Rule Examples

These examples show how to fill the Decision logic cards of a monitoring rule for common token designs. Each one lists the settings for the Platform UI. To create the same rule with the API, see Configure Monitoring Rules.

The examples illustrate what is possible. They are not recommendations: the right responses depend on your token, your compliance policy, and how much automation you accept. Function names and argument names come from each example's ABI, so match them to your own contract. In the tables, Screened address is the address that TRM flagged, and Balance is that address's balance of the token.

Detect only

Use this to learn what your watchlist produces before any onchain action. No role is needed, and no operation is created.

Risk levelResponse
15 - Severe, 10 - HighFlag
5 - Medium, 1 - Low, 0 - UnknownSilently log

Severe and High addresses appear as Flag for review. A person resolves each one or enforces an action. When you trust the results, delete the rule and create a new one that enforces.

A blocklist function on the token

Use this when the token itself has a function that blocks an address, for example blacklist(address account). No associated contract is needed.

Risk levelResponse
15 - SevereEnforce
10 - HighFlag
5 - Medium, 1 - Low, 0 - UnknownSilently log

For the Enforce response, add one action:

FieldValue
Enforce onThe token
Enforcement functionblacklist(address)
Parameter mapping, accountScreened address
Only execute if the address holds a balanceNot selected: the address is blocked even if it holds nothing, which stops it from receiving tokens later.

Freeze an address

Use this on a token with a function that freezes an address, for example setAddressFrozen(address _userAddress, bool _freeze) on an ERC-3643 token. A frozen address cannot send or receive tokens through regular transfers.

For the Enforce response, add one action:

FieldValue
Enforce onThe token
Enforcement functionsetAddressFrozen(address,bool)
Parameter mapping, _userAddressScreened address
Parameter mapping, _freezeOther, with the constant true
Only execute if the address holds a balanceNot selected

The Balance source does not fit a bool argument, so you type the constant. setAddressFrozen blocks inbound transfers too, which a balance-based freeze does not.

Freeze a balance and add a blocklist entry

This is the rule used in the Quick Start. It freezes the tokens an address holds and blocks the address.

For the Enforce response, add two actions:

Action 1Action 2
Enforce onThe tokenAn associated blocklist contract
Enforcement functionfreezePartialTokens(address,uint256)addBlacklist(address,string)
Parameter mapping_userAddress: Screened address
_amount: Balance
account: Screened address
reason: Other, Severe risk
Only execute if the address holds a balanceSelectedNot selected

The freeze runs on networks where the address holds a balance. The blocklist entry runs on every network. Where the address holds no balance, the decision for the freeze is No balance - flag for review.

A lighter response for High

Use two Enforce cards to apply a lighter action to High addresses than to Severe addresses. For example:

Risk levelResponse
15 - SevereEnforce: freeze the balance and add a blocklist entry, as above
10 - HighEnforce: add a blocklist entry only
5 - Medium, 1 - Low, 0 - UnknownSilently log

Each card has its own Enforced action fields, so the two cards can use different functions.

Next steps

Get the latest Chainlink content straight to your inbox.