Runtime and Sift
Runtime vs Sift: Sift scores fraud and decides in real time. Runtime agents work the review queue Sift creates, investigating across ledger, processor, and tickets, then write the decision back.
TL;DR: Sift and Runtime do different jobs. Sift scores events and automates fraud decisions using its global data network. Runtime agents investigate the cases Sift sends to manual review, across your ledger, processor, and tickets, and write the decision back to Sift with a person approving.
| Feature | ||
|---|---|---|
| Core job | Investigate and act on cases | Score and decide on events |
| Fraud scoring | Uses your Sift score | Real-time ML risk scores |
| Network data | Your systems and shared org memory | 1 trillion+ events a year |
| Rules and automated decisions | Approvals before money moves | Decisioning engine and workflows |
| Manual review | Agents draft decisions with evidence | Console, queues, ActivityIQ summaries |
| Data it reads | Ledger, processor, bank files, tickets, Sift | Events you send to Sift |
| Teams covered | Risk, payment ops, finance, support, more | Fraud and trust and safety |
| Where it runs | Your cloud, or self-hosted | Sift-hosted |
| Pricing | Free, Teams from $99/seat/month | Not published |
Sift and Runtime get compared because both use AI on fraud. They do different jobs, and a team running Sift does not need to replace it to use Runtime. Sift decides whether an event is risky. Runtime agents do the investigation and follow-up that a person would otherwise do after Sift flags it.
What each does
Sift is a fraud decisioning platform. Its products are Payment Protection and Account Defense, with the Sift Score API for teams that bring Sift's signals into their own models. Sift scores events in real time using a network it says processes more than 1 trillion events a year, and its decisioning engine lets teams set thresholds, workflows, and friction. Cases that need judgment go to analysts in the Sift Console, where ActivityIQ summarizes user activity and the newer Attack Detection Agent groups attacks into investigations. Sift lists fintech customers such as Remitly and CoinJar.
Runtime is the AI agent harness for payment and fintech teams. Anyone on risk, payment ops, finance, compliance, or support builds agents from their SOPs. Agents work on their own isolated computers in your cloud and reach your tools through APIs, databases, CLIs, MCP servers, and a browser for portals with no API. They start read-only, stop for approval before anything moves money, and record every run end to end.
Where they overlap
Be honest about the overlap: both help a fraud team spend less time on manual review.
- Sift reduces how many cases need review. Better scores and rules mean more events are accepted or blocked automatically.
- Sift helps analysts review faster. ActivityIQ summaries and attack grouping speed up work inside the console.
- Runtime does the review work itself. An agent gathers the evidence, applies your SOP, and drafts the decision.
If every case can be decided from what Sift already sees, Sift's own tools may be enough. The gap opens when the answer sits in systems Sift never receives: the ledger, the processor, bank files, the support history, or a sponsor bank's request.
How they work together
A typical flow for a payment or account case that Sift sends to review:
- Sift scores the event. Low-risk events pass, high-risk events are blocked, and the rest go to a review queue.
- A Runtime agent picks up the case. A Sift webhook or the queue itself triggers the agent, which pulls the user, the score, and the event history from Sift.
- The agent investigates outside Sift. It checks the transaction in the processor, the balance and prior entries in the ledger, open support tickets, past chargebacks, and anything the company already learned about similar cases.
- It drafts a decision with evidence. Accept, block, or hold, with the reasoning and the data behind it, written the way your SOP asks.
- A person approves in Slack or Teams. Anything that moves money, such as releasing a held payout or applying a reserve, waits for sign-off.
- The agent writes back. It applies the decision in Sift through the Decisions API, updates the ticket, and notifies the team that needs to know.
- The full record is kept. The trigger, every query and tool call, the approval, the cost, and the result are stored and exportable for your sponsor bank or an auditor.
The same case often touches more than fraud. If the blocked payment was a customer's payout, support has a ticket and finance has a break. On Runtime that is one investigation with one record, not three separate ones.
What changes for the fraud team
- Sift stays the source of truth for risk. Scores, rules, and decisions still live in Sift. The agent reads them and writes back to them.
- Analysts review drafts, not raw cases. Each case arrives with the evidence already gathered from systems Sift does not see, and the analyst approves, edits, or rejects.
- Your SOP sets the rules. The agent follows your written procedure, starts read-only, and only takes the actions you allow. Once a pattern is solved, it can become a deterministic script that lives in your repo.
- The memory compounds. Every resolved case, including the false positives, becomes context the next agent run can use, for fraud and for the other teams on Runtime.
When you need both
- Your Sift review queue keeps growing and you are about to hire more analysts
- Reviewers routinely leave the Sift Console to check the ledger, processor, or help desk
- Fraud cases spill into support, payment ops, or finance work
- You need approvals and a full run record before any payout is released or reserve applied
- Case data has to stay in your cloud, with your choice of models
When Sift alone is enough
- Most decisions are automated by Sift's scores and rules
- Manual review volume is small and stable
- Reviewers can decide a case from what Sift already sees
- Fraud is the only team you want to change right now
Put an agent on your Sift review queue
Bring one SOP. A forward-deployed AI engineer builds the first agent with your team, inside your cloud.
Frequently asked questions
Is Runtime an alternative to Sift?
No. Sift scores events for fraud risk and automates decisions using data from its global network. Runtime does not score fraud. Runtime agents work the cases Sift routes to manual review and the follow-up work across other teams.
How does Runtime connect to Sift?
Through Sift's APIs. Sift can notify your systems of decisions with webhooks, and decisions can be applied to users and orders through its Decisions API, so a Runtime agent can pick up a case, investigate it, and write the approved decision back.
Does Sift have AI agents?
Sift has added AI to its console, including ActivityIQ, which summarizes user activity for investigators, and the Attack Detection Agent, the first part of its Fraud Attack Defense Suite, which detects and groups fraud attacks into investigations.
When is Sift alone enough?
When most decisions are automated by Sift's scores and rules, manual review volume is manageable, and reviewers rarely need data outside Sift's console to decide a case.
Is Sift pricing public?
No. Sift does not publish pricing; it is sold through sales. Runtime publishes its tiers: Free for one session, Teams from $99 per seat per month, and custom Enterprise pricing.
Related comparisons
Sardine vs Sift
Sardine vs Sift compared for fintech and payments: fraud scoring, AML and KYC coverage, AI agents, network data, and pricing. Plus where Runtime fits as the agent layer for every payment team.
Runtime vs Sardine
Runtime vs Sardine compared: Sardine is an agentic fraud and AML platform with ten risk agents. Runtime is an agent harness for every payment team, in your cloud. Where each fits, and how to run both.
Runtime vs Footprint
Runtime is one agent harness for every payment team, from risk to payment ops, finance, and support. Footprint is an identity and risk operations platform with AI agents for KYC, KYB, and fraud.
Runtime and Alloy
Runtime vs Alloy: Alloy orchestrates identity, KYC, KYB, and fraud decisions. Runtime agents work the manual review queue, re-reviews, and cross-team investigations around those decisions.