Score a SIM change, port-out or account request against the challenge set your officer certified, hold what fails and route it — a fraud analyst decides whether any number is locked.
A confirmed swap is rare against the volume of legitimate SIM changes, so wrongly-held customers outnumber caught attackers at any usable threshold. Nestack reports the overturn rate on holds by slice, not only in total.
Slice performance — reported separately, not only in aggregateIllustrative example
Slice
Failure rate
Lift
Lift vs. threshold
Status
Line-separation requests
9.7%
3.4×
Review
Recent movers and travellers
8.3%
2.9×
Review
Prepaid and shared accounts
4.3%
1.5×
Watch
Routine device upgrades
2.0%
0.7×
Normal
Bar: overturn-rate lift vs. the device-upgrade baseline · scale 0–4.0× · tick marks the 2.0× review threshold2 of 4 slices over threshold
Evidence-linked improvement
A miss becomes a standing test
The loop shuts when the miss is a case in the suite, not when it has been explained. That suite is what the next SIM change requested is measured against.
Improvement cycle · five stagesSwitchback — the path turns at Improve and returns at Learn
01Detect
Overturn rate rises in a request slice.
02Diagnose
Signal, challenge set or threshold? The desk reads the held cases until one cause stands.
03Improve
Whatever changes ships against a version, with the cases that prompted it attached.
04Verify
Nothing ships until the affected cases pass a second time.
05Learn
The suite grows by one case; so does the exemption list.
Learn → DetectThe return edge. The next cycle is measured against a suite one case longer.
Typical build scope
Twelve workstreams across six weeks
The build scope read against the delivery timeline. Week structure follows the six-week plan — discovery, sources, triage workflow, evaluation, integration, then production validation and handover.
WorkstreamWeek 1Week 2Week 3Week 4Week 5Week 6
01Triage workflow discovery and automation-boundary definition.
02Signal and case-source assessment.
03Challenge-set, exemption and escalation-rule mapping.
04Request ingestion and signal normalisation.
05Scoring logic and evidence binding.
06Confidence scoring and desk routing.
07Fraud-desk review workflow.
08Fraud-platform and BSS integration.
09False-hold regression cases.
10Guardrails and release controls.
11Case-trail instrumentation.
12Deployment, documentation and Agent Care handover.
12 workstreams · 6 weeks · bar shows the weeks a workstream is active — several run in parallelFinal scope and sequence confirmed in discovery
Engagement tiers
What each tier includes
Rows are the capabilities named in each tier's scope. Higher tiers include everything below them.
Capability✓ in scope · — not at this tierPilotOne market, one change pathProductionProduction fraud systemsAdvancedMultiple markets / brands
Introduced at Pilot
Triage on your challenge set✓✓✓
Analyst release✓✓✓
Hold-precision baseline✓✓✓
Introduced at Production
Reporting by change type—✓✓
Desk workflow in your systems—✓✓
Approved write-back—✓✓
Fraud-platform integration—✓✓
Introduced at Advanced
Multi-market challenge sets——✓
Multi-stage fraud approvals——✓
High request volume——✓
Multi-market fraud controls——✓
Build priceFrom $5,000From $8,000Custom quote
Final build priceConfirmed after discovery based on integrations, workflow complexity, transaction volume, approval controls and deployment requirements.
Separate from buildBuild pricing is separate from recurring Agent Care, which covers managed monitoring, evaluations, incidents and verified improvements after launch.
What we need from you
What you bring, and what we build with it
Each input maps to a piece of build scope and a week in the delivery timeline.
You bringWe build with it
01Your request intake paths and account record structure→Request ingestion and signal mappingWeek 1
02Representative held and released cases→Scoring baseline, signal extraction and evidence bindingWeek 2
03Your challenge set and exemption policy→Challenge-set, exemption and escalation-rule mappingWeek 1
04Access to relevant APIs, feeds or exports→Signal and case-source assessment, then integration setupWeek 2
05Holds you would not want placed→False-hold cases and the evaluation suiteWeek 4
06What must reach an analyst before a number is locked→Confidence scoring, desk routing, guardrails and release controlsWeek 3
07Named fraud analysts to decide held cases→Fraud-desk review workflow, then pilot and production validationWeeks 5–6
Nothing else is requiredDeployment, documentation and Agent Care handover are ours.
Delivery timeline
Four phases across six weeks
The bands follow real work rather than a plan, so evaluation and pilot genuinely share the fifth week.
PhaseW1W2W3W4W5W6
DiscoveryW1
BuildW2 – W3
EvaluateW4 – W5
Pilot & LaunchW5 – W6
Week focusW1Triage workflow discovery, challenge mapping and the automation boundaryW2Signal and case-source integration and the scoring baselineW3Triage workflow, confidence logic and release controlsW4Evaluation suite, false-hold cases and failure-mode testingW5Fraud-platform integration, pilot cases and targeted correctionsW6One review cycle triaged under the fraud desk, then handover
Reading the bandEach band spans only the weeks its work is named in. The fifth week genuinely carries two kinds of work.
At the end of W6Once the cycle validates, Agent Care owns the running agent.
DurationSix-week plan shown · typical delivery 4–6 weeks depending on scope confirmed in discovery.
Next step · Telecom AI agent
Build a fraud agent around the challenge set your officer certifies.
Show us your change paths, your challenge set and who decides a lock. Get it wrong and you cut a real customer's number, their second factor and their emergency calls. We'll set the boundary and name what stays with an analyst.