Sanctions Update Alert — Watchlist Change Monitor
Pricing
from $8.50 / 1,000 delivered sanctions watch evidence rows
Sanctions Update Alert — Watchlist Change Monitor
Monitor buyer-authorized names against complete current OFAC SDN and EU consolidated exports. Establish one persistent baseline per watch, then receive only reviewable new or changed potential matches with source hashes, confidence, gaps, manual action and reconciled billing state.
Pricing
from $8.50 / 1,000 delivered sanctions watch evidence rows
Rating
0.0
(0)
Developer
Tim Zinin
Maintained by CommunityActor stats
0
Bookmarked
2
Total users
1
Monthly active users
12 days ago
Last modified
Categories
Share
Sanctions Update Alert — evidence-first watchlist change monitor
Watch buyer-authorized person or organization names against current OFAC SDN and EU consolidated exports, preserve one account-scoped baseline per watch, and receive only reviewable baseline, new-hit, changed-hit, disappearance, or operational evidence. This Actor is a deterministic screening monitor, not an identity-verification service and not a legal conclusion.

What you get
Each run belongs to one persistent watch_name. The runtime serializes runs for that watch, loads the official source exports, proves conservative size and parsed-record minimums, screens the normalized unique names, compares the complete observation with the last committed baseline, and emits evidence that can be reviewed without guessing what happened during delivery.
- A first-run baseline row that records how many potential hits were observed.
- One paid result candidate for each delivered new or materially changed potential hit.
- Free Dataset notices for no change, disappeared hits, source incompleteness, pricing failure, budget stop, or runtime failure.
- Stable entity identifiers where the official export provides them.
- Observed source URL, final HTTPS origin/path with temporary query credentials removed, response bytes, body SHA-256, ETag, Last-Modified value, parsed-record count, completeness flag, and error.
- A conservative decision layer with freshness, confidence basis, gaps, recommended action, priority,
safeToAutomate:false, failure diagnostics, and settlement-neutral billing intent. - A current-run KVS
OUTPUTreceipt with requested, unique, duplicate, successful, failed, delivered, paid, free, withheld, partial, budget, fatal, and replay facts. - Exact named
result-foundcounter evidence for every paid row. - A durable per-watch lock and delivery journal so overlapping runs cannot both advance the same baseline.
The Actor deliberately does not decide whether a person or organization is the listed party. A token match is an investigation signal. A reviewer must open the cited official record, examine identifiers and context, resolve aliases and transliteration, and apply the organization’s own legal process.
Who uses it
The intended users are compliance operations teams, vendor-onboarding teams, procurement controls, marketplace trust teams, internal audit, risk operations, and engineering teams that already own a lawful screening purpose and a human review process.
Good uses include monitoring a stable vendor roster, producing a change queue for an internal review desk, preserving evidence for an audit trail, and separating newly observed potential matches from a large unchanged baseline. The Actor is especially useful when repeatedly exporting a full fuzzy-match table would overwhelm reviewers with unchanged rows.
Do not use it to make an autonomous account closure, payment hold, hiring, travel, medical, credit, insurance, immigration, law-enforcement, or other high-impact decision. Do not submit names you are not authorized to process. Do not treat a common-name match, disappearance, score, program string, or sourceComplete:true flag as proof of identity, innocence, guilt, legality, or current sanctions status outside the exact observed source files.
How to run
- Choose one narrow operational purpose and one durable
watch_name. - Submit 1–100 names that you are authorized to screen.
- Start with
minScore: 0.8; lower it only when your reviewers can absorb more false positives. - Set
max_itemsto the maximum number of paid baseline/new/changed result rows that the run may intentionally deliver. - Run once to establish the baseline. A baseline row is a paid commercial result because it creates the reference state required by the monitor.
- Schedule later runs with the same normalized watch name.
- After every terminal run, read KVS key
OUTPUTand requireOUTPUT.runIdto match the platform run. - Reconcile Dataset length,
result-foundcounters, source evidence, baseline revision, and terminal state before routing a review ticket. - If delivery or settlement is unknown, preserve the original run and do not blind-retry it.
{"names": ["Yevgeniy Prigozhin", "Acme Trading LLC"],"minScore": 0.8,"watch_name": "daily-vendor-sanctions-watch","max_items": 20}
The public schema exposes watch_name and the explicitly labelled legacy baseline_key. Existing saved Tasks and API clients remain compatible when watch_name is absent. New integrations should use watch_name.

