コンテンツにスキップ

Fraud / abuse control pack — 不正損失・正当 conversion・appeal・AI 原価を閉じる14書式

この pack は、決済 fraud、card testing、trial / promo / referral abuse、credential stuffing、account takeover、API key 盗用、AI / infra resource abuse を、同じ control decision へ結ぶコピー用書式である。使い方と根拠は25章、状態・制約の架空実装はSQLite companionを参照する。

全書式の値、ID、件数、金額、人物、incident は fully synthetic である。実績、fraud score、攻撃手順、検知 benchmark、推奨閾値ではない。

raw card data、password、session token、API secret、本人確認書類、完全な IP / device fingerprint、support 添付をこの pack、public issue、生成 AI prompt へ記録しない。opaque ID、coarse signal category、access-controlled evidence reference を使う。

出力権限は NEXT_CONTROL_PROPOSAL_ONLY、live_action_authority = NONE。live block、account suspend / delete、refund、dispute submission、commission clawback、customer / provider / authority への連絡、key revoke を自動実行しない。

decision unit:
abuse_control_contract_id / contract_version
minimum grain:
risk_exposure_id = one pre-outcome eligible business action
retry = business_action_id + attempt_sequence
event spine:
ELIGIBLE_EXPOSURE_FROZEN
→ SIGNALS_OBSERVED_AS_OF
→ POLICY_ACTION_RECORDED
→ BUSINESS / PROVIDER OUTCOME
→ CASE REVIEW
→ APPEAL / REMEDIATION / RESTORE
→ SETTLEMENT / DISPUTE / CASH / COST RECONCILIATION
→ MATURITY_SNAPSHOT
→ CONTROL DECISION
exposure action:
ALLOW | STEP_UP | LIMIT | HOLD | DENY | RESTORE
decision priority:
STOP > PAUSE > UNKNOWN > REMEDIATE > PROPOSE_BOUNDED_CONTROL
  • risk / bot score、IP、device、3DS result、CAPTCHA pass、provider decline は signal であり、fraud label や人物同一性ではない。
  • missing、pending、unmatured、unreconciled、unattributed は0やNOT_APPLICABLEへ丸めない。
  • payment authorization、settlement、provider balance、payout、bank cash、accepted product outcome を分ける。
  • blocked attempt を realized savings と呼ばない。counterfactual がない場合は avoided exposure とする。
  • refund、chargeback、fraud write-off の同一 principal loss は排他的に一度だけ計上する。
  • control が利益を増やしても、secret compromise、cross-tenant exposure、hard-cost breach、privacy / legal veto を相殺しない。
  • accepted appeal は entitlement、access、cash / credit、case label、customer communication を correction event で戻す。

abuse_control_contract_id:
contract_version:
contract_status: DRAFT | FROZEN | SUPERSEDED
seller / business:
product / offer_version:
protected_action_class:
route / jurisdiction / environment:
eligible exposure definition:
explicit exclusions:
legitimate exceptions:
time_zero / exposure_start / exposure_end:
follow_up_end / maturity_rule_version:
reference_policy_id / revision / digest:
candidate_policy_id / revision / digest:
assignment_method / assignment_key:
policy_frozen_at:
maximum principal loss:
maximum AI / infra cost:
maximum review minutes / queue:
maximum false-positive harm:
maximum restore delay:
minimum maturity / label / reconciliation coverage:
minimum matured_risk_adjusted_contribution_delta:
incident_owner / case_owner / appeal_owner:
provider_reconciliation_owner / cash_owner:
rollback_owner / rollback_artifact:
independent_reviewer:
authority_cap: NEXT_CONTROL_PROPOSAL_ONLY
live_action_authority: NONE
frozen_at / frozen_by / signature_ref:

protected_action_class は SIGNUP / LOGIN / RECOVERY / PROMO_REDEMPTION / PAYMENT_ATTEMPT / REFERRAL_CLAIM / API_AI_JOB / ENTITLEMENT_USE 等から一つに絞る。複数 action を束ねる場合も各 exposure は分け、contract が relation を明示する。

推定 relation は risk signal であり、本人確定や destructive merge ではない。

entity_ref entity_class controller / owner state source retention access merge prohibited?
[opaque] ACCOUNT / TENANT / CREDENTIAL / SESSION / PAYMENT_INSTRUMENT / BENEFICIARY / REFERRER / DEVICE_SIGNAL / NETWORK_SIGNAL VERIFIED / CLAIMED / UNKNOWN / COMPROMISED [controlled ref] [date/rule] [role] YES
relation_id left_ref right_ref relation_type confidence class observed_as_of purpose reviewer expires_at
[id] [opaque] [opaque] SHARED_TENANT / SHARED_BENEFIT / SHARED_INSTRUMENT / COARSE_NETWORK / SUPPORT_LINK / OTHER OBSERVED / INFERRED / UNKNOWN [ts] [protected action] [human/system] [ts]

禁止事項:

  • raw PAN、CVV、password、token、secret、本人確認画像を記載しない。
  • shared IP、language、timezone、device family だけで同一人物としない。
  • inferred relation で victim account と abuser account を統合・削除しない。
  • purpose が消えた relation と signal を無期限保存しない。

書式 3 — Protected action / eligibility cohort

Section titled “書式 3 — Protected action / eligibility cohort”
protected_action_class:
business value delivered:
worst-case irreversible loss per action:
downstream entitlement / payment / AI / partner effects:
eligibility source fields available before outcome:
eligibility SQL / rule digest:
exclusion rule and reason:
legitimate exception path:
cohort cutoff / time zero:
business_action_id construction:
attempt_sequence construction:
risk_exposure_id construction:
assignment written before action?: YES | NO
future outcome used in eligibility?: MUST_BE_NO

