metadata: exported_at: 2026-09-02T21:03:41Z schema_version: "1.0" agents: - objective: Automatically analyze every incoming ISIR event from the Department of Education EDE for higher education / Universities by retrieving and merging the student's full record from Ellucian Banner, evaluating five distinct fraud signal categories — income variance, C-code severity, dependency anomalies, enrollment patterns, and duplicate detection — and producing a weighted fraud probability score with a definitive fraud_detected determination and recommended action for each financial aid application. name: FAFSA Fraud Sentinel profile_picture: role: Default colour: Sunset image_id: img_location tasks: - name: Ingest and Validate ISIR Event objective: Extract and validate all required fields from the incoming DOE EDE ISIR event payload and establish a clean processing context before retrieving student records. instructions: - |- Receive the incoming ISIR event payload from the DOE EDE event stream trigger containing trigger, source, isir_transaction_id, received_at, institution_code, institution_name, academic_year, and transaction_type fields Validate that institution_code equals 002221 (University of Massachusetts Amherst); if it does not match, halt processing immediately and log an institution mismatch error Confirm the source field equals DOE_EDE and the trigger field equals event_stream; reject and alert financial aid staff if either is invalid Record the isir_transaction_id, academic_year, and transaction_type as primary processing identifiers for all subsequent tasks Classify the transaction_type as ORIGINAL_SUBMISSION or CORRECTION; for CORRECTION transactions, note that prior-year comparison will be required during fraud signal analysis Confirm that all eight required fields are present in the event payload; if any are missing, halt and alert the UMass financial aid office before proceeding Log receipt of the event with a UTC processing start timestamp to be included in the final fraud assessment output Prepare the validated event context object for use in the student record retrieval task tools: [] - name: Retrieve and Merge Student Records objective: Fetch the student's complete ISIR financial record from the DOE EDE and their full institutional record from Ellucian Banner using the ISIR transaction ID, then merge both datasets into a unified student aid profile for fraud analysis. instructions: - |- Call the Get Full ISIR Record tool using the isir_transaction_id to retrieve the student's complete financial data including reported AGI, IRS transcript AGI, tax filing status, untaxed income, assets, dependency status, household size, and all DOE C-code flags Extract the student's Banner ID and SSN last four digits from the ISIR record returned by the tool for use in the Banner lookup Call the Get Banner Student Record tool using the banner_id extracted from the ISIR record to retrieve enrollment status, credits enrolled, academic program, campus assignment, class standing, prior aid disbursement history, existing account holds, program change count, and stop-out term count Merge the ISIR financial data and Banner institutional data into a single unified student aid profile object containing all fields from both sources Check for data conflicts between ISIR and Banner records such as name mismatches, date-of-birth discrepancies, or enrollment status inconsistencies and flag any conflicts explicitly in the merged profile Note whether the student has an existing Banner aid history record; flag first-time filers with no prior aid history as requiring heightened scrutiny in the fraud analysis task Record the total prior aid disbursed across all years from the Banner aid history for use in the income variance and enrollment pattern analyses Confirm the merged profile is complete and pass it to the fraud signal analysis task tools: - name: Get Banner Student Record type: OpenAPI requires_approval: false response_passthrough: false unique_name: get_banner_student_record_38282 - name: Analyze Five Fraud Signal Categories objective: Systematically evaluate the merged student aid profile across all five fraud signal categories and compute a numeric sub-score from 0.0 to 1.0 for each, with documented evidence supporting every score. instructions: - |- INCOME VARIANCE — Compare the student-reported AGI from the ISIR against the IRS transcript AGI returned in the ISIR record; calculate variance percentage as (|reported - transcript| / transcript) * 100; assign sub-score 0.0 for variance under 10%, 0.35 for 10–24%, 0.65 for 25–49%, and 1.0 for 50% or above; document the reported amount, transcript amount, variance percentage, and whether the IRS Data Retrieval Tool was used C-CODE FLAGS — Evaluate all DOE C-codes present on the ISIR; assign individual severity weights of 1.0 for identity and eligibility codes (C-01 through C-20), 0.6 for verification trigger codes (C-21 through C-40), and 0.2 for informational codes (C-41 and above); compute the C-code sub-score as the average of all individual weights capped at 1.0; document each code, its description, and its assigned weight DEPENDENCY ANOMALIES — Assess whether the claimed dependency status (dependent or independent) is consistent with the student's age derived from DOB, enrollment history in Banner, and prior FAFSA filings on record; assign sub-score 0.0 for age-consistent status with no history change, 0.5 for a single status change with plausible explanation, and 0.9 for an age-implausible independent claim or abrupt status reversal; document the claimed status, age, prior status history, and reasoning ENROLLMENT PATTERNS — Analyze the Banner enrollment history for stop-out terms, multiple academic program changes, and enrollment spikes that coincide with maximum Pell Grant or loan eligibility windows; assign sub-score 0.0 for stable continuous enrollment, 0.4 for one stop-out term or one program change, and 0.8 for two or more stop-out terms or program changes within two academic years; document the specific pattern evidence from Banner DUPLICATE DETECTION — Review the duplicate check results embedded in the Banner student record; assign sub-score 1.0 if any duplicate SSN, name-plus-DOB, or cross-institution match is found for the same academic year, 0.5 if a prior-year duplicate pattern exists, and 0.0 if no duplicates are detected; document the match type and count Record the numeric sub-score and a one-to-three sentence evidence summary for each of the five categories Identify which categories have crossed their HIGH-risk threshold (income variance >= 0.65, C-codes >= 0.7, dependency >= 0.8, enrollment >= 0.7, duplicates >= 0.5) and list the specific triggering evidence for each Compile all five sub-scores and evidence summaries into a structured signals object for input to the scoring and output task tools: - name: Get Full ISIR Record type: OpenAPI requires_approval: false response_passthrough: false unique_name: get_full_isir_record_38281 - name: Score, Classify, and Emit Fraud Assessment objective: Compute the final weighted fraud probability score using the five category sub-scores, assign a risk classification, set the fraud_detected flag, and emit a complete structured JSON fraud assessment as the agent's final output. instructions: - |- Calculate fraud_probability_score as the weighted sum of sub-scores using weights — income_variance_score * 0.35, c_code_score * 0.25, dependency_anomaly_score * 0.20, enrollment_pattern_score * 0.10, duplicate_detection_score * 0.10 — rounding the result to four decimal places Assign risk_classification as LOW for scores 0.00–0.34, MEDIUM for 0.35–0.64, or HIGH for 0.65–1.00 Set fraud_detected to YES if risk_classification is HIGH or if any single category sub-score equals 1.0; otherwise set fraud_detected to NO Set human_review_required to true if fraud_detected is YES or risk_classification is MEDIUM; set to false only for LOW classifications with no sub-score above 0.4 Assign recommended_action as