Pricing
The primary paid unit is one delivered sanctions watch evidence row: either the first complete baseline for a watch, one new potential hit, or one materially changed potential hit. The automatic Actor start event is separate. No-change, disappearance, source-incomplete, budget, pricing, lock, and failure notices do not intentionally emit result-found.
| Tier | Actor start | One delivered evidence row |
|---|---|---|
| FREE | $0.00500 | $0.01000 |
| BRONZE | $0.00475 | $0.00950 |
| SILVER | $0.00450 | $0.00900 |
| GOLD | $0.00425 | $0.00850 |
| PLATINUM | $0.00410 | $0.00820 |
| DIAMOND | $0.00400 | $0.00800 |
At FREE-tier event prices, one baseline or changed-hit row plus start is $0.015 before compute and storage. At DIAMOND event prices it is $0.012. The live pricing panel is authoritative for the buyer’s current tier.
Before paid work, runtime requires an exact approved paired tier, no unknown event, an optional Dataset event priced at exact numeric zero, a readable current spend that already includes the start event, sufficient charge cap, and a named result counter equal to the number of already confirmed paid rows. A linked Dataset push is paid only when the named counter advances exactly by one and the aggregate receipt is bounded and well formed.
The Dataset row carries billing eligibility and intent, never settlement proof. KVS OUTPUT is authoritative for paid, free, anomalous, or unknown settlement. A returned push with no named increment is a known free delivery. A thrown push is unknown Dataset delivery. A returned push with unreadable settlement is a known Dataset write with unknown settlement. None of those uncertain paths is retried automatically.
Input contract
| Field | Required | Boundary |
|---|---|---|
names | Yes | 1–100 strings, each 1–160 characters after NFC normalization and trim. Controls are rejected. Case-insensitive whitespace-normalized duplicates collapse to the first spelling. |
minScore | No | Finite number from 0 to 1; default 0.5. It is query-token coverage, not probability or identity confidence. |
watch_name | No | 1–120 nonblank characters; default default. Same normalized value shares baseline state. |
baseline_key | No | Deprecated compatibility alias with the same bounds. Used only when watch_name is absent. |
max_items | No | Integer 1–200; default 20. Caps paid baseline/new/changed deliveries, not free notices. |
Unknown top-level fields, non-string names, empty arrays, whitespace-only values, control characters, non-finite numbers, fractional limits, and out-of-range values fail closed before source or paid work. Runtime does not stringify arbitrary objects.
Names and watch identifiers are stored in the run INPUT and can appear in Dataset, baseline, journal, and OUTPUT records. Do not place API keys, credentials, signed URLs, health details, confidential investigations, protected-class notes, or unrelated personal data in these fields. Configure Apify storage access and retention for the lawful purpose, and delete state when the watch is no longer needed.
Happy, partial, and failure output
A first complete local acceptance produces one paid baseline candidate, one exact result-found increment, a committed baseline revision, and a current-run receipt. The wrapper below names the checked local contract; the production acceptance replaces its IDs with the actual immutable build and no-retry canary evidence.
{"runId": "local-sanctions-baseline-acceptance","buildId": "local-contract-0.2.0","status": "SUCCEEDED","evidenceAccepted": true,"output": {"actor": "sanctions-update-alert","watchName": "daily-vendor-sanctions-watch","replaySafe": false,"counts": {"requestedNames": 1,"uniqueNames": 1,"duplicateNames": 0,"successfulNames": 1,"failedNames": 0,"unprocessedNames": 0,"attemptedPaidRows": 1,"deliveredRows": 1,"paidRows": 1,"freeRows": 0,"localNonMonetizedRows": 0,"unchargedAttemptedRows": 0,"withheldRows": 0,"unknownDeliveryRows": 0,"unknownSettlementRows": 0,"anomalousSettlementRows": 0},"delivery": {"resultEvent": "result-found", "resultCountBefore": 0, "resultCountAfter": 1, "exactPaidDelta": 1},"terminal": {"outcome": "SUCCEEDED", "failureStage": null, "primaryKvsWrite": "confirmed", "recoveryKvsWrite": "not_attempted", "exit": "requested"}}}
A later complete no-change acceptance writes one free notice, advances the observation timestamp without inventing a paid change, and is safe with respect to result delivery. A new platform run still has its own automatic start event.
