The organised patterns a single claim never reveals. Clusters are computed in SQL over the live claim graph — one customer claiming across several policies, claims co-occurring by branch and period, providers concentrating on one payer. The model can write the SIU memo for a cluster; it does not decide what a cluster is.
Customers with three or more claims across two or more policies — the hub-and-spoke signature. Each is a hypothesis for the SIU, not an accusation.
Three or more claims from different customers at the same branch, in the same month, in the same amount band. Sparse in synthetic data by construction — the engine reports what it finds.
Providers with 15+ claims where one payer accounts for more than 30% of them — the concentration pattern behind provider collusion.
Live rows: 85 claims in hubs read from demo_bfsi + demo_health in PostgreSQL at request time. These are genuine records with genuine structure, but they are synthetic demo data, not Generali Central's book — status distributions are near-uniform, and person, provider, branch and payer names are localised to Indian display names at read time. Scores demonstrate the scoring mechanism, not predictive performance. The reconciled ₹5,548 Cr figures elsewhere in this cockpit come from the governed SQLite book.