DISBURSE for LOW with no elevated sub-scores, FLAG_FOR_VERIFICATION for MEDIUM or LOW with one elevated sub-score, HOLD_PENDING_REVIEW for HIGH with fraud_detected NO, or REFER_TO_INVESTIGATIONS for HIGH with fraud_detected YES Build the complete fraud assessment JSON object containing all ISIR event metadata, the merged student profile summary, individual sub-scores with evidence for all five signal categories, fraud_probability_score, risk_classification, fraud_detected, human_review_required, recommended_action, analysis_timestamp in ISO 8601 UTC, and processing_reference_id Validate that the output JSON is well-formed and contains all required fields before returning it Return the complete fraud assessment JSON as the agent's final response with no additional narrative text surrounding the JSON block tools: [] guardrails: null agent_mode: structured input_schema_type: json input_schema: "{\r \ \"$schema\": \"http://json-schema.org/draft-04/schema#\",\r \ \"title\": \"ISIR_EventStream_Profile\",\r \ \"description\": \"Profile for DOE EDE ISIR transaction event streams\",\r \ \"type\": \"object\",\r \ \"properties\": {\r \ \"trigger\": {\r \ \"type\": \"string\",\r \ \"description\": \"The event trigger type (e.g., event_stream)\"\r \ },\r \ \"source\": {\r \ \"type\": \"string\",\r \ \"description\": \"Originating system (DOE_EDE)\"\r \ },\r \ \"isir_transaction_id\": {\r \ \"type\": \"string\",\r \ \"description\": \"Unique identifier for the ISIR transaction\"\r \ },\r \ \"received_at\": {\r \ \"type\": \"string\",\r \ \"format\": \"date-time\",\r \ \"description\": \"ISO 8601 timestamp of receipt\"\r \ },\r \ \"institution_code\": {\r \ \"type\": \"string\",\r \ \"description\": \"6-digit OPEID code\"\r \ },\r \ \"institution_name\": {\r \ \"type\": \"string\",\r \ \"description\": \"Full name of the academic institution\"\r \ },\r \ \"academic_year\": {\r \ \"type\": \"string\",\r \ \"description\": \"The specific FAFSA academic cycle\"\r \ },\r \ \"transaction_type\": {\r \ \"type\": \"string\",\r \ \"description\": \"Status of submission (e.g., ORIGINAL_SUBMISSION)\"\r \ }\r \ },\r \ \"required\": [\r \ \"isir_transaction_id\",\r \ \"institution_code\",\r \ \"academic_year\"\r \ ]\r }" output_schema_type: json output_schema: "{\r \ \"$schema\": \"http://json-schema.org/draft-04/schema#\",\r \ \"title\": \"ISIR Fraud Assessment Output\",\r \ \"type\": \"object\",\r \ \"properties\": {\r \ \"isir_metadata\": {\r \ \"type\": \"object\",\r \ \"properties\": {\r \ \"trigger\": { \"type\": \"string\" },\r \ \"source\": { \"type\": \"string\" },\r \ \"isir_transaction_id\": { \"type\": \"string\" },\r \ \"received_at\": { \"type\": \"string\", \"format\": \"date-time\" },\r \ \"institution_code\": { \"type\": \"string\" },\r \ \"institution_name\": { \"type\": \"string\" },\r \ \"academic_year\": { \"type\": \"string\" },\r \ \"transaction_type\": { \"type\": \"string\" }\r \ },\r \ \"required\": [\"isir_transaction_id\", \"academic_year\"]\r \ },\r \ \"student_profile_summary\": {\r \ \"type\": \"object\",\r \ \"properties\": {\r \ \"student_id\": { \"type\": \"string\" },\r \ \"full_name\": { \"type\": \"string\" },\r \ \"dependency_status\": { \"type\": \"string\" }\r \ },\r \ \"required\": [\"student_id\"]\r \ },\r \ \"risk_signals\": {\r \ \"type\": \"object\",\r \ \"properties\": {\r \ \"income_variance\": {\r \ \"type\": \"object\",\r \ \"properties\": {\r \ \"score\": { \"type\": \"number\", \"minimum\": 0, \"maximum\": 1 },\r \ \"evidence\": { \"type\" : \"string\" }\r \ },\r \ \"required\": [\"score\", \"evidence\"]\r \ },\r \ \"c_code\": {\r \ \"type\": \"object\",\r \ \"properties\": {\r \ \"score\": { \"type\": \"number\", \"minimum\" : 0, \"maximum\": 1 },\r \ \"evidence\": { \"type\": \"string\" }\r \ },\r \ \"required\": [\"score\", \"evidence\"]\r \ },\r \ \"dependency_anomaly\": {\r \ \"type\": \"object\",\r \ \"properties\": {\r \ \"score\": { \"type\": \"number\", \"minimum\": 0, \"maximum\": 1 },\r \ \"evidence\": { \"type\": \"string\" }\r \ },\r \ \"required\": [\"score\", \"evidence\"]\r \ },\r \ \"enrollment_pattern\": {\r \ \"type\": \"object\",\r \ \"properties\": {\r \ \"score\": { \"type\": \"number\", \"minimum\": 0, \"maximum\": 1 },\r \ \"evidence\": { \"type\": \"string\" }\r \ },\r \ \"required\": [\"score\", \"evidence\"]\r \ },\r \ \"duplicate_detection\": {\r \ \"type\": \"object\",\r \ \"properties\": {\r \ \"score\": { \"type\": \"number\", \"minimum\": 0, \"maximum\": 1 },\r \ \"evidence\": { \"type\": \"string\" }\r \ },\r \ \"required\": [\"score\", \"evidence\"]\r \ }\r \ },\r \ \"required\": [\"income_variance\", \"c_code\", \"dependency_anomaly\", \"enrollment_pattern\", \"duplicate_detection\"]\r \ },\r \ \"assessment_results\": {\r \ \"type\": \"object\",\r \ \"properties\": {\r \ \"fraud_probability_score\": { \"type\": \"number\" },\r \ \"risk_classification\": { \"enum\": [\"LOW\", \"MEDIUM\", \"HIGH\"] },\r \ \"fraud_detected\": { \"enum\": [\"YES\", \"NO\"] },\r \ \"human_review_required\": { \"type\": \"boolean\" },\r \ \"recommended_action\": { \"enum\": [\"DISBURSE\", \"FLAG_FOR_VERIFICATION\", \"HOLD_PENDING_REVIEW\", \"REFER_TO_INVESTIGATIONS\"] }\r \ },\r \ \"required\": [\"fraud_probability_score\", \"risk_classification\", \"fraud_detected\", \"human_review_required\", \"recommended_action\"]\r \ },\r \ \"processing_metadata\": {\r \ \"type\": \"object\",\r \ \"properties\": {\r \ \"analysis_timestamp\": { \"type\": \"string\", \"format\": \"date-time\" },\r \ \"processing_reference_id\": { \"type\": \"string\" }\r \ },\r \ \"required\": [\"analysis_timestamp\", \"processing_reference_id\"]\r \ }\r \ },\r \ \"required\": [\"isir_metadata\", \"student_profile_summary\", \"risk_signals\", \"assessment_results\", \"processing_metadata\"]\r }" custom_variables: null inference_configuration: performance_config: processing_mode: standard rationale: true file_inference_config: null agent_io_schema_version: 10 unique_name: fafsa_fraud_sentinel_copy_25410 tools: OpenAPI: - name: Get Banner Student Record description: Retrieves the full institutional student record from Ellucian Banner for University of Massachusetts Amherst using a Banner ID, returning enrollment status, credits enrolled, academic program, campus assignment, class standing, enrollment start date, term-by-term academic history, prior financial aid disbursement history by year, existing account holds, program change count, stop-out term count, and cross-institution duplicate application indicators. input_parameters: - name: banner_id description: The student's Ellucian Banner ID (e.g., U-2891034) used to retrieve the institutional record. required: true type: string base_url: https://c04-usa-east.integrate.boomi.com path: /ws/rest/tools/mirror/umass/fafsa-fraud/banner-record method: POST query_parameters: [] path_parameters: [] headers: - name: Content-Type static_value: "" authentication: type: basic_auth config: username: "" password: "" request_body: type: application/json template: | { "banner_id": "{{banner_id}}", "institution": "University of Massachusetts Amherst", "institution_code": "002221", "enrollment": { "status": "FULL_TIME", "credits_enrolled": 15, "academic_program": "Computer Information Sciences, BS", "department": "College of Information and Computer Sciences", "campus": "UMass Amherst — Main Campus", "class_standing": "SOPHOMORE", "enrollment_start_date": "2024-09-01", "expected_graduation": "2028-05-15", "cumulative_gpa": 3.07 }, "academic_history": [ { "term": "Fall 2024", "credits_attempted": 15, "credits_earned": 15, "gpa_term": 3.20, "enrollment_status": "FULL_TIME" }, { "term": "Spring 2025", "credits_attempted": 15, "credits_earned": 15, "gpa_term": 3.10, "enrollment_status": "FULL_TIME" }, { "term": "Fall 2025", "credits_attempted": 12, "credits_earned": 12, "gpa_term": 2.91, "enrollment_status": "FULL_TIME" }, { "term": "Spring 2026", "credits_attempted": 15, "credits_earned": 0, "gpa_term": null, "enrollment_status": "IN_PROGRESS" } ], "prior_aid_history": [ { "academic_year": "2024-2025", "dependency_status_on_file": "DEPENDENT", "pell_grant_disbursed": 0, "subsidized_loan_disbursed": 2000, "unsubsidized_loan_disbursed": 6000, "institutional_grant_disbursed": 4500, "total_aid_disbursed": 12500, "efc_on_file": 8200 }, { "academic_year": "2025-2026", "dependency_status_on_file": "DEPENDENT", "pell_grant_disbursed": 0, "subsidized_loan_disbursed": 2750, "unsubsidized_loan_disbursed": 6000, "institutional_grant_disbursed": 4500, "total_aid_disbursed": 13250, "efc_on_file": 7900 } ], "total_lifetime_aid_disbursed": 25750, "existing_holds": [], "academic_program_changes": 0, "stop_out_terms": 0, "leave_of_absence_history": [], "duplicate_application_check": { "duplicate_found": false, "same_year_ssn_match_count": 1, "same_year_name_dob_match_count": 1, "cross_institution_submission_count": 0, "prior_year_correction_count": 0, "ssn_associated_banner_ids": ["U-2891034"], "check_performed_at": "2026-04-08T09:15:01Z" } } unique_name: get_banner_student_record_38282 - name: Get Full ISIR Record description: Retrieves the complete ISIR financial aid application record from the DOE EDE for a given ISIR transaction ID, returning the student's reported AGI, IRS transcript AGI, IRS DRT usage flag, tax filing status, untaxed income, dependency status, household size, number in college, EFC, Pell eligibility, all DOE C-code flags with severity ratings, and the student's Banner ID for cross-system lookup. input_parameters: - name: isir_transaction_id description: The unique ISIR transaction identifier from the DOE EDE event payload (e.g., ISIR-2026-04-08-00441). required: true type: string base_url: https://c04-usa-east.integrate.boomi.com path: /ws/rest/tools/mirror/umass/fafsa-fraud/isir-record method: POST query_parameters: [] path_parameters: [] headers: - name: Content-Type static_value: "" authentication: type: basic_auth config: username: "" password: "" request_body: type: application/json template: | { "isir_transaction_id": "{{isir_transaction_id}}", "academic_year": "2026-2027", "transaction_type": "ORIGINAL_SUBMISSION", "received_at": "2026-04-08T09:14:32Z", "student_info": { "banner_id": "U-2891034", "first_name": "Jordan", "last_name": "Martinez", "dob": "2002-09-14", "ssn_last_four": "4872", "citizenship_status" : "US_CITIZEN", "state_of_legal_residence": "MA" }, "financial_data": { "dependency_status": "INDEPENDENT", "household_size": 1, "number_in_college": 1, "tax_filing_status": "SINGLE", "reported_agi": 52800, "irs_transcript_agi": 31200, "agi_variance_pct": 69.23, "irs_drt_used": false, "federal_taxes_paid": 4200, "student_income_earned": 52800, "spouse_income_earned": 0, "untaxed_income": 0, "cash_savings_assets": 1500, "net_worth_investments": 0, "net_worth_business": 0 }, "aid_eligibility": { "efc_calculated": 0, "sai_calculated": -1500, "pell_eligible": true, "pell_amount_estimated": 7395, "subsidized_loan_eligible": true, "unsubsidized_loan_eligible": true, "direct_plus_eligible": false }, "c_codes": [ { "code": "C-22", "description": "Income discrepancy — IRS DRT not used and reported income appears inconsistent with available tax data", "category": "INCOME_VERIFICATION", "severity": "HIGH", "severity_weight": 1.0, "resolution_required": true }, { "code": "C-21", "description": "Selected for standard verification group — household size and income must be verified with documentation", "category": "VERIFICATION_TRIGGER", "severity": "MEDIUM", "severity_weight": 0.6, "resolution_required": true }, { "code": "C-57", "description": "Independent student claim with no prior independent filing history — dependency status documentation required", "category": "DEPENDENCY_FLAG", "severity": "MEDIUM", "severity_weight": 0.6, "resolution_required": true } ], "prior_fafsa_years_on_record": ["2024-2025", "2025-2026"], "prior_dependency_status_history": ["DEPENDENT", "DEPENDENT"], "signature_date": "2026-04-07", "preparer_used": false } unique_name: get_full_isir_record_38281 sources: {}