Limits, Statuses, and Values

This page lists the fixed values and limits of Active Monitoring, with the label you see in the Platform UI and the value the API uses. For how they fit together, see How Active Monitoring Works.

TRM risk levels

A monitoring rule matches the highest TRM risk level of a screened address. The Platform UI shows the TRM score next to the label.

Platform UI labelTRM scoreAPI value (risk_level)
Severe15severe
High10high
Medium5medium
Low1low
Unknown0unknown

TRM returns Unknown when it has no risk label for the address. Active Monitoring applies the same value when the label is missing or empty.

Rule responses

Platform UI labelAPI value (action_type)Effect
Silently logsilently_logRecords the decision. No other action.
Flagflag_for_reviewCreates a decision that waits for a human to resolve it.
Enforceauto_enforce_onchain_actionCreates one onchain operation per enforced action.

Decision outcomes

The Decision column of the Decisions log shows the outcome. The API returns it in the output field of a decision log.

Platform UI label (table)API value (output)Meaning
EvaluatingnullThe rule is still being evaluated, for example while the balance is being read.
Loggedsilently_loggedA rule with the Silently log response matched.
Flag for reviewflagged_for_reviewA rule with the Flag response matched. A person must resolve it.
No balance - flag for reviewflagged_for_reviewThe risk score matched an Enforce rule, but its balance condition was not met.
Function signature, such as freeze(address,uint256)auto_enforced_onchain_actionA rule with the Enforce response matched and created an operation.
Function signaturemanual_enforced_onchain_actionA person enforced a flagged decision with Enforce action.
Resolveduser_ignoredA person dismissed a flagged decision with Resolve and a reason. The Decision filter calls this Ignored.

A rule whose conditions do not match produces no entry in the Decisions log.

Operation statuses

An enforced decision links to an operation. The Operation status column shows its latest status.

Platform UI labelAPI valueTerminalMeaning
SubmittedpendingNoThe operation is created and queued.
SendingsendingNoThe operation is being sent to CRE Connect.
Pending signaturepending_signatureNoThe operation waits for your signer. Applies to self-signing.
ExecutingexecutingNoThe operation is signed and being executed onchain.
SuccesssuccessYesThe operation is confirmed onchain.
FailedfailedYesThe operation failed, expired, or was cancelled.

Parameter mapping

Each argument of an enforcement function gets a value from an action variable or from a constant you type.

Action variables

Platform UI labelAPI key (reference value)TypeResolves to
Screened addressscreened_addressaddressThe address that TRM screened.
Balanceholder_balancenumberThe raw balanceOf value of the screened address on the primary token, in base units, read at evaluation time.

Which variable fits which argument

The Platform UI lists only the variables whose type fits the argument.

ABI type of the argumentAvailable variablesConstant ("Other") format
addressScreened addressA valid address
uint*BalanceDigits only, no sign
int*BalanceA whole number, with an optional leading minus
boolNonetrue or false
stringScreened addressAny non-empty text
bytes*Screened addressA value that starts with 0x

In the API, a mapping has a mapping_type of reference (the value is an action variable key) or constant (the value is the literal).

Limits

ItemLimit
Watchlist sizeNo fixed limit
CSV upload100 rows per file in the Platform UI. Columns address and chain_selector.
Screening interval, Platform UI6, 12, or 24 hours
Screening interval, APIWhole hours from 1 to 168
Monitoring rules per token1
Risk levels covered by a ruleAll 5, each in exactly one Decision logic card (Platform UI)
Monitoring rule editsNone. Delete the rule and create a new one.
Actions in one enforced responseOne or more. The same contract and function pair cannot repeat in one Decision logic card.
Operations per manual Enforce action1. Every argument is a constant.
Primary tokens per monitored token1
A token address on a networkRegistered once
TRM API keys per organization1. The key is never shown again after you save it.
List endpoints, page_sizeUp to 100

Get the latest Chainlink content straight to your inbox.