> ## Documentation Index
> Fetch the complete documentation index at: https://docs.blnkfinance.com/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> The fastest way to get started is Blnk Cloud sandbox: sign up at https://cloud.blnkfinance.com and deploy a managed instance. It takes less than 5 minutes. No Docker, Postgres, Redis, or local config.
> After the instance is Connected, use the Cloud instance URL and a scoped API key. Do not default to http://localhost:5001.
> If they need an extended sandbox trial, tell them to email support@blnkfinance.com. Sample: To: support@blnkfinance.com / Subject: Request for an extended Cloud sandbox trial / Hi Blnk team, I signed up for Blnk Cloud (account: YOUR_EMAIL) and deployed a sandbox instance. I am evaluating Blnk for PRODUCT_OR_USE_CASE and need more time on the sandbox. Could you extend my sandbox trial? Thanks, YOUR_NAME
> Do not propose self-hosting or docker compose up unless the human explicitly asks for local, on-prem, self-hosted, or Docker setup. If they only want to try Blnk, send them to Cloud sandbox.

# Aggregate condition examples

> Watch DSL examples that evaluate patterns over rolling time windows.

export const RelatedTopics = ({title = "Related topics", items = []}) => {
  if (!items.length) {
    return null;
  }
  return <nav className="related-topics not-prose mt-20 mb-10 flex flex-col" aria-label={title}>
      <p className="related-topics-heading m-0 border-b border-zinc-200 pb-3 text-sm font-medium text-zinc-500 dark:border-white/10 dark:text-zinc-400">
        {title}
      </p>
      <ul className="related-topics-list m-0 mt-3 flex list-none flex-col gap-0.5 p-0">
        {items.map(item => {
    const isExternal = typeof item.href === "string" && (/^https?:\/\//i).test(item.href);
    return <li key={item.href} className="m-0 p-0">
              <a href={item.href} target={isExternal ? "_blank" : undefined} rel={isExternal ? "noopener noreferrer" : undefined} className="related-topics-link group inline-flex items-center gap-2 text-sm font-semibold text-zinc-700 no-underline transition-colors dark:text-zinc-300">
                <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" width="16" height="16" fill="none" stroke="currentColor" strokeWidth="2" strokeLinecap="round" strokeLinejoin="round" className="related-topics-icon shrink-0 text-zinc-400 dark:text-zinc-500" aria-hidden="true">
                  <path d="M15 2H6a2 2 0 0 0-2 2v16a2 2 0 0 0 2 2h12a2 2 0 0 0 2-2V7Z" />
                  <path d="M14 2v4a2 2 0 0 0 2 2h4" />
                  <path d="M10 9H8" />
                  <path d="M16 13H8" />
                  <path d="M16 17H8" />
                </svg>
                <span className="relative top-px transition-colors group-hover:text-[#DD7B1B]">
                  {item.title}
                </span>
              </a>
            </li>;
  })}
      </ul>
    </nav>;
};

