A fraud evaluation that scored high enough to be worth keeping, one row per scored operation. Only operations at or above the watch threshold are written, because a clear score on every checkout would be a great deal of noise for no information. Each row records what was scored, the score and the band it fell into, whether the operation was actually blocked, and a per-rule breakdown so a reviewer can see how the score was arrived at. This is an append-only log rather than a record a user edits, so it is deliberately not auditable; auditing it would double every row for nothing. The geolocation columns are held here rather than in a separate table because a profile's own recent rows are the cheapest available answer to whether that profile has been seen in this location before, which is what the unusual-location rule needs.

Group: Database Entities

Implements: Serializable


Properties

PropertyReturnsDescription
adminOrgOrganisationThe account the scored operation happened in. Every query on this class is scoped by it, so history from one account never influences another account's scores.
bandStringThe band the score fell into, as one of the FraudBand names. This is what policy is written against, rather than the raw number.
blockedbooleanWhether the operation was actually rejected. Distinct from the band, because blocking is switched off while a new rule set is being calibrated, so a high band with no block is normal in that mode.
breakdownStringThe per-rule contributions to the score, as a JSON string, so a reviewer can see why the score was what it was.
cityStringThe city the client IP geolocated to, used by the unusual-location rule.
contextTypeStringWhich kind of operation was scored, as one of the FraudContextType names, for example a checkout, a signup or a redemption.
countryCodeStringThe ISO country code the client IP geolocated to, used by the unusual-location rule.
createdByProfileThe logged in user at the time. For an administrator placing an order on someone's behalf this is not the same as the profile the operation was for.
createdDateDateWhen the evaluation ran. All of the velocity and history queries on this class window on this column.
failedRulesStringThe rules that threw or timed out and were therefore left out of the score, as a comma separated list. A non-null value here means the score understates the risk.
idlongDatabase identifier for this event.
ipAddressStringThe client IP the operation came from, which is what the IP velocity rule counts and what the geolocation columns were resolved from.
messageStringThe message shown to the user when the operation was blocked.
profileProfileThe profile the scored operation was for. Null for a signup that was blocked before a profile was created, which is exactly the case the velocity rules care about, so do not assume it is set.
scoreintThe overall risk score for the operation, from 0 for no risk to 100 for the highest. Note that a score is understated when some rules failed to run; see getFailedRules.
subjectIdLongThe database id of the subject named by the subject type. Deliberately a loose reference rather than a foreign key, because the subject may not exist yet at evaluation time, so it can point at a row that was never created or has since been deleted.
subjectTypeStringWhat the operation was about, for example a cart or a voucher.
websiteWebsiteThe website the scored operation happened on.

Methods

getId() · getAdminOrg() · getWebsite() · getProfile() · getCreatedBy() · getCreatedDate() · getContextType() · getIpAddress() · getScore() · getBand() · isBlocked() · getSubjectType() · getSubjectId() · getCountryCode() · getCity() · getBreakdown() · getFailedRules() · getMessage()

getId()

Returns: long

Database identifier for this event.

getAdminOrg()

Returns: Organisation

The account the scored operation happened in. Every query on this class is scoped by it, so history from one account never influences another account's scores.

getWebsite()

Returns: Website

The website the scored operation happened on.

getProfile()

Returns: Profile

The profile the scored operation was for. Null for a signup that was blocked before a profile was created, which is exactly the case the velocity rules care about, so do not assume it is set.

getCreatedBy()

Returns: Profile

The logged in user at the time. For an administrator placing an order on someone's behalf this is not the same as the profile the operation was for.

getCreatedDate()

Returns: Date

When the evaluation ran. All of the velocity and history queries on this class window on this column.

getContextType()

Returns: String

Which kind of operation was scored, as one of the FraudContextType names, for example a checkout, a signup or a redemption.

getIpAddress()

Returns: String

The client IP the operation came from, which is what the IP velocity rule counts and what the geolocation columns were resolved from.

getScore()

Returns: int

The overall risk score for the operation, from 0 for no risk to 100 for the highest. Note that a score is understated when some rules failed to run; see getFailedRules.

getBand()

Returns: String

The band the score fell into, as one of the FraudBand names. This is what policy is written against, rather than the raw number.

isBlocked()

Returns: boolean

Whether the operation was actually rejected. Distinct from the band, because blocking is switched off while a new rule set is being calibrated, so a high band with no block is normal in that mode.

getSubjectType()

Returns: String

What the operation was about, for example a cart or a voucher.

getSubjectId()

Returns: Long

The database id of the subject named by the subject type. Deliberately a loose reference rather than a foreign key, because the subject may not exist yet at evaluation time, so it can point at a row that was never created or has since been deleted.

getCountryCode()

Returns: String

The ISO country code the client IP geolocated to, used by the unusual-location rule.

getCity()

Returns: String

The city the client IP geolocated to, used by the unusual-location rule.

getBreakdown()

Returns: String

The per-rule contributions to the score, as a JSON string, so a reviewer can see why the score was what it was.

getFailedRules()

Returns: String

The rules that threw or timed out and were therefore left out of the score, as a comma separated list. A non-null value here means the score understates the risk.

getMessage()

Returns: String

The message shown to the user when the operation was blocked.

To get full access to the Kademi Hub existing customers can login here, or new customers can register here.