Skip to content
POST /v1/eventsRequest access
Detection

Rules & patterns

The rules ship with every workspace, each a sentence with numbers you can change. They’re live from your first event, with defaults tuned for mobile money, and choosing your use case switches on the ones that matter for your business.

Three modes

  • Off: not evaluated.
  • Watch: evaluated, counted and fed into patterns, but never acts alone. Use it to trial a rule on live traffic.
  • Enforce: also adds to the risk score, so it can send an event to review or block it.

Changing a rule safely

Edit a number and press Test on last 30 days. Sieve replays your real events through the changed rule and shows how many times it would have fired, how many verdicts would change, and its precision on cases you’ve already judged. Save, and it applies to the next event. Every change is versioned in the audit log.

Rules across customers

Most rules look at one customer. Fraud rings are built to beat exactly that: two accounts per phone, a few senders each, every account under every limit. Five rules look at your customers together instead. Customers are linked when they share a device, a payout account, a phone, an email, a national ID or a BVN, or when money moves between them, and the rules read the groups that form:

  • Part of a linked group of new accounts: a group of 4 or more linked customers, at least 3 of them opened in the last 30 days.
  • Passing on money from other customers: at least half of what another of your customers sent is passed on within a day, or the customer sits on a chain or cycle of such transfers.
  • Close to confirmed fraud: within 2 links of a customer with confirmed fraud.
  • New accounts crowding one IP address: 4 or more accounts opened in the last 7 days used the same IP address within 24 hours.
  • Payout account suddenly shared by new accounts: 3 or more accounts opened in the last 30 days added the same payout account within 48 hours.

All five start in Watch: they feed the probability and your patterns from day one, and you switch them to Enforce once you’ve seen what they catch. The groups are worked out in the background, within about 20 seconds of new activity (up to 10 minutes on workspaces with more than 20,000 customers), and within seconds when fraud is confirmed, because distance to fraud changes the moment it is known. The numbers above are defaults you can change like any rule’s.

The rule library

RuleDefault

Preset patterns

Which patterns are on at the start depends on the use case you pick; every one can be switched on, tuned or turned off later.

  • New-account cash-out: a new account swaps its phone or payout details, then withdraws.
  • Account takeover: new device or place, credential reset, money out.
  • SIM-swap drain: a SIM swap, a PIN reset and an emptied wallet. The swap is a required step.
  • Money mule: many senders in, nearly everything straight out, often to a shared account.
  • Structuring: amounts kept just under the reporting threshold. Alerts, never blocks: it’s an STR case.
  • Crypto cash-out: money arrives by mobile money, card or bank and leaves as crypto within hours, to a wallet the customer has never used, often split across several.
  • Cross-border layering: funds gathered from many senders pushed out across borders, to new or high-risk countries. Starts in Watch.
  • Card testing: stolen card numbers tried with tiny payments until some work, then used for a large purchase.
  • Dormant-account abuse and Scripted activity.