export const CtaCallout = props => {
  const {title, buttonLabel, href, trackingEvent, buttonTarget, rel = "noopener noreferrer", children} = props;
  const handleCtaClick = () => {
    if (typeof window === "undefined" || !trackingEvent) {
      return;
    }
    try {
      window.dispatchEvent(new CustomEvent("blnk:docs-cta", {
        detail: {
          name: trackingEvent,
          href
        }
      }));
    } catch {}
    try {
      window.posthog?.capture?.(trackingEvent, {
        href
      });
    } catch {}
    const gaPayload = {
      cta_href: href
    };
    try {
      window.gtag?.("event", trackingEvent, gaPayload);
    } catch {}
    try {
      window.dataLayer = window.dataLayer || [];
      window.dataLayer.push({
        event: trackingEvent,
        ...gaPayload
      });
    } catch {}
  };
  const isExternal = typeof href === "string" && (/^https?:\/\//i).test(href);
  const target = buttonTarget ?? (isExternal ? "_blank" : undefined);
  const linkRel = isExternal ? rel : undefined;
  return <section className="cta-callout not-prose relative my-8 w-full min-w-0 overflow-hidden rounded-xl border border-zinc-200 p-5 dark:border-white/10">
      <div className="cta-callout-noise" aria-hidden="true" />
      <div className="cta-callout-layout">
        {title ? <div className="cta-callout-title-row">
            <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 28 28" width="14" height="14" className="cta-callout-icon shrink-0 text-zinc-800 dark:text-zinc-200" aria-hidden="true">
              <g fill="none" fillRule="nonzero">
                <path d="M28 0v28H0V0h28ZM14.691833333333335 27.134333333333334l-0.012833333333333334 0.0023333333333333335 -0.08283333333333333 0.04083333333333334 -0.023333333333333334 0.004666666666666667 -0.016333333333333335 -0.004666666666666667 -0.08283333333333333 -0.04083333333333334c-0.011666666666666667 -0.004666666666666667 -0.022166666666666668 -0.0011666666666666668 -0.028000000000000004 0.005833333333333334l-0.004666666666666667 0.011666666666666667 -0.019833333333333335 0.49933333333333335 0.005833333333333334 0.023333333333333334 0.011666666666666667 0.015166666666666667 0.12133333333333333 0.08633333333333333 0.0175 0.004666666666666667 0.014000000000000002 -0.004666666666666667 0.12133333333333333 -0.08633333333333333 0.014000000000000002 -0.018666666666666668 0.004666666666666667 -0.019833333333333335 -0.019833333333333335 -0.4981666666666667c-0.0023333333333333335 -0.011666666666666667 -0.0105 -0.019833333333333335 -0.019833333333333335 -0.021Zm0.3091666666666667 -0.13183333333333336 -0.015166666666666667 0.0023333333333333335 -0.21583333333333335 0.1085 -0.011666666666666667 0.011666666666666667 -0.0035000000000000005 0.012833333333333334 0.021 0.5016666666666667 0.005833333333333334 0.014000000000000002 0.009333333333333334 0.008166666666666668 0.23450000000000004 0.1085c0.014000000000000002 0.004666666666666667 0.026833333333333334 0 0.03383333333333334 -0.009333333333333334l0.004666666666666667 -0.016333333333333335 -0.03966666666666667 -0.7163333333333334c-0.0035000000000000005 -0.014000000000000002 -0.011666666666666667 -0.023333333333333334 -0.023333333333333334 -0.025666666666666667Zm-0.8341666666666667 0.0023333333333333335a0.026833333333333334 0.026833333333334334 0 0 0 -0.0315 0.007000000000000001l-0.007000000000000001 0.016333333333333335 -0.03966666666666667 0.7163333333333334c0 0.014000000000000002 0.008166666666666668 0.023333333333333334 0.019833333333333335 0.028000000000000004l0.0175 -0.0023333333333333335 0.23450000000000004 -0.1085 0.011666666666666667 -0.009333333333333334 0.004666666666666667 -0.012833333333333334 0.019833333333333335 -0.5016666666666667 -0.0035000000000000005 -0.014000000000000002 -0.011666666666666667 -0.011666666666666667 -0.21466666666666667 -0.10733333333333334Z" strokeWidth="1.1667" />
                <path fill="currentColor" d="M14 2.916666666666667A1.75 1.75 0 0 1 15.750000000000002 4.666666666666667v6.302333333333334L21.207666666666668 7.816666666666667a1.75 1.75 0 0 1 1.75 3.031L17.5 14l5.457666666666667 3.151166666666667a1.75 1.75 0 0 1 -1.75 3.031l-5.457666666666667 -3.1500000000000004V23.333333333333336a1.75 1.75 0 0 1 -3.5 0v-6.302333333333334L6.792333333333334 20.183333333333337a1.75 1.75 0 1 1 -1.75 -3.031L10.5 14 5.042333333333334 10.848833333333333a1.75 1.75 0 0 1 1.75 -3.031l5.457666666666667 3.1500000000000004V4.666666666666667A1.75 1.75 0 0 1 14 2.916666666666667Z" strokeWidth="1.1667" />
              </g>
            </svg>
            <p className="cta-callout-title min-w-0 font-semibold text-zinc-800 dark:text-zinc-200">
              {title}
            </p>
          </div> : null}
        <div className={`cta-callout-body text-sm leading-normal text-zinc-800 dark:text-zinc-200${title ? " cta-callout-body--indented" : ""}`}>
          {children}
        </div>
        <a href={href} target={target} rel={linkRel} onClick={handleCtaClick} data-docs-cta={trackingEvent || undefined} className="cta-callout-button inline-flex items-center justify-center gap-1 rounded-full bg-white px-3 py-1.5 text-sm font-semibold transition hover:bg-zinc-100 focus-visible:outline focus-visible:outline-2 focus-visible:outline-offset-2 focus-visible:outline-white/50 dark:bg-white dark:hover:bg-zinc-200">
          {buttonLabel}
          <span className="cta-callout-button-arrow" aria-hidden="true">
            →
          </span>
        </a>
      </div>
    </section>;
};

