Nestack Agent Care
Industries / Telecom / Fraud triage agent

Telecom AI agent · Fraud triage

Fraud & SIM-Swap Triage AI Agent

Score a SIM change, port-out or account request against the challenge set your officer certified, hold what fails and route it — a fraud analyst decides whether any number is locked.

4–6 weeksTypical delivery
Your stackDeployment
Challenge-boundAnalyst review
Agent CareAfter launch

What this agent does

Does the triage, not the lockout decision

In
01

SIM-change, port-out and profile-transfer requests arrive from supported care, retail, self-service or API sources.

02

Account, device, network and channel signals are normalised, each carried forward with the record it came from.

Reason
03

The fixed challenge set is scored as configured, and no easier path is offered.

04

The carrier's configured risk, market and exemption rules are applied.

05

Each factor in the score is bound to the record it was read from, and the gaps are marked.

Decide
06

Line-separation signals are recognised and routed to trained staff, unscored.

07

A hold on the change goes to the named fraud analyst to decide.

Out
08

The signal, the evidence, the analyst's decision and the timing stay on the case.

09

Execute write actions only inside the approval boundaries agreed during implementation.

Product statement

The agent triages and holds; a fraud analyst decides each release and lock, and an officer still certifies the procedures.

Example workflow

One SIM change, request to decision

AgentHuman
1Change request receivedCare call, retail visit, app self-service or an inbound port request
2Signals assembledAccount, device, tenure, channel and network signals, each with its named source
3Request scoredChallenge result, risk factors and confidence
4Controls appliedFixed challenge set, exemption checks, line-separation detection and confidence threshold
No human action required

Stages 1 to 4 run unaided and none of them locks anything — the agent is triaging, and the analyst's lane opens at the confidence gate.

5DecisionBranches at the confidence threshold
High confidence

Goes to the fraud analyst to decide.

Low confidence

Adds a second analyst's read first.

Fraud-desk review

The change is held with its signals, its evidence and the confidence.

Clear · Uphold · Escalate to security
Cleared — change proceeds
6Fraud systems updatedOnly where write access and approval policy allow it
7Outcome evaluatedHold precision, analyst overturns, time to review and swaps confirmed after the fact
Overturns

Every analyst overturn is counted in the evaluation.

What should not run autonomously

Human approval stays in control

Outside the boundary — human approval required8 items
Lifting a hold so a SIM change can go through.
Locking a number, suspending it or freezing a port.
Substituting an easier challenge for a failed one.
Actioning a line-separation request from a survivor.
Automation boundaryAgent acts unaided
Score the request against the challenge set as configured.
Assemble the evidence a fraud analyst would need to decide.
Place a hold on the change and route it to the fraud desk.
Surface exemption signals and stop short of adjudicating them.
Any write happens inside the boundaries agreed at implementation, never ahead of a release.
Changing the challenge set or its configuration.
Treating an SMS passcode as the authenticating factor.
Restoring a number after a swap has been confirmed.
Changes to hold, exemption or escalation rules.

Example output

One held change, annotated

A SIM change is itself access to CPNI, so what the agent proposes stays attached to its evidence.

Triage output · single requestIllustrative example
Account
Agent action
Channel
Failed challenge
Confidence
Customer impact
Long-tenure postpaid line
Held for fraud-desk review rather than locked outright
Retail, out of market
Knowledge factor failed
88%
Number stays live
As receivedTaken from the account record, the challenge result and the network signals — nothing on this side is inferred.
Signals used Challenge result Device and SIM history Channel and location
Why this holdThe challenge failed and no easier one is offered and a person still decides.
ActionClearUpholdEscalate to security
What the score decidesBelow the configured threshold the hold picks up a second analyst's read before anyone clears it.

Value

Where AI adds value

The same four claims, placed at the point in the workflow where each one applies.

Where the value landsValue 01 – 04
Every change requestFrom care, retail and self-service
03Triage

Score against the set

Draw on the account record, the fixed challenge result and the device, network and channel signals.

01Approved path

Hold the change, not the customer

Routine changes clear without an analyst touching them.

02Human review

Send the desk to the real calls

Held changes carry their evidence, so the analyst's time goes to the cases where a decision is owed.

04Build an evidence trail

The signal, the evidence behind it and the analyst who released the hold stay on the case.

Integrations

Typical integrations

Five system groups connect to the same agent. Which of them are in scope is decided in discovery.

