Glob Payment

Customer & System Journey

Companion to the scope proposal

One client,
two views

We follow a single client from signup to scale — first through the glass (everything they see and feel), then under the hood (the machine, the AI agents, and the humans working every moment of it).

4

chapters of ordinary life

12

scenarios, good days and bad

12

AI agents preparing the work

1

rule: humans hold every pen that matters

§01 — The client

Meet Meridian

Meridian Electronics Sdn Bhd

Electronics exporter, Kuala Lumpur

Pays suppliers in

Shenzhen & Ho Chi Minh City

Gets paid by

Distributors in Germany

Declared at signup

CN / VN corridors · $250–400k / month

§02 — Through the glass

Four chapters of ordinary life

01

The front door days 0–5

There's no self-signup, deliberately. Meridian submits company documents, who really owns the business (traced past holding companies down to actual humans), and its directors. Every name is checked against global sanctions and political-exposure lists.

Then the most underrated step: the promise — where money will go, roughly how much, and what for. We don't take it on trust; we take it as the yardstick everything is measured against later. A risk score is born. A human approves. Days, not weeks.

02

Their house, their rules

The CFO invites the team: the finance manager can prepare payments; the CFO must approve anything over $50k or any new payee. Their thresholds, our enforcement — and the system physically won't let one person play both roles. Payees are screened now, at creation, so payment day isn't slowed by checks later.

03

The first payment, second by second

$80k to the Shenzhen supplier. The finance manager creates it; the CFO taps approve. In under a second, the system asks:

Payee still clear on today's lists? Destination in the promise? Amount inside the declared range? Any splitting pattern lately? Anything else odd?

All quiet → banking partner → supplier paid next day. What Meridian saw: a progress bar. The quiet part is the achievement — their first week wasn't frozen, because the promise pre-cleared expected behaviour. Being new is never itself a flag.

04

Ordinary life

They convert EUR to USD at a rate locked the moment they accept the quote — we buy at that same moment, never gambling on rates with client money. Their German distributor pays into Meridian's own EUR receiving account. The money appears immediately but becomes spendable on a timetable — that payment type can be reversed for a while, so a short hold at first, shrinking as Meridian's track record grows.

§03 — The days something is different

Twelve scenarios

False alarm or growth Threat caught Client protected The world changed Watching ourselves

False alarm

The name coincidence

A new payee shares a name with someone on a watchlist — as thousands of innocent people do.

System: the AI adjudicator compares birthdate, country, business context — different person, reasoning drafted; a human confirms in minutes. Meridian never knows.

Threat caught

The real match

A payee genuinely on a sanctions list.

System: the payment stops instantly — never a judgment call — human alerted immediately, case opened, possibly a report to authorities. The client sees only "under review": warning anyone, even an honest client, is a crime called tipping-off.

Threat caught

Splitting under the radar

Nine payments of $9,800 in two days to related payees. Each innocent alone; the pattern has a shape.

System: payments hold; the officer opens an AI-prepared brief and asks for context through the portal. Invoices arrive → cleared, recorded. They don't → the case deepens.

Client protected

The 2am hack

Meridian goes silent for three weeks. Then Monday, 2am: a brand-new payee in an undeclared country, three maximum-size payments.

System: dormant-then-burst + unknown destination + speed — everything stops before the first dollar leaves. We phone the CFO on the number from onboarding. Their email was hacked. Detection is the honest client's bodyguard.

Growth

Success outgrows the promise

Business booms; volume trends toward the declared ceiling.

System: before anything trips, the portal nudges: "update your expected activity." Compliance approves the new promise. Growth is never punished — only unexplained change is.

Threat caught

In and straight out

Funds landing and leaving within hours, over and over, nothing sticking — worse when many strangers pay in and it all flows out to one place.

System: the classic laundering shape. Outbound payments hold; a case opens.

The world changed

Lists change overnight

Sanctions lists update somewhere in the world.

System: by morning the entire book is re-checked — every client, owner, director, payee. A match that didn't exist yesterday pauses whatever it touches today.

Threat caught

The dissolved company

Our registry watch notices a client company was quietly struck off the companies register.

System: frozen automatically — a dissolved company has no business moving money. Softer version: directors and ownership change together → not a block, a fresh look, because that's how shell companies get repurposed.

The world changed

Politics & the news

A director's spouse becomes a government minister; a news article mentions "Meridian."

System: the risk score rises and future activity gets closer attention — nothing blocks. For the article, an AI filter first checks it's even our Meridian. It usually isn't.

Client protected

Money taken back

The German distributor's payment is recalled five days later by the sending bank.

System: still inside the holding window → returned, client informed. Already released, because Meridian earned fast access → the shortfall becomes a debt we recover. The timetable exists to make that second story rare.

False alarm

The unmatched arrival

Money arrives with a garbled reference — whose is it?

System: parked, never guessed. An AI matcher searches references, invoices and expected payers, proposes the answer; a human confirms — or the money goes back where it came from.

Watching ourselves

Watching the watchers

Could an officer clear alerts too generously — carelessly, or worse?

System: large dismissals need a second officer; an AI quality reviewer scans decisions for inconsistency; a sample is re-reviewed blind, without the AI's recommendation visible — so humans never drift into rubber-stamping.