{"runId": "local-sanctions-no-change-acceptance","buildId": "local-contract-0.2.0","status": "SUCCEEDED","evidenceAccepted": true,"output": {"actor": "sanctions-update-alert","watchName": "daily-vendor-sanctions-watch","replaySafe": true,"counts": {"requestedNames": 1,"uniqueNames": 1,"duplicateNames": 0,"successfulNames": 1,"failedNames": 0,"unprocessedNames": 0,"attemptedPaidRows": 0,"deliveredRows": 1,"paidRows": 0,"freeRows": 1,"localNonMonetizedRows": 1,"unchargedAttemptedRows": 0,"withheldRows": 0,"unknownDeliveryRows": 0,"unknownSettlementRows": 0,"anomalousSettlementRows": 0},"delivery": {"resultEvent": "result-found", "resultCountBefore": null, "resultCountAfter": null, "exactPaidDelta": null},"terminal": {"outcome": "SUCCEEDED", "failureStage": null, "primaryKvsWrite": "confirmed", "recoveryKvsWrite": "not_attempted", "exit": "requested"}}}
PARTIAL means some intended change rows were withheld by max_items or budget after confirmed work. SOURCE_INCOMPLETE means the official source observation did not meet the completeness contract; the baseline is not changed. DELIVERY_UNKNOWN means the linked push threw and Dataset delivery cannot be claimed. SETTLEMENT_UNKNOWN means the Dataset write returned but settlement could not be read. SETTLEMENT_ANOMALY means the observed counter/receipt combination contradicted the expected result. RECOVERED means an earlier confirmed delivery’s pending baseline was durably completed without another paid push.
Field dictionary
| Field | Meaning and boundary |
|---|---|
recordType | Stable row identity sanctions_update_alert. |
baselineKey | Preserved legacy output key; equals normalized watchName. |
watchName | Current public watch identifier. |
found | True for baseline/new/changed result candidates; false for operational notices. It is not a settlement claim. |
changeType | new-hit, changed-hit, or null. A disappearance is a free notice, not a paid negative result. |
baselineCreated | True only for the initial complete reference observation. |
name | Buyer-submitted screened name. Null on watch-level rows. |
entityId | Official-list identifier when supplied by the source export. |
entityName | Canonical listed name selected from the observed export. |
matchedName | Exact primary or alias string that produced the best retained token score. |
matchedNameType | primary or alias where the parser can distinguish it. |
listName | OFAC SDN or EU Consolidated. |
program | Source-provided sanctions program string; not normalized into legal advice. |
score | Fraction of query tokens present in the candidate name, rounded to three decimals. Not probability. |
sourceComplete | True only when every required source evidence item is complete for this run. |
sourceEvidence | Fixed-source URL, query-redacted final HTTPS origin/path, bytes, SHA-256, cache headers, parsed count, completeness, and error. |
observedAt / checkedAt | UTC runtime observation timestamps. They do not prove the source’s legal effective time. |
freshness | Current-run observation status and basis. It is not a regulatory effective-date calculation. |
decision.confidence | requires_manual_review for potential-hit changes or informational for operational rows. |
confidenceBasis | Explicit token-overlap basis; never identity certainty. |
gaps | False-positive and later-source-change limitations that remain open. |
recommendedAction | Manual source-record review or continued monitoring. |
priority | manual_review or informational. |
safeToAutomate | Always false for the compliance decision. Storage and ticket creation may be automated separately. |
failureDiagnostics | Code, message, and stage for an operational failure row; null on normal rows. |
billing | Settlement-neutral eligibility, intent, event, unit, and current-run OUTPUT authority. |
OUTPUT.counts | Exact requested/unique/duplicate/success/failed/unprocessed and delivery settlement partition, including local free notices separately from uncharged paid attempts. |
OUTPUT.delivery.operations | Per-attempt operation ID, state, named counters, and bounded aggregate receipt. |
OUTPUT.baseline | Revision before/after, whether it advanced, and whether it was recovered. |
OUTPUT.run | Normalized run-level work and delivery totals plus partial/budget/fatal flags. |
OUTPUT.terminal | Outcome, failure stage, primary/recovery KVS write state, and requested/failed exit. |
OUTPUT.replaySafe | False after any uncertain or confirmed paid push; true only when no paid result retry is at risk. |
Evidence and boundaries
The runtime retrieves four fixed official exports: OFAC SDN primary names, OFAC ALT aliases, OFAC ADD addresses for best-effort disambiguation, and the EU consolidated financial-sanctions CSV. It does not accept source URLs, credentials, cookies, browser sessions, proxies, or redirects to buyer-controlled hosts.