Fraud and risk platformsSAS · NICE Actimize
Feedzai · in-house rules engines
BSS / OSSAmdocs · Netcracker
CSG · Optiva · provisioning stack
CRM and careSalesforce · Dynamics 365
Zendesk · ServiceNow

Agent

Fraud & SIM-swap triage

Reads the signals
Scores the request
Holds for the desk

Identity and authenticationIAM · knowledge-factor store
Document check · in-store photo ID
Observability & evaluationOpenTelemetry · Langfuse
Supported monitoring/evaluation sources

Integration availability depends on the client's existing systems and API access.

Agent controls

Six layers between the model and the customer's line

Every layer wraps the next. What none of them catches is in the map below.

L6 · Outermost — last line of defenceInward → L1 · closest to the model
L6Rollback / safe modeFall back to manual review when evaluation or production signals degrade.Roll back
L5Version monitoringTrack model, prompt, challenge-set and threshold configuration changes.Track
L4TraceabilityRecord the signals, the score, the evidence, the decision and the analyst.Record
L3Analyst releaseA person decides any release or lock; an officer certifies the procedures, not the agent.Gate
L2Challenge guardrailsTest the request against the fixed challenge set; a substitution is refused and the case returns.Restrict
L1Confidence thresholdsRoute low-confidence holds to a second read; confidence is not a reading of intent.Require review
Model coreRequest scored — challenge result, risk factors, exemption signals and confidence
L1 – L2Test whether a request may stand
L3Puts the release in an analyst's hands
L4 – L5Hold the evidence the signal was raised on
L6Falls back to manual review when signals degrade

How Nestack evaluates it

Evaluate the whole triage workflow — not only the swaps you confirmed.

Coverage runs the whole depth of the workflow, and every layer is cut by slice.

Surface — the decision the customer feels
Depth of coverage ▼
E1Final-output evaluationWas the challenge result read correctly, and was the hold precise?
E2Step-level evaluationDid the agent use the right account, challenge set and exemption rules?
E3Tool evaluationDid it read and write the correct account and the correct case?
E4Confidence calibrationDo low-confidence holds actually attract more analyst overturns?
E5Slice evaluationHow does performance change across specific request types?
E6Business outcomeHow many holds were overturned, and how many swaps were confirmed after the fact?
Floor — who ends up locked out

Failure modes

Where each failure originates in the agent

Seven failure modes, placed at the stage each one originates.

Agent lifecycleDirection of processing →
01 · Retrieval1 mode
QV-03

Stale account signal

Device or address history read from a superseded record.

Stage gathersAccount record, challenge set , with the source each came from
02 · Reasoning2 modes
QV-04

Weakest-challenge substitution

A failed challenge is replaced with an easier one the caller can pass.

QV-06

Survivor read as attacker

A line-separation request scores as account takeover.

Stage proposesThe score, its factors and the confidence
03 · Tool / write2 modes
QV-02

Circular authentication

The change is verified over the number being changed.

QV-05

Hold without evidence

A hold reaches the desk without what an analyst needs.

Stage writesOnly where write access and approval policy allow it
04 · Output1 mode
QV-01

Wrongful lockout

A legitimate customer is cut off from their own number.

Stage returnsThe decision the analyst makes and the customer feels
05 · Change / Version1 mode
QV-07

Silent threshold regression

A model or rule change widens what the agent holds.

Stage tracksModel, prompt, challenge set and threshold config
Sev-1 · a number is locked without an analyst Sev-2 · a wrongful hold reaches the customer Sev-3 · signal degrades, case routes to the desk

Affected slices

Overall precision can hide one bad cohort

A confirmed swap is rare against the volume of legitimate SIM changes, so wrongly-held customers outnumber caught attackers at any usable threshold. Nestack reports the overturn rate on holds by slice, not only in total.

Slice performance — reported separately, not only in aggregateIllustrative example
SliceFailure rateLift Lift vs. thresholdStatus
Line-separation requests9.7%3.4× Review
Recent movers and travellers8.3%2.9× Review
Prepaid and shared accounts4.3%1.5× Watch
Routine device upgrades2.0%0.7× Normal
Bar: overturn-rate lift vs. the device-upgrade baseline · scale 0–4.0× · tick marks the 2.0× review threshold 2 of 4 slices over threshold

Evidence-linked improvement

A miss becomes a standing test

The loop shuts when the miss is a case in the suite, not when it has been explained. That suite is what the next SIM change requested is measured against.

