Trades Reconstructed — teaching lab ‹ back to Interactives
synthetic reconstruction bench · not a product · not a monitoring platform · all data is invented · you are the analyst
Trades Reconstructedthe order–trade–fulfillment lifecycle
teaching lab

This is a teaching lab, not a surveillance system. Nothing here detects, monitors, or reports on real activity — every account, order, and trade is synthetic and generated on your device. The detection logic is deliberately simple and fully visible so you can see exactly why each pattern is flagged. The point is to let you stand in the analyst's chair and reconstruct how a trade becomes a report — not to demonstrate a tool. When you reach the end, the lab reveals what was really in the data, so you can see what the rules caught and what they missed.

no dataset loaded
stage 0 · acquire

Download a synthetic client dataset

You are a surveillance analyst at a broker-dealer. In a moment you'll pull a day's worth of invented client order and trade activity — a mix of ordinary trading and, possibly, some conduct worth a second look. You will not be told in advance what is in it. Choose a market and a seed, then download.

Reminder. This dataset is produced by a seeded generator running in your browser. The same seed always yields the same case, so a run is reproducible and shareable — but none of it corresponds to any real account, firm, or instrument.
stage 1 · reporting

The reporting footprint

Every order event first becomes a record. Below is the full blotter for the session. In the US these are captured by the Consolidated Audit Trail; in the EU, executions by RTS 22 and every order by RTS 24. Select any row to reconstruct its full regulatory record. Nothing is flagged yet — this is only the raw footprint.

click a row → full record
eventtimeaccountinstrtypesideqtypricerecord
stage 2 · surveillance

Run surveillance over the data

Surveillance does not add data — it derives from the reporting footprint. Running the engine applies five transparent rules across the whole blotter and raises an alert wherever a pattern crosses threshold. Every rule shows its working. These rules are deliberately simplified — real surveillance is calibrated and context-aware; this shows the logic, not a production system.

stage 3 · report

Triage and file

You now decide. For each alert, confirm the suspicion or dismiss it. Confirming generates the suspicious-activity report the regime requires — a firm-filed STOR in the EU; an SRO referral (and, only where Bank Secrecy Act criteria are met, a FinCEN SAR) in the US. The reports are pre-populated from the very records you inspected on stage 1.

stage 4 · reveal

Ground truth

Because the data was generated, the lab knows exactly what was embedded. Here is how your run compares — what the rules and your triage caught, what slipped through, and what was flagged that shouldn't have been. This gap is the real lesson: surveillance is a filter, not an oracle.

What this shows — and doesn't. A missed pattern here is not a bug; it is what happens when conduct sits just below a threshold, and it is why real surveillance is tuned, layered, and never trusted alone. A false positive is not a failure either; it is the ordinary cost of casting a net. The lesson of the bench is that the reporting footprint is only as good as the questions asked of it — and that the analyst, not the rule, carries the judgment. None of this was a monitoring tool; it was a reconstruction of the reasoning.