๐Ÿ›ก๏ธ aegis
๐Ÿ›ก๏ธ
v0.1 ships today: schema validation, feature engineering, rule mining, and an explainable XGBoost classifier โ€” hardened, license-clean, and CI-tested.

aegis

Config-driven ML triage for false-positive sanctions alerts.

Classical ML and rule mining only โ€” no LLMs in the runtime. Score alerts for auto-clearing, mine exception rules for Fircosoft, and keep every decision auditable.

Why aegis

No LLMs in the runtime

Every decision runs through XGBoost, SHAP, and a RIPPER rule miner. Deterministic, seeded, and reproducible โ€” the same training set always exports the same rules.

Dual, auditable output

A per-alert probability with its SHAP attribution, and mined IF-THEN rules exportable straight to a Fircosoft exception list, each carrying the support and confidence it was measured at.

Config-driven

Thresholds, feature toggles, and rule-mining parameters live in one YAML file, not code. Ship a new config to recalibrate, not a new release.

Built for adoption

Schema-validated inputs, PII-safe error messages, an all-permissive (MIT/BSD/Apache) dependency tree, and no model persistence or pickle deserialization anywhere.

How it works

Every alert flows through the same validated feature matrix โ€” a classifier and a rule miner both learn from it, producing two complementary outputs.

Raw alerts โ”€โ”€โ–ถ schema validation โ”€โ”€โ–ถ feature engineering โ”€โ”€โ”ฌโ”€โ”€โ–ถ XGBoost + SHAP โ”€โ”€โ–ถ cleared_probability (PaymentAlertInput) (string distance, corporate โ”‚ + top-3 explanation suffix, country match, โ”‚ raw screening score) โ””โ”€โ”€โ–ถ RIPPER rule miner โ”€โ”€โ–ถ Fircosoft exception rules (support + confidence)

Country fields resolve to ISO 3166-1 alpha-2 by exact match only โ€” fuzzy matching is deliberately avoided, since it silently resolves placeholder values like XX or NONE to real countries. Both fit and predict_batch validate every row and use the coerced result, so a numeric-string score actually reaches the model instead of leaving an object-dtype column behind.

Rule export contract

generate_fircosoft_rules() returns exception rules whose conditions mirror the discretizer's actual bin semantics โ€” no Infinity in the JSON, no ambiguity about which edge is inclusive:

OperatorMeaning
betweenlow < x <= high โ€” low-exclusive, high-inclusive, matching the miner's own bins
>open-ended top bin, x > value
<=open-ended bottom bin, x <= value
==categorical/binary features, or a continuous feature too low-cardinality to bin

A rule ships only when support >= rule_mining.min_support and confidence >= rule_mining.min_confidence (default 0.99) โ€” an exported rule permanently suppresses every future alert it matches, so the bar for exporting one is deliberately high.

Config keys

KeyControls
thresholds.auto_clearProbability at or above which predict_batch sets auto_clear (default 0.992)
features.enabledWhich transformers run: string distance, corporate-suffix normalization, geographic match, raw screening score
rule_mining.min_supportMinimum fraction of training alerts a rule must cover to be exported (default 0.02)
rule_mining.max_depthMaximum conditions per mined rule (default 4)
rule_mining.min_confidenceMinimum fraction of a rule's covered alerts that analysts actually cleared (default 0.99)
model.paramsPassed straight to XGBClassifier (default 200 estimators, depth 4, lr 0.05, seeded)

Quickstart

# Install:
pip install aegis-triage

# df needs PaymentAlertInput columns (+ disposition, for training)
from aegis.main import TriagePipeline

pipeline = TriagePipeline.from_config()      # packaged default config
pipeline.fit(df_train)
pipeline.generate_fircosoft_rules()          # IF-THEN rules for Fircosoft
pipeline.predict_batch(df_test)              # cleared_probability, SHAP, auto_clear

See example_usage.py for a full runnable example, and config.yaml for every tunable key.

Regulatory use: auto-clearing a sanctions alert is a regulated decision. This library ships no model-validation evidence โ€” calibrate thresholds.auto_clear and rule_mining.min_confidence against your own labelled alert history, and have a human review every mined rule before it enters a Fircosoft exception list.

Roadmap