Finance playbook · AI Employee: Fin

Card Lock & Lost Replacement

Card lock within 30 seconds of report

The problem

Card is lost, stolen, or compromised. Employee reports it to IT / finance, waits days for the block to happen, meanwhile potentially fraudulent charges accrue. Getting the replacement issued means another sequence of tickets, courier delays, and often flying blind for a week before the new card arrives. Every minute of delay is real money at risk.

At a glance
Trigger
Chat
Approvals
None (self-service)
What it does
Writes to your systems
Systems
Ramp · Brex
How it feels in production

An hour-by-hour walkthrough.

Priya messages Fin: "lost my Ramp card at the airport." Fin executes within 30 seconds: - Locks the physical card in Ramp (no further physical-card charges possible) - Issues a virtual card immediately for continued purchases while travelling - Sends Priya the virtual card details via secure DM - Confirms recent-30-day charges look normal or flags any suspicious activity - Files a lost-card record + orders replacement physical card shipped to Priya's home address Priya continues her business day with the virtual card. Physical replacement arrives in 3-5 days. When it arrives, Priya activates it via the app + the virtual card is retired. For compromised cards (fraudulent charges detected), Fin locks + files fraud claims with the card provider + issues replacement + coordinates with security for compromise-investigation.
How it works

Step by step.

  1. 01

    Detect lost / stolen / compromised card report

    User message (Slack, email, app), card-provider fraud alert, or security team notification. Immediate action — no ticket queue.

    Slack · Card provider fraud API · Security alerting
  2. 02

    Lock the physical card immediately

    Provider API call to lock. Confirmed within 5 seconds. Prevents further physical-card charges.

    Ramp · Brex · Amex · Airbase · Divvy
  3. 03

    Issue continuity virtual card

    Virtual card with same limits + categories issued immediately. Secure delivery to user (in-app or encrypted DM). Continues business function during physical replacement.

    Card provider virtual issuance · Secure delivery
  4. 04

    Review recent charges + flag suspicious

    30-day charge review. Anything anomalous (unusual merchants, out-of-pattern locations, unusual amounts) flagged for user confirmation.

    Fraud pattern detection · User confirmation
  5. 05

    Order replacement + close the loop

    Replacement physical card shipped to user's address (verified). Delivery tracking; on activation, virtual card retired. Case closed with audit record.

    Card provider shipping · Address verification · Tracking
Systems and wiring

What you connect to make this run.

Ramp · Brex · Amex · Airbase · Divvy

read+write

Card lifecycle: lock, issue virtual, order replacement, activate. All via provider APIs.

Slack · Teams · Secure DM

read+write

Report intake + secure delivery of virtual card details. Never sends card numbers over standard email.

Address service · HRIS

read

Shipping address verification to prevent misdirected replacements.

Fraud detection · Security alerting

read+write

Suspicious-charge patterns feed alerts; compromise-investigation coordination with security team.

What changes

Before and after, honestly.

Time from report to physical card locked
Before
1-24 hours
After
Under 60 seconds
Business days user waits for continuity solution
Before
3-7 days (no card)
After
Zero (virtual card immediate)
Fraudulent charges post-report
Before
$50-500 per incident
After
Under $20 per incident
Finance / IT hours per lost card
Before
30-60 minutes
After
Under 2 minutes
Frequently asked

Answers about this playbook.

What if the user isn't sure whether the card is lost or misplaced?

Lock the card immediately; unlock is one-click when user finds it. Better to inconvenience for 20 minutes than absorb fraudulent charges.

How does it handle international travel where user needs local currency withdrawals?

Some cards support ATM PIN; virtual replacements support the same PIN. Card provider dependent; specific flows per provider.

What about corporate-card programs where card and identity are joined?

Compromised card + potential identity compromise triggers full security-incident flow, not just card replacement.

Can users lock their own card via app?

Yes — user-side app locks are always supported. Fin flow is for cases where user needs help or the report path is different.

How does it handle cards issued to service accounts (shared cards)?

Shared cards get different flow: lock + notify all users of the shared card + coordinate on continuity. Prefer per-user cards where possible.

See it run on your data.

Free plan, no credit card. Connect the systems this playbook needs and run it against a past event first.