Risk Levels
Risk level is a fixed set. Every response that carries one uses these values and no others, so you can branch on them safely.
A level is a band, not a verdict. It summarises how severe the underlying intelligence source rated the subject; it is not a statement that AlphaToken KYT verified any particular activity. Decide for yourself which bands block, which ones route to review, and which ones pass.
| Value | Level | What it means |
|---|---|---|
RISK_LEVEL_CRITICAL | Critical | Top of the severity range — the strongest risk indicators an intelligence source reports for this subject. |
RISK_LEVEL_HIGH | High | Strong risk indicators, one band below critical. |
RISK_LEVEL_MEDIUM | Medium | Mid-range indicators: worth a look, not conclusive. |
RISK_LEVEL_LOW | Low | No significant risk indicators. Subjects a source lists as trusted also land here. |
Two values that are not the same
These two look interchangeable and are not. Treating either one as “no risk” is the mistake this section exists to prevent.
RISK_LEVEL_UNKNOWN— a level could not be established. That covers a source value we do not recognise, and it covers data we could not obtain at all. It does not tell you that the subject was screened, so do not record it as a completed screening.RISK_LEVEL_UNSPECIFIED— the field carries no value. Read it as absent: the response says nothing about this subject’s level, one way or the other. It is not a claim about what was or was not screened.
If you need to distinguish “we have an answer and it is inconclusive” from “we could not get data,” do not infer it from the level — neither value carries that distinction.