Improvement cycle · five stagesSwitchback — the path turns at Improve and returns at Learn
01Detect

Overturn rate rises in a request slice.

02Diagnose

Signal, challenge set or threshold? The desk reads the held cases until one cause stands.

03Improve

Whatever changes ships against a version, with the cases that prompted it attached.

04Verify

Nothing ships until the affected cases pass a second time.

05Learn

The suite grows by one case; so does the exemption list.

Learn → DetectThe return edge. The next cycle is measured against a suite one case longer.

Typical build scope

Twelve workstreams across six weeks

The build scope read against the delivery timeline. Week structure follows the six-week plan — discovery, sources, triage workflow, evaluation, integration, then production validation and handover.

Workstream Week 1Week 2Week 3Week 4Week 5Week 6
01Triage workflow discovery and automation-boundary definition.
02Signal and case-source assessment.
03Challenge-set, exemption and escalation-rule mapping.
04Request ingestion and signal normalisation.
05Scoring logic and evidence binding.
06Confidence scoring and desk routing.
07Fraud-desk review workflow.
08Fraud-platform and BSS integration.
09False-hold regression cases.
10Guardrails and release controls.
11Case-trail instrumentation.
12Deployment, documentation and Agent Care handover.
12 workstreams · 6 weeks · bar shows the weeks a workstream is active — several run in parallel Final scope and sequence confirmed in discovery

Engagement tiers

What each tier includes

Rows are the capabilities named in each tier's scope. Higher tiers include everything below them.

Capability✓ in scope · — not at this tier PilotOne market, one change path ProductionProduction fraud systems AdvancedMultiple markets / brands
Introduced at Pilot
Triage on your challenge set
Analyst release
Hold-precision baseline
Introduced at Production
Reporting by change type
Desk workflow in your systems
Approved write-back
Fraud-platform integration
Introduced at Advanced
Multi-market challenge sets
Multi-stage fraud approvals
High request volume
Multi-market fraud controls
Build price From $5,000 From $8,000 Custom quote
Final build priceConfirmed after discovery based on integrations, workflow complexity, transaction volume, approval controls and deployment requirements.
Separate from buildBuild pricing is separate from recurring Agent Care, which covers managed monitoring, evaluations, incidents and verified improvements after launch.

What we need from you

What you bring, and what we build with it

Each input maps to a piece of build scope and a week in the delivery timeline.

You bringWe build with it
01Your request intake paths and account record structure Request ingestion and signal mappingWeek 1
02Representative held and released cases Scoring baseline, signal extraction and evidence bindingWeek 2
03Your challenge set and exemption policy Challenge-set, exemption and escalation-rule mappingWeek 1
04Access to relevant APIs, feeds or exports Signal and case-source assessment, then integration setupWeek 2
05Holds you would not want placed False-hold cases and the evaluation suiteWeek 4
06What must reach an analyst before a number is locked Confidence scoring, desk routing, guardrails and release controlsWeek 3
07Named fraud analysts to decide held cases Fraud-desk review workflow, then pilot and production validationWeeks 5–6
Nothing else is required Deployment, documentation and Agent Care handover are ours.

Delivery timeline

Four phases across six weeks

The bands follow real work rather than a plan, so evaluation and pilot genuinely share the fifth week.

Phase W1W2W3W4W5W6
Discovery W1
Build W2 – W3
Evaluate W4 – W5
Pilot & Launch W5 – W6
Week focus W1Triage workflow discovery, challenge mapping and the automation boundary W2Signal and case-source integration and the scoring baseline W3Triage workflow, confidence logic and release controls W4Evaluation suite, false-hold cases and failure-mode testing W5Fraud-platform integration, pilot cases and targeted corrections W6One review cycle triaged under the fraud desk, then handover
Reading the bandEach band spans only the weeks its work is named in. The fifth week genuinely carries two kinds of work.
At the end of W6Once the cycle validates, Agent Care owns the running agent.
DurationSix-week plan shown · typical delivery 4–6 weeks depending on scope confirmed in discovery.

Next step · Telecom AI agent

Build a fraud agent around the challenge set your officer certifies.

Show us your change paths, your challenge set and who decides a lock. Get it wrong and you cut a real customer's number, their second factor and their emergency calls. We'll set the boundary and name what stays with an analyst.

Nestack Agents · Fraud & SIM-swap triageAGT-TL-14 · Agent Care available after launch