Sardine named a Leader in The Forrester Wave™: Financial Crime Management Solutions, Q3 2026

Learn More

Your AI agents shouldn't need someone to hit go

Headshot of a smiling woman with long blonde hair.
Annie Liegel
bg-image
bg-image
Illustration of Sardine's AI agents connected to a central hub and a clock, representing automated, scheduled fraud and compliance checks.
Subscribe to newsletter
Share

Fraud doesn't wait for your team to remember to check for it. Card testing starts at 2am. A sanctions list updates on a Sunday. A chargeback pattern builds for two weeks before anyone notices it's a pattern and not noise.

An AI agent that can investigate all of that only helps if someone opens the tool and asks it to. Most recurring work in a fraud or compliance team doesn't wait for a single trigger event, it runs on a clock: a daily check for new anomalies, a monthly review of a customer cohort, a weekly scan for card-testing patterns. Today, an analyst still has to remember to kick it off.

We're introducing Agent Routines, where users can schedule any Sardine AI agent to run on its own, on whatever cadence the task needs, like hourly, daily, monthly, or on demand. Then it delivers findings straight to your team, instead of waiting for someone to go looking.

Put recurring investigations on a schedule

Set up an agent, whether it's a built-in agent like the Data Analyst Agent, a Custom Risk Agent built around your own standard operating procedure, or anything else already running inside Sardine’s Agent Hub, and attach a schedule to it instead of running it by hand every time. A Routine can do whatever the underlying agent can already do. You’re simply deciding when it runs, whether that’s hourly, daily, monthly, or on another cadence, instead of waiting for someone to trigger it.

A few examples of what teams are running today:

  • A burst of small-dollar authorizations hits the same card at 2am. A routine catches the card-testing pattern before it turns into real fraud, instead of waiting for someone to notice it in the morning.
  • New chargebacks start concentrating in one channel. A scheduled agent flags the concentration the same day it starts, not two weeks later once it's already a trend.
  • The first of the month arrives. A routine runs your enhanced due diligence cohort and drops a report per entity in the inbox before anyone has to ask for it.
  • An analyst clears an alert as a false positive. The same agent re-checks it against new data later and applies the follow-up automatically if something's changed.

Findings land in a notification inbox, prioritized by severity, so your team reviews what actually needs attention instead of digging through raw output. Anyone on your team can still open a chat with the agent on anything it flags to ask follow-up questions or dig deeper.

None of this runs off to the side. A Routine wraps around agents that already sit inside Sardine, drawing on the same device, transaction, and identity signals your other agents use, so scheduling one doesn't mean standing up a separate tool or a separate data feed. Set it up once, and it's off your list for good.

Running an agent unattended is the hard part

Ask an agent to do the same open-ended task twice and it can take two different paths and land on two different answers. That's a reasonable trade-off in a chat window where someone is watching. It's not one you can make for a task that's supposed to run itself on a schedule.

Reliably scheduling an agent takes more than a cron job. Left to run on its own, an agent needs to carry context between runs, your policies, your business details, the things it would otherwise have to be re-told every time, instead of starting from zero. It needs governed access to the tools and data it's allowed to touch. And it needs a way to run unattended without losing the oversight that a regulated process requires.

Fraud detection interface displaying a bar chart showing nearly 1,000 customers linked to a single digital fingerprint, '5dc7...06b8', confirming suspicious activity. An AI chat input is at the bottom.

The architecture is designed around an agent harness that brings memory, tool access, and orchestration together. Rather than running an agent against a fixed script, the agent can determine which tools to use and which path to take, while the harness maintains the execution context and record needed to make each run traceable and repeatable.

We’re building this on the same class of open-source agent-harness components emerging across the AI ecosystem, adapted for fraud and compliance workflows. The focus is on the controls regulated teams require: tenant isolation, auditability, governed tool access, and human oversight, including for agents that run on a schedule.

Every scheduled run still follows the same governance model as an agent you'd run by hand: outputs are logged, evidence is cited, and higher-risk findings can be routed for mandatory human review rather than acted on automatically.

Some fraud and compliance teams are already building agents like this themselves, directly on a foundation model. That can work when a team has the engineering bandwidth to own it long term. What it doesn't come with on day one is years of fraud and compliance signal, the audit trail regulators expect, or a team that's already run agents like this in production. A Routine isn't a fresh prompt against a blank model, it's an agent working off the same device, transaction, and identity data Sardine's other agents already use, with tenant isolation and an audit trail built in from the start.

For your team, that means being able to point a routine at a queue you don't have time to watch yourself, and still know exactly why it flagged what it flagged.

If it doesn't hold up, it doesn't ship

Nothing here is a new category of work. It's automation for the cadence fraud and compliance teams already run manually: daily fraud-trend digests, weekly card-testing scans, monthly due diligence cohorts, periodic sanctions re-screening. All of it can run itself, with a human reviewing outcomes instead of triggering every step, alongside Sardine Flow and the rest of Sardine's agents on the same platform.

We run Routines against our own production traffic before we ship them to anyone else, the same categories of recurring review most fraud teams run by hand: traffic that's fallen off a cliff, chargebacks with a pattern behind them, card-testing attempts. If it doesn't hold up on our own book of business, it doesn't ship.

A review that used to depend on someone remembering to run it on a Friday afternoon now runs whether anyone's watching or not. The pattern that would have sat in a queue for two weeks gets flagged the day it starts.

Find out what's sitting in your queues right now, before it becomes next month's incident report. Contact us to set up your first Agent Routine.

What are Agent Routines?

Agent Routines let you schedule a Sardine AI agent to run automatically, hourly, daily, monthly, or on demand, instead of triggering it manually each time. Results are delivered to a notification inbox prioritized by severity.

How is this different from Sardine Flow?

They solve related but different problems. A Routine schedules a single agent to repeat a task on a cadence. Flow is the broader workflow layer for chaining multiple steps together, rules, agents, third-party data, and human review, into one process. A Flow step can also run on a fixed schedule, say, every 15 minutes, but that's a deterministic process repeating itself on a timer. A Routine is an agent deciding its own steps within a harness, on the cadence you set.

What is an "AI harness," and why does it matter?

An agent harness is the underlying layer that gives an AI agent memory across sessions, governed access to tools and data, and the ability to run reliably without a person driving every step. It's the difference between an agent that might take a different path each time you ask, and one that follows a documented process you can point to afterward. Ours is built on open-source agent-harness foundations, adapted for the auditability and human-oversight requirements of regulated fraud and compliance work.

Why build this on Sardine instead of a generic agent stack?

Because the data underneath matters as much as the model on top. A Routine runs on the same device, transaction, and identity signals already flowing through Sardine, with tenant isolation and audit logging built in, not a blank foundation model with a prompt in front of it.

Do scheduled agents run without human oversight?

No. Every Routine follows the same governance model as an agent run on demand: outputs are logged and evidence-cited, and higher-risk or ambiguous findings can be routed for mandatory human review rather than acted on automatically.

Is this available now?

Yes. Agent Routines and the underlying harness are live today across Sardine's AI agents.

How do I get started with Agent Routines?

Contact our team to set up your first scheduled agent, or reach out to your Sardine account team if you're already a customer.