{
  "$schema": "https://json-schema.org/draft/2020-12/schema",
  "$id": "https://www.firstmilelabs.com/schemas/webhooks/monitoring.review.escalated.v1.json",
  "title": "FirstMileLabs Outbound Webhook — monitoring.review.escalated (v1)",
  "description": "A review was handed to the tenant’s MLRO for senior review. Pairs with the escalation.created event raised on the same customer case.",
  "type": "object",
  "additionalProperties": true,
  "required": [
    "event",
    "eventId",
    "eventVersion",
    "timestamp",
    "orgId",
    "caseId",
    "reviewCaseId",
    "alertType",
    "occurrenceNo",
    "escalationReason"
  ],
  "properties": {
    "event": {
      "type": "string",
      "const": "monitoring.review.escalated"
    },
    "eventId": {
      "type": "string",
      "format": "uuid"
    },
    "eventVersion": {
      "type": "integer",
      "const": 1
    },
    "timestamp": {
      "type": "string",
      "format": "date-time"
    },
    "orgId": {
      "type": "string"
    },
    "crmRecordId": {
      "type": [
        "string",
        "null"
      ]
    },
    "crmSource": {
      "type": [
        "string",
        "null"
      ]
    },
    "caseId": {
      "type": "string",
      "description": "The monitored customer’s case — the record your CRM holds. Never the review case."
    },
    "reviewCaseId": {
      "type": "string",
      "format": "uuid",
      "description": "The monitoring review case this event is about. Stable across every event for the same review."
    },
    "reviewRef": {
      "type": [
        "string",
        "null"
      ],
      "description": "Human-readable reference for the review, as shown in the review queue."
    },
    "alertType": {
      "type": "string",
      "description": "The monitoring alert that opened the review, e.g. \"sanctions_hit\", \"adverse_media\", \"structure_change\"."
    },
    "severity": {
      "type": [
        "string",
        "null"
      ],
      "enum": [
        "low",
        "medium",
        "high",
        "critical",
        null
      ]
    },
    "subjectRole": {
      "type": [
        "string",
        "null"
      ],
      "description": "The flagged party’s role on the case, e.g. \"UBO\" or \"Director\". Reviews never carry the party’s name."
    },
    "subjectRef": {
      "type": [
        "string",
        "null"
      ],
      "description": "Where the flagged party sits in the case’s ownership data, e.g. \"ubo_0\", \"dir_1\" or \"company\"."
    },
    "personId": {
      "type": [
        "integer",
        "string",
        "null"
      ],
      "description": "Person-registry id of the flagged party, when they are linked to one."
    },
    "occurrenceNo": {
      "type": "integer",
      "minimum": 1,
      "description": "How many times this same fact has opened a review on this customer. 2+ means it has been reviewed before."
    },
    "escalationReason": {
      "type": "string",
      "enum": [
        "analyst_escalate",
        "band_increase",
        "model_drift"
      ],
      "description": "\"analyst_escalate\": the analyst could not call it. \"band_increase\": a confirmed match raised the customer’s risk band. \"model_drift\": an all-false-positive close re-scored the customer on the current model and the band still moved."
    },
    "escalationId": {
      "type": [
        "integer",
        "string",
        "null"
      ]
    },
    "assignedTo": {
      "type": [
        "string",
        "null"
      ],
      "description": "The MLRO it was assigned to. Null when no default MLRO is nominated and it waits in the senior queue."
    },
    "bandBefore": {
      "type": [
        "string",
        "null"
      ]
    },
    "bandAfter": {
      "type": [
        "string",
        "null"
      ]
    }
  }
}