Completeness is fail-closed for the match-bearing sources. OFAC primary and alias bodies must exceed conservative byte and parsed-record minimums. The EU export must contain the expected columns and exceed its byte and parsed-name minimums. An HTTP 200 empty ALT file or header-only EU file is incomplete, not a clean negative. A missing ADD address file reduces disambiguation context but cannot hide a name match, so it is not by itself a match-completeness failure.
The SHA-256 in sourceEvidence is calculated over the body observed by this run. It is an integrity fingerprint for reconciliation, not a cryptographic verification against a publisher-signed digest. ETag and Last-Modified are copied when present and are not treated as guarantees.
Matching normalizes Unicode, removes diacritics, uppercases, tokenizes letters and numbers, and scores candidate names by query-token coverage. A single-token query found inside a longer listed name can score 1.0. That deliberate review bias can produce many false positives. The Actor does not use dates of birth, passports, ownership chains, citizenship, geographic context, or adverse-media evidence to verify identity.
Source completeness does not mean worldwide sanctions completeness. This product covers only the named OFAC SDN and EU exports observed at run time. It does not include every national list, sectoral rule, ownership rule, general licence, interpretive guidance, enforcement notice, or later correction.
Decision routing
| Evidence state | Human route | Do not infer |
|---|---|---|
| Baseline created | Review the initial candidate set and approve the watch definition. | Not a new designation event. |
| New potential hit | Open the official record and resolve identity and context. | Not proof the buyer’s subject is sanctioned. |
| Changed potential hit | Compare prior/current source fields and review the entity. | Not proof legal status became stricter. |
| Disappeared hit | Review prior/current official records and query sensitivity. | Not proof of delisting or clearance. |
| No change | Retain the accepted receipt and continue the cadence. | Not proof that no relevant sanctions changed elsewhere. |
| Source incomplete | Stop the compliance route; preserve the free notice and evidence. | Never convert to no match. |
| Budget or max-items partial | Review delivered rows and explicitly schedule remaining work. | Do not call the watch complete. |
| Unknown delivery/settlement | Freeze automatic retry and reconcile the original run. | Never assume paid, free, delivered, or absent. |
| Fatal pre-delivery failure | Correct the explicit problem and intentionally start a new run. | Do not assume the start event was refunded. |
Every business row has safeToAutomate:false. A downstream system may automate record storage, ticket creation, notifications, or assignment, but the identity and compliance decision stays with an authorized reviewer.
Commercial playbooks
Vendor onboarding watch
Use a stable watch for an authorized vendor roster. Review the baseline, then route only new/changed candidates. Keep procurement approval separate from the Actor signal.
Daily counterparty control
Schedule one run per watch after defining the source scope, reviewer, escalation path, and retention period. Store the run ID and OUTPUT alongside review tickets.
Alias-sensitive monitoring
Keep OFAC alias completeness visible. If ALT is incomplete, stop; do not accept primary-only screening as equivalent coverage.
Change investigation
For a changed score, program, or matched alias, compare the exact prior and current evidence. A score can change because the source spelling changed, not because legal status changed.
Disappearance review
A disappeared candidate is free and informational. Confirm the source record and query definition before clearing an alert.
Portfolio operations
Use separate watch names for separate purposes or teams. Never overload one baseline with unrelated names or silently change the screening threshold without documenting the series break.
Manual reconciliation
When replay safety is false, preserve the original run, build, Dataset, KVS, source hashes, operations, counters, and logs. Do not create a second paid attempt until the first state is understood.
Audit export
Store Dataset evidence separately from OUTPUT run facts. Join by run ID, watch name, timestamps, and baseline revisions; do not flatten null into zero.
For every playbook, assign an owner, lawful purpose, review SLA, escalation rule, source scope, watch definition, maximum paid rows, retention date, and deletion process before scheduling recurring spend.
Integration recipes
Apify API
curl -sS -X POST \"https://api.apify.com/v2/acts/zinin~sanctions-update-alert/runs?maxTotalChargeUsd=0.015" \-H "Authorization: Bearer $APIFY_TOKEN" \-H "Content-Type: application/json" \--data-binary @examples/input.json
Poll only the returned run ID. When terminal, fetch its default KVS OUTPUT and Dataset. Require current-run binding and reconcile counts before routing evidence.