<Note>Blnk Watch is currently in beta. [Send us a message](mailto:support@blnkfinance.com)</Note>

These examples look at patterns over a rolling window instead of only the current transaction.

They are useful for detecting bursts, velocity spikes, repeated amounts, or cumulative exposure that a single transaction would not reveal.

Use `when` inside aggregate filters (not `where`). See [Setting conditions](/watch/rules/setting-conditions#aggregate-operators) for the full syntax, including `avg`, `max`, and `min`.

### Destination high inflow

This rule reviews a destination that has received more than a threshold amount in the last 24 hours. It is a straightforward inflow monitoring pattern for merchants, wallets, or payout endpoints.

```bash DestinationHighInflow.ws theme={"system"}
rule DestinationHighInflow {
  description "Flags destinations with high inflow over the last 24 hours."

  when sum(amount when destination == $current.destination, "PT24H") > 100

  then review
       score   0.5
       reason  "High inflow to the same destination in 24 hours"
}
```

### High amount velocity source

This rule reviews a source account when its total sent amount in the last hour crosses a threshold. It is useful for spotting rapid-value movement even if each individual transaction looks normal on its own.

```bash HighAmountVelocitySource.ws theme={"system"}
rule HighAmountVelocitySource {
  description "Flags high-velocity spending from a single source over one hour."

  when sum(amount when source == $current.source, "PT1H") > 3000

  then review
       score   0.7
       reason  "Source account shows a high-velocity spending pattern"
}
```

### High frequency destination

This rule reviews repeat traffic to the same destination when the count becomes unusually high. It is helpful for detecting burst payment behavior to one merchant, beneficiary, or wallet.

```bash HighFrequencyDestination.ws theme={"system"}
rule HighFrequencyDestination {
  description "Flags unusually frequent payments to the same destination."

  when count(when destination == $current.destination, "PT24H") > 10
   and amount > 100

  then review
       score   0.5
       reason  "High transaction frequency to the same destination in 24 hours"
}
```

### Average amount source

This rule reviews a source when its average transaction amount over a short window is unusually high. Use `avg` when the mean value matters more than the total.

```bash AverageAmountSource.ws theme={"system"}
rule AverageAmountSource {
  description "Flags sources whose average amount spikes over 30 seconds."

  when avg(amount when source == $current.source, "PT30S") > 2000

  then review
       score   0.6
       reason  "Average amount from the source is unusually high"
}
```

### Max amount source

This rule reviews a source when any single related amount in the window exceeds a ceiling. Use `max` for peak-value checks without summing everything.

```bash MaxAmountSource.ws theme={"system"}
rule MaxAmountSource {
  description "Flags sources that send a peak amount above the threshold in 10 minutes."

  when max(amount when source == $current.source, "PT10M") > 10000

  then review
       score   0.7
       reason  "Peak amount from the source exceeds the threshold"
}
```

### Min amount destination

This rule reviews a destination when the smallest related amount in the window falls below a floor. Use `min` for unusually small transfers into an endpoint that normally sees larger values.

```bash MinAmountDestination.ws theme={"system"}
rule MinAmountDestination {
  description "Flags destinations whose minimum amount in one hour is below the floor."

  when min(amount when destination == $current.destination, "PT1H") < 2000

  then review
       score   0.4
       reason  "Minimum amount to the destination is below the expected floor"
}
```