Through all twelve, Meridian sees one honest, boring status — "under review; we may ask a question" — with a service-time promise. Inside, every review starts from an AI-prepared file and ends with a human decision, recorded forever. And every decision feeds back: jumpy rules get tuned, patterns humans caught become new rules, and each client's score drifts with their behaviour — good history buys faster money and fewer questions. Trust is earned by the ledger, not claimed on a form.

§04 — Under the hood

Three layers, hard walls

Layer 1 — The machine

deterministic code · milliseconds · same answer every time

Moves money, enforces gates, keeps the books. Every hold and every release is dumb, fast, honest code.

Layer 2 — The agents

12 narrow specialists · read, gather, prepare, recommend

Never touch money, never in the payment path. Banned from the hot path for three unbending reasons: latency, determinism — and prompt injection. Payment references are attacker-written text; an AI inside the approval gate means criminals get to talk directly to your gatekeeper.

Layer 3 — The humans

deciders, not assemblers

Every agent output lands as a recommendation in a queue a human already works. Every judgment that matters — release, escalate, file, approve — is a human's, recorded forever.

The same journey, seen from inside

Every moment of Meridian's story, and who — or what — was working it.

Journey momentThe machine doesThe agent working itThe human call
Access request arrivesCreates prospect, fires screening + registry callsKYB Analyst — extracts docs, builds ownership graph, flags declared-vs-registry gaps, drafts approval memoApprove / decline the client
Payees addedScreens every name at creationScreening Adjudicator — resolves name-hits, drafts match/no-matchConfirm the disposition
Payment submittedApproval policy → ledger hold → inline rules → rails. Milliseconds.no agent, everNone, unless flagged
A rule firesAuto-holds payment, writes explainable alertTriage Analyst — assembles evidence pack, recommends clear / escalateRelease or escalate
Case opensCase record, RFI channel, SLA clocksCase Investigator — research, transaction reconstruction, drafts RFI + report narrativeConclusion; file or not
World changesDelta re-screens the book, diffs registries into eventsWatch Filter — kills same-name noise, scores what's materialAct on what surfaces
Payin can't be attributedParks funds in unmatched queuePayin Matcher — searches references, invoices, expected payers; proposes match or returnConfirm match / return
Payout bouncesException queue item with partner's reason codeException Repair — diagnoses, drafts corrected resubmission or outreachApprove the resubmit
End of dayIngests partner statement, auto-matches ~95%Recon Analyst — classifies residual breaks, proposes correcting entriesBook the correction, four-eyes
Liquidity driftsThreshold alarms on balances vs pipelineTreasury Drafter — proposes a rebalance as a makerTreasury human approves as checker
Client asks "where's my money?"Serves the payment timelineSupport Responder — drafts the reply; its tools cannot see investigations, so it cannot leak themSend it
Month endFalse-positive and agreement dashboardsRule Tuner — proposes threshold changes with backtests · QA Reviewer — audits decision consistencyCompliance officer approves every rule change

Note the treasury row: the internal money move rides the same maker–checker rails as a client payment — the drafter is just a maker who happens to be software.

Mechanics 01

One pattern, twelve instances

Every agent is a stateless worker: event fires → runs with read-only tools → emits one structured recommendation → human queue. Adding agent thirteen is a prompt, a tool list and a trigger — not new architecture.

Mechanics 02

No agent-to-agent chat

Handoffs go through the same queues humans use: triage recommends escalation, a human escalates, the case's creation is the investigator's trigger. Auditable, resumable — and if every agent is down, humans work the same queues unassisted. Slower, never unsafe.

Mechanics 03

Boundaries are permissions, not promises

The Support Responder cannot leak an investigation because its tools cannot return investigation data — secrecy is enforced in the access scope, not in the prompt. Each agent: least-privilege reads, exactly one write.

Mechanics 04

Right model for the job

Cheap, fast models for filtering and matching — high volume, simple judgment. The strongest models for investigation memos and report narratives — low volume, high stakes. Overnight batch wherever real-time buys nothing. Client data stays inside privately-hosted models.

Mechanics 05

Governance in the plumbing

Every run logs model version, evidence seen, recommendation made. Agreement-with-humans per agent is a standing dashboard; blind sampling keeps reviewers honest. When a regulator asks "how do you validate these models?" — the answer is a query, not a scramble.

Mechanics 06

Safety never depends on an agent

Holds happen in the machine layer whether agents are up or not. Agents make the queues fast; they are never what makes the system safe.

§05 — The payoff

What this buys, and when

The number

15–20 4–6

Back-office headcount at a few hundred clients, without agents vs with them. Without: every alert costs 30–45 minutes of assembly before a minute of judgment. With: agents prepare, humans decide. Order-of-magnitude honest, not a promise — and the people you do hire change character: deciders, not assemblers.

Sequencing — why nothing gets rebuilt

P1

Zero agents. Volume is small; humans work the queues raw — and their recorded decisions become the corpus every agent is later measured against.

P2

Three agents — Screening Adjudicator, Triage Analyst, Payin Matcher: the highest-drudgery queues, each graded against months of human decisions from day one.

P3

The rest — investigation, recon, treasury, support, tuning, QA. Cheap to add, because the queues, explainable alerts and decision records built in P1 are the agent interfaces. The layer plugs in; nothing gets rebuilt.

The whole design in one sentence: a dumb, fast, honest machine in the middle; twelve narrow specialists reading everything around it; and a small group of humans holding every pen that matters.