JavaScript
import { ApifyClient } from 'apify-client';const client = new ApifyClient({ token: process.env.APIFY_TOKEN });const input = { names: ['Yevgeniy Prigozhin'], minScore: 0.8, watch_name: 'vendor-daily', max_items: 1 };const run = await client.actor('zinin/sanctions-update-alert').call(input, { maxTotalChargeUsd: 0.015 });const output = await client.keyValueStore(run.defaultKeyValueStoreId).getRecord('OUTPUT');if (!output?.value || output.value.runId !== run.id) throw new Error('Missing or unbound OUTPUT');const { items } = await client.dataset(run.defaultDatasetId).listItems();console.log({ output: output.value, rows: items });
Python
import osfrom apify_client import ApifyClientclient = ApifyClient(os.environ['APIFY_TOKEN'])actor_input = {'names': ['Yevgeniy Prigozhin'], 'minScore': 0.8, 'watch_name': 'vendor-daily', 'max_items': 1}run = client.actor('zinin/sanctions-update-alert').call(run_input=actor_input, max_total_charge_usd=0.015)record = client.key_value_store(run['defaultKeyValueStoreId']).get_record('OUTPUT')if not record or record['value'].get('runId') != run['id']:raise RuntimeError('Missing or unbound OUTPUT')rows = list(client.dataset(run['defaultDatasetId']).iterate_items())print({'output': record['value'], 'rows': rows})
Webhook and warehouse
Trigger only after terminal platform status. Read OUTPUT first, then Dataset. Store work counts, delivery settlement, source hashes, baseline revisions, and review outcome in separate normalized tables. Preserve the raw evidence row for audit rather than rebuilding it from a human summary.
Agent workflow
An agent may create a review ticket containing the candidate, source evidence, gaps, and recommended action. It must not close the ticket, clear a counterparty, freeze funds, or represent the output as legal advice. Keep safeToAutomate:false in every routed payload.
Operating guide
Before launch, define the watch owner, lawful purpose, exact roster source, watch_name, score threshold, run cadence, charge cap, reviewer queue, escalation policy, retention, and deletion. Run one bounded acceptance and verify the intended immutable build, source evidence, Dataset row, KVS receipt, named counter, aggregate receipt, baseline revision, and platform status.
During operation, monitor source completeness, parsed-record counts, source body hashes, requested/unique names, duplicates, current/new/changed/disappeared hits, free notices, withheld rows, unknown delivery, unknown settlement, anomalies, baseline revision, lock failures, KVS writes, and duration. A large source-count discontinuity should halt review automation even when byte minimums pass.
Keep the same names, threshold, and watch purpose when comparing a series. If those definitions change materially, start a new watch rather than making incomparable observations look continuous. Case-insensitive duplicate names collapse; the first submitted spelling is kept for display.
The watch lock is account-scoped and prevents two overlapping runs from buying and committing the same revision. The delivery journal is keyed by watch, baseline revision, and canonical input digest. Confirmed delivery is journaled before baseline advancement. If baseline persistence fails after paid delivery, the next run completes the pending baseline instead of buying the same change again.
Acceptance checklist
Require the same immutable build and run across every check: build status SUCCEEDED; platform run terminal; OUTPUT.runId equals platform run ID; source evidence contains the expected complete fixed sources; Dataset length equals the OUTPUT delivered partition; requested equals unique plus duplicate; successful plus failed plus unprocessed equals unique; free equals local non-monetized plus uncharged attempted rows; delivered equals paid plus free plus unknown-settlement plus anomalous-settlement; attempted paid equals paid plus uncharged-attempted plus unknown-delivery plus unknown-settlement plus anomalous-settlement; result counters advance exactly once per paid row; no paid default Dataset event exists; baseline advanced only after safe delivery state; KVS primary or recovery write is confirmed; and logs contain no unexpected error, exception, timeout, schema, pricing, or source marker.
For the row itself, require legacy baselineKey and current watchName to agree; sourceComplete true for a paid candidate; entity ID/name/list consistent with source evidence; score within 0–1; decision safeToAutomate false; recommended action manual; billing settlementSource current-run KVS OUTPUT; and no failure diagnostics on a normal paid row.
Incident response
Preserve the original run ID, build ID, Dataset ID, KVS ID, watch name, input digest, baseline revisions, journal state, source hashes, timestamps, operations, named counters, aggregate receipt, logs, and terminal OUTPUT. Unknown delivery means the linked push threw. Unknown settlement means the push returned but settlement could not be read. An anomaly means observable facts contradicted the exact paid/free lattice. None authorizes a blind second run.
