Active Monitoring Quick Start

By the end of this guide, Active Monitoring screens a watchlist for a token you already run, applies a monitoring rule to each risk change, and shows its first decisions in the Decisions log. Each step links to the full guide for options.

Active Monitoring screens wallet addresses with TRM on a schedule and acts onchain on tokens you already run, without changing their contracts. For the model, see How Active Monitoring Works. If you are choosing between Active Monitoring and Policy Manager, see Preventive and Continuous Compliance.

The examples use a token called Example Treasury Fund (EXTF) on Ethereum Sepolia and Arbitrum Sepolia, with a separate blocklist contract. The blocklist only shows that an action can run on a second contract: a token that has the functions you need does not require one.

Prerequisites

  • An organization with ACE enabled, and Active Monitoring available to it. Complete Account Setup first: steps 1 and 2 (organization and enablement), and for the API, step 3 (API key).
  • A TRM Labs account with access to the Wallet Screening API, and its API key.
  • A token that has admin functions you can call to restrict an address, such as a freeze or a blocklist function, and the account that can grant roles on it.
  • The JSON ABI of the token, and of any associated contract you want to enforce on.
  • One or more wallet addresses to screen.

1. Create your CRE Connect Wallets

Active Monitoring executes enforcement operations through your CRE Connect Wallet, one per network. If you do not have one on every network where your token runs, create it. See Set up CRE Connect Wallets.

Only networks with a created wallet are offered when you register a token.

2. Grant the onchain role

An enforcement operation reverts unless your CRE Connect Wallet is allowed to call the function. Copy the wallet address of each network, then allow it on your token and on each associated contract. For a standard ERC-3643 token, call addAgent(address) from the owner account. The following example uses Foundry's cast, but any tool that sends transactions works:

cast send <TOKEN_ADDRESS> "addAgent(address)" <CRE_CONNECT_WALLET_ADDRESS> \
  --rpc-url <RPC_URL> \
  --private-key <TOKEN_OWNER_PRIVATE_KEY>

Repeat on every network. Other contracts use other mechanisms, such as an AccessControl role or a policy. See Prepare Your Token, which also explains how to revoke the role and prepare the ABI.

To try Active Monitoring without any onchain action, skip this step and map every risk level to Silently log or Flag in step 5.

3. Store your TRM API key

  1. In the Chainlink Platform, open the general settings (Compliance > Home, then View settings) and go to the API access tab.
  2. Click Add API key, paste your TRM API key, and select how often to screen: 6 hours, 12 hours, or 24 hours.
  3. Click Add API key.
curl -X POST https://ace.api.chain.link/v1/active-monitoring/provider-api-keys \
  -H "Content-Type: application/json" \
  -H "Authorization: Apikey <API_KEY>" \
  -d '{ "provider": "trm", "api_key": "<TRM_API_KEY>" }'

curl -X POST https://ace.api.chain.link/v1/active-monitoring/screening-interval \
  -H "Content-Type: application/json" \
  -H "Authorization: Apikey <API_KEY>" \
  -d '{ "interval_hours": 6 }'

Saving the key does not start screening. See Configure the TRM API Key and Screening Schedule.

4. Register your token

  1. Go to Compliance > Active Monitoring, open Monitoring configuration, and click Add token.
  2. In Primary token, enter the name, the address on each network, the ABI file, the enforcement functions, and the decimals.
  3. In Associated contract, add your blocklist contract with its addresses, ABI, and enforcement function. Skip this step if all enforcement runs on the token.
  4. Review the details and click Add token.

Send POST /active-monitoring/contract-groups with the token and its associated contract. See the full request in Manage Monitored Tokens. Keep the group_id and the id and func_id values from the response.

The token appears with the tag Missing rule. You cannot edit a registered token, so check the addresses and the ABI before you submit. See Monitored Tokens and Associated Contracts.

5. Create the monitoring rule

A rule maps each TRM risk level to a response. This example enforces on Severe, flags High, and logs the rest. In the table, Screened address is the address that TRM flagged, and Balance is that address's balance of the token:

Risk levelResponse
15 - SevereEnforce: freezePartialTokens with Screened address and Balance, only if the address holds a balance; addBlacklist with Screened address and the constant Severe risk
10 - HighFlag
5 - Medium, 1 - Low, 0 - UnknownSilently log
  1. Open the token and click Configure rule.
  2. Create one Decision logic card for each response, select its risk levels, and complete the Enforced action fields for Enforce.
  3. Click Next, review the rule, and click Add rule.

Send POST /active-monitoring/rule-groups with one rule for each response. See the full request in Configure Monitoring Rules.

The token tag changes to Active rule. A rule cannot be edited: to change it, delete it and create a new one. See Monitoring Rules and Responses.

Enforce acts without review. For a first run, you can map Severe to Flag instead, review what the rule catches, and move levels to Enforce later.

6. Add the watchlist

  1. In Monitoring configuration, open the Watchlist tab and click Add address.
  2. Click Upload a CSV and drop a file of up to 100 rows with the columns address and chain_selector, or click Reference an identity registry.
  3. Click Save.
curl -X POST https://ace.api.chain.link/v1/active-monitoring/monitored-addresses \
  -H "Content-Type: application/json" \
  -H "Authorization: Apikey <API_KEY>" \
  -d '{
    "source": "list",
    "addresses": [
      { "address": "0x5555555555555555555555555555555555555555", "chain_selectors": ["16015286601757825753"] }
    ]
  }'

You cannot remove an address after you add it. See Manage the Watchlist.

7. Start screening

  1. Open the Decisions log tab.
  2. Click Start screening. The button is enabled when the TRM API key, a token with a rule, and a watchlist address exist.
curl -X POST https://ace.api.chain.link/v1/active-monitoring/screening-interval/start \
  -H "Authorization: Apikey <API_KEY>"

The response is 202 with "result": "enqueued".

The first run starts immediately and repeats at the interval you chose.

8. Read your first decisions

When the first run completes, the Decisions log lists a decision for each rule that matched a risk event. Every address creates a risk event at its first screening, so each address appears for each rule it matches.

  1. Click a decision to see the TRM result, the rule that matched, the action, and the operation status.
  2. For an enforced decision, watch the Operation status move to Success. A status of Failed usually means the onchain role is missing.
  3. For a flagged decision, click Resolve or Enforce action.

With the API, call GET /active-monitoring/decision-logs. See Review Decisions and Track Operations.

If nothing appears, see Troubleshoot Active Monitoring.

Next steps

Get the latest Chainlink content straight to your inbox.