Skip to main content

Absolute paths compare against the response; bare names compare against the bound element of the enclosing exists — category under addressIdentifications, exposures or triggers; exposureType, direction and value under exposures; percentage and the ruleTriggered fields under triggers. Core fields work here too, and are the only ones a pre-screen rule may use. String fields lowercase both sides before comparing, except exposureType, whose vocabulary is closed. cluster and ruleTriggered are nullable, so a field beneath either is unknown.

Available options:
tx.amountUsd,
tx.asset,
chain,
address,
chainalysis.risk,
chainalysis.riskReason,
chainalysis.cluster.category,
chainalysis.cluster.name,
category,
exposureType,
direction,
value,
percentage,
ruleTriggered.risk,
ruleTriggered.exposureType,
ruleTriggered.direction
Example:
Last modified on October 6, 2026