For a pre-delivery input, pricing, budget, lock, source, baseline-read, or journal-write failure, correct the explicit cause and start a new intentional run only when OUTPUT says replay-safe. The automatic start event is separate and may already have occurred.
FAQ
Is a match a legal sanctions determination?
No. It is a token-overlap candidate requiring manual identity and legal review.
Is score a probability?
No. It is the fraction of normalized query tokens present in a listed name. One token inside a longer name can score 1.0.
Why is the first baseline paid?
It creates the delivered reference evidence required for all later change-only monitoring. Later no-change and disappearance notices remain free of result-found.
Why can a disappearance be free?
It is informational negative movement, not a newly delivered risk candidate. It still requires review before clearing anything.
What happens when a source returns HTTP 200 but no useful data?
Conservative byte and record-count checks reject empty or implausibly small match-bearing sources. The run emits a free source-incomplete notice and does not advance the baseline.
Does sourceComplete mean every sanctions regime is covered?
No. It means only that the required OFAC SDN and EU export contracts for this product passed during the current run.
Are OFAC addresses required?
No. ADD.CSV is best-effort disambiguation context. Primary and alias name coverage drives the OFAC match-completeness gate.
What creates a paid row?
One first baseline, new potential hit, or changed potential hit returned by a linked Dataset push with exact named +1 settlement proof.
Can overlapping schedules double-charge one change?
The durable per-watch lock serializes the baseline revision. The journal protects delivery-before-baseline ordering and prevents automatic replay of an unresolved attempt.
What does replaySafe mean?
It describes whether retrying the result delivery is safe. It does not mean a new Actor run avoids the automatic start event.
What if OUTPUT is missing?
Treat the run as unreconciled. Do not infer success or settlement from a Dataset row or platform label alone.
Can I put customer or employee names in the input?
Only when you have a lawful purpose and authorization. Names persist in Apify storage and monitor state. Apply access, minimization, retention, deletion, and human-review controls.
Does the Actor verify beneficial ownership or the OFAC 50 Percent Rule?
No. It screens observed list-name strings. Ownership analysis and legal interpretation are out of scope.
Can I automate blocking a payment?
No. safeToAutomate is false. Automate evidence routing, not the high-impact decision.
Sources and rights
The runtime uses fixed public files published by the U.S. Department of the Treasury Office of Foreign Assets Control and the European Commission’s consolidated financial-sanctions resources. It does not fetch arbitrary URLs, accept source credentials, scrape search pages, or resell a private provider API.
OFAC’s Sanctions List Service publishes the SDN data formats and related list resources. The EU Commission publishes consolidated sanctions resources for operational access. Public availability supports observation, but buyers remain responsible for current official terms, attribution expectations, lawful purpose, data-protection duties, and any downstream redistribution constraints that apply to their use.
The Actor transforms bounded official-list name records into a buyer-specific change signal. It does not republish a complete source database as the commercial result. Source URLs, observed hashes, counts, and errors remain visible so the buyer can review what the run actually used.
Official list data can change, be corrected, lag legal instruments, contain aliases and transliterations, or require interpretation with regulations, licences, ownership rules, and guidance. Always open the authoritative record and applicable legal materials before acting. Nothing here is legal advice, an official screening certificate, or a guarantee of completeness, accuracy, identity, or current legal status.
The buyer remains responsible for rights to submit names, notice and lawful basis where required, access control, retention, deletion, correction requests, downstream sharing, and human decision-making. Do not use the product for harassment, profiling unrelated to a lawful purpose, protected-trait inference, covert surveillance, or automatic adverse action.
Before adopting the monitor, record the exact source URLs, intended jurisdictional scope, reviewer qualifications, escalation owner, retention period, and authoritative materials that govern the organization’s decision. Revisit that record whenever OFAC or the European Commission changes file formats, distribution routes, update practices, or guidance. If an official route is unavailable or its observed body fails the completeness contract, the correct result is an incomplete-source notice—not a reconstructed list, cached legal conclusion, or silent fallback to an unofficial mirror.
The Store description and examples describe this Actor’s technical behavior only. They do not grant permission to process a particular person, satisfy a notice requirement, transfer the publisher’s authority, or replace counsel and compliance controls. Keep every downstream copy linked to its run, timestamp, watch, source evidence, and manual disposition so later reviewers can distinguish the Actor’s observation from the organization’s decision.