A companion to the reconstruction bench. There, you ran surveillance and found what was there. Here, the alerts are already raised — you inherit a queue, and your job is the analyst's: work out why each one flagged, decide what is real and what is a false positive, and file the right report. All data is synthetic and generated on your device. The detection that produced these alerts is deliberately simple; the judgment is yours.
You are the analyst on shift. Overnight, surveillance raised a handful of alerts on a synthetic client feed. Some are real. Some are noise. One or two are real conduct that still may not need the report you'd reach for first. Choose a market and pull the queue.
Open each alert. Inspect the events, decide why it flagged, then dispose of it — dismiss it as a false positive, or escalate it and choose the report the conduct actually calls for. Escalation and a SAR are not the same decision: some conduct is market abuse that travels by referral, and some is reportable only because it has no lawful purpose. One framing to hold: in the US the analyst opens a market-abuse case and files SARs, but the referral to the SEC is made by the SRO from the CAT data — it is not a form filed at this desk.
The other half of the desk's day. These executions from the same session must be reported — CAT — accurately and on time. Complete the fields that matter, and handle the one report that came back needing a correction.
Because the queue was generated, the lab knows the truth of every alert. Here is your work against it — what you disposed of correctly, where the report you filed was the right one, and the reports you were right not to file.