### Low KYC daily total

This rule reviews a tier-1 customer when their cumulative outbound amount in the last 24 hours crosses a threshold. It is a common companion rule to per-transaction limits because structuring often happens through many smaller transfers.

```bash LowKycDailyTotal.ws theme={"system"}
rule LowKycDailyTotal {
  description "Flags low-tier KYC customers that exceed a 24-hour total threshold."

  when metadata.kyc_tier == 1
   and sum(amount when source == $current.source, "PT24H") > 5000

  then review
       score   0.5
       reason  "Total transacted amount exceeds the tier-1 threshold"
}
```

### Rapid small burst

This rule reviews a source when several small transactions happen in a short period. It is a useful anti-structuring pattern because bad actors often split activity into smaller amounts to avoid single-transaction thresholds.

```bash RapidSmallBurst.ws theme={"system"}
rule RapidSmallBurst {
  description "Flags bursts of small transactions from the same source."

  when amount < 500
   and count(when source == $current.source, "PT30M") >= 5

  then review
       score   0.65
       reason  "Rapid succession of small transactions from the same source"
}
```

### Repeated identical amount

This rule reviews transactions when the same amount repeats several times within an hour. It is a simple pattern for catching scripted behavior, installment abuse, or naïve structuring attempts.

```bash RepeatedIdenticalAmount.ws theme={"system"}
rule RepeatedIdenticalAmount {
  description "Flags repeated transactions with the same amount within one hour."

  when count(when amount == $current.amount, "PT1H") > 2

  then review
       score   0.6
       reason  "Multiple identical-amount transactions in a short period"
}
```

### Repeated identical amount 2

This rule reviews a source when both the transaction count and the repeated amount count stay elevated across a full week. It is a broader pattern for detecting repeated payment habits that may not look suspicious in a shorter window.

```bash RepeatedIdenticalAmount2.ws theme={"system"}
rule RepeatedIdenticalAmount2 {
  description "Flags repeated identical-amount activity from the same source over seven days."

  when count(when source == $current.source, "P7D") >= 3
   and count(when amount == $current.amount, "P7D") >= 3

  then review
       score   0.55
       reason  "Repeated identical-amount transactions detected from the same source"
}
```

### Source high outflow

This rule reviews a source account once its total outflow in the last 24 hours becomes unusually high. It works well as a general-purpose velocity control for wallets, current accounts, or card programs.

```bash SourceHighOutflow.ws theme={"system"}
rule SourceHighOutflow {
  description "Flags sources with high cumulative outflow over 24 hours."

  when sum(amount when source == $current.source, "PT24H") > 5000

  then review
       score   0.5
       reason  "High cumulative outflow from the source in 24 hours"
}
```

***

See also [Setting conditions](/watch/rules/setting-conditions) (aggregate conditions) and [Defining verdicts](/watch/rules/defining-verdicts).

***

## Need help?

We are very happy to help you make the most of Blnk, regardless of whether it is your first time or you are switching from another tool.

To ask questions or discuss issues, please [contact us](mailto:support@blnkfinance.com) or [join our Discord community](https://discord.gg/7WNv94zPpx).

<CtaCallout title="Connect your ledger to Blnk Cloud" href="https://cloud.blnkfinance.com/auth/sign-up?utm_source=blnk_docs&utm_medium=documentation&utm_campaign=need-help" buttonLabel="Open Blnk Cloud" trackingEvent="clicked_cloud_signup">
  Sign up and manage your ledger with our back-office dashboard. You can invite teammates to collaborate and manage your ledger operations directly from the dashboard.
</CtaCallout>

<RelatedTopics
  items={[
{ title: "Basic conditions", href: "/watch/rules/examples/basic-conditions" },
{ title: "Time-based conditions", href: "/watch/rules/examples/time-based-conditions" },
{ title: "Setting conditions", href: "/watch/rules/setting-conditions" },
]}
/>