Negative tests:

  • retry が新しい unique customer / sale / referral へ膨らまない。
  • outcome を見てから reference / candidate を選び直せない。
  • alias、invite、複数 tenant、法人 NAT、travel 等の legitimate exception が appeal 可能である。
  • eligible = observed after successful payment のような immortal-time selection を拒む。
signal_id / version signal class source / observed_at / recorded_at exact meaning missing state privacy purpose retention prohibited inference
[id] VELOCITY / RELATION / AUTH / PAYMENT / BOT / RESOURCE / RECOVERY / PROVIDER [source] [what was measured] UNKNOWN / NOT_OBSERVED [purpose] [rule] fraud label / identity / protected trait

Checklist:

  • feature は outcome 前に取得可能か。
  • timestamp と policy revision に束縛されているか。
  • score 0、missing、not evaluated、safe を混同していないか。
  • signal source outage / plan change / schema drift を検出できるか。
  • coarse signal で十分か。raw value を保持する必要があるか。
  • groupwise harm、accessibility、shared network、travel を review したか。
control_id / revision lane precondition action duration scope owner observe-before-block fail mode rollback
[id] IDENTITY / INCENTIVE / PAYMENT / ENTITLEMENT / API_AI / REVIEW [signals + state] ALLOW / STEP_UP / LIMIT / HOLD / DENY [ttl] [action/tenant] [owner] YES / N/A FAIL_OPEN / FAIL_CLOSED / PAUSE [artifact]

DENY の前に STEP_UP / LIMIT / HOLD で可逆性を保てるか検討する。ただし active secret compromise、cross-tenant exposure、hard cost breach 等は即時 containment が必要になり得る。fail mode は availability、privacy、安全、最大損失を踏まえて人が決める。

Policy binding:

expected edge config digest:
expected origin auth / quota digest:
expected offer / payment config digest:
expected AI routing / budget digest:
observed digests:
drift state: MATCH | DRIFT | UNKNOWN

書式 6 — Identity / session / recovery control

Section titled “書式 6 — Identity / session / recovery control”
login identifier class / storage:
password / passkey / MFA policy:
failed-attempt and stuffing control:
trusted-session / reauthentication rule:
session expiry / revoke-all path:
recovery entry points:
high-risk changes protected:
operator authority split:
out-of-band notice:
cooling-off / delay:
victim-safe trusted-session path:
account / entitlement restore path:
synthetic drills:
[ ] credential stuffing across many accounts
[ ] password spray / distributed source
[ ] session theft after password change
[ ] reset-link replay / expiry
[ ] support social engineering
[ ] email + MFA + API key + payout simultaneous change rejected
[ ] victim can recover without permanent lockout

書式 7 — Trial / promo / referral eligibility

Section titled “書式 7 — Trial / promo / referral eligibility”
offer_version / benefit:
eligible actor / tenant / benefit owner:
one-time / period / region / channel rule:
server-recomputed eligibility fields:
prior redemption source:
legitimate multi-tenant / invite exception:
referrer / beneficiary / order relation:
self-referral / related-party review rule:
conversion maturity definition:
refund / dispute / cash maturity:
commission holdback / reversal event:
appeal / correction path:

Adversarial cases:

  • email alias、new customer record、device reset、new payment instrument。
  • concurrent redemption、coupon stacking、replay、client-side price override。
  • duplicate referral claim、code / cookie stuffing、self-referral、related party。
  • stolen-card conversion が commission 確定前に dispute になる。
  • benefit 取消と commission reversal で同じ principal を二重控除する。

書式 8 — Payment / dispute / cash spine

Section titled “書式 8 — Payment / dispute / cash spine”
payment_event_id business_action_id / attempt provider object / event state amount / currency idempotency ref occurred_at received_at correction_of
[id] [id]/[n] [opaque] INTENT / REQUIRES_ACTION / AUTHORIZED / CAPTURED / FAILED / REFUNDED / DISPUTED / WON / LOST / SETTLED / PAID_OUT / BANK_CASH [minor units] [ref] [ts] [ts] [id/null]
Webhook signature verified:
duplicate provider event handled:
out-of-order transition handled:
business idempotency and provider idempotency bound:
EMV 3-D Secure integration / applicable baseline / exception evidence:
PSP / acquirer confirmation and coverage:
issuer frictionless / challenge result and availability:
additional step-up cohort / authority:
challenge completion and legitimate conversion:
dispute reason / deadline / evidence owner:
dispute_stream_id / sequence / supersedes / recorded_at:
one evidence submission rule checked:
reserve / provider balance / payout / bank cash:
principal loss group:
provider / region / contract snapshot:

決済 page を iframe / provider へ委託しても、自社 page、script、account、Webhook、access control、app-side eligibility の責任が自動で消えるとは限らない。PCI scope / SAQ、acquirer / PSP 要件は current integration で確認する。

書式 9 — Credential / API / AI cost guard

Section titled “書式 9 — Credential / API / AI cost guard”
credential_id / project_id / environment:
owner / tenant / feature authorization:
candidate policy id / digest / frozen_at:
resource guard checked_at / freshness cutoff:
least privilege / allowed models / endpoints:
created_at / expires_at / last_rotated_at:
secret manager / client exposure MUST_BE_NONE:
provider alert / soft threshold:
provider enforced limit / lag / scope:
app tenant hard ceiling:
credential / project hard ceiling:
per-job worst-case reservation:
token / time / payload / batch / concurrency / tool-depth ceiling:
