deployment. The agent automatically resolves and closes over 40% of false positives with zero human intervention. Customers sign $40,000 annual contracts because they successfully reassign tier-1 analysts to proactive incident response rather than noise reduction.
**What Proves Wrong**: SOC managers force human analysts to manually verify the agent's classifications on more than 80% of alerts, entirely neutralizing the labor offset. Integration friction with legacy on-premise SIEMs pushes deployment times past 30 days. The fear of missing a critical intrusion keeps the agent permanently locked in a read-only advisory mode.

## Opportunity Build Profile

**Hardest Part**: Achieving a near-zero false negative rate on alert dismissal while parsing undocumented vendor-specific JSON payloads. Security teams demand absolute mathematical proof that the agent never auto-closes a legitimate threat.
**Min Viable Scope**: Restrict v1 strictly to Okta identity alerts and impossible travel flags, outputting only a confidence score and a triage summary to a Slack channel. Deliberately exclude automated ticket closure, network isolation actions, and multi-vendor alert correlation.
**Cold Start Problem**: Security teams refuse to grant API write access to an untested agent without proof of accuracy. Break this by running the v1 agent in a read-only shadow mode on 90 days of historically resolved alerts to establish a baseline.
**Time To First Value**: 1 to 2 weeks of read-only shadowing to calibrate confidence thresholds
**Data Moat Available**: true
**Technical Difficulty**: High

## Neighborhood

### Where the gap lives

- [Compliance Review Cycle Time](/Metrics/Compliance_Review_Cycle_Time) — latent gap · Metrics
- [Risk Threshold Breach Frequency](/Metrics/Risk_Threshold_Breach_Frequency) — latent gap · Metrics

### Incumbent in

- [Bespoke Python Scripts](/Products/Bespoke_Python_Scripts) — incumbent in · Products
- [Tines Security Automation](/Products/Tines_Security_Automation) — incumbent in · Products
- [Manual Alert Review](/Products/Manual_Alert_Review) — incumbent in · Products
- [Splunk SOAR](/Products/Splunk_SOAR) — incumbent in · Products
- [Cortex XSOAR](/Products/Cortex_XSOAR) — incumbent in · Products
- [Excel Alert Trackers](/Products/Excel_Alert_Trackers) — incumbent in · Products
- [MSSP Triage Teams](/Products/MSSP_Triage_Teams) — incumbent in · Products

### Applies thesis

- [Managed Security Provider](/CompanyTypes/Managed_Security_Provider) — applies thesis · CompanyTypes

### Embodies

- [Agent](/Theses/Agent) — embodies · Theses

### Similar Opportunities

- [Compliance Analyst Agent](/Opportunities/Compliance_Analyst_Agent) — similar · Opportunities
- [Compliance Drift Detection](/Skills/Monitoring/Opportunities/Compliance_Drift_Detection) — similar · Opportunities
- [Account Risk Automation](/Opportunities/Account_Risk_Automation) — similar · Opportunities
- [KYC Remediation Agent](/Opportunities/KYC_Remediation_Agent) — similar · Opportunities
- [KYC Resolution Agent](/Opportunities/KYC_Resolution_Agent) — similar · Opportunities
- [Sanctions Screening Automation](/Opportunities/Sanctions_Screening_Automation) — similar · Opportunities
- [Autonomous KYC Investigator](/Industries/Finance_and_Insurance/Opportunities/Autonomous_KYC_Investigator) — similar · Opportunities
- [Compliance Forensic Analyst](/Opportunities/Compliance_Forensic_Analyst) — similar · Opportunities
- [Marketing Compliance Agent](/Opportunities/Marketing_Compliance_Agent) — similar · Opportunities
- [Vendor Risk Monitoring for Fintech](/Opportunities/Vendor_Risk_Monitoring_for_Fintech) — similar · Opportunities
- [Marketing Compliance Firewall](/Opportunities/Marketing_Compliance_Firewall) — similar · Opportunities
- [Regulatory Data Validation](/Opportunities/Regulatory_Data_Validation) — similar · Opportunities
- [Launch Compliance Agent](/Opportunities/Launch_Compliance_Agent) — similar · Opportunities
- [AI Rule Validator](/Opportunities/AI_Rule_Validator) — similar · Opportunities
- [Fintech KYC Artifact Retrieval](/Opportunities/Fintech_KYC_Artifact_Retrieval) — similar · Opportunities
- [Code Compliance Triage](/Opportunities/Code_Compliance_Triage) — similar · Opportunities
- [Headless Sanctions Engine](/Opportunities/Headless_Sanctions_Engine) — similar · Opportunities
- [Predictive Compliance Scoring](/Opportunities/Predictive_Compliance_Scoring) — similar · Opportunities
- [Regulatory Mapping Agent](/Skills/Complex_Problem_Solving/Opportunities/Regulatory_Mapping_Agent) — similar · Opportunities
- [AML Audit Agent](/Opportunities/AML_Audit_Agent) — similar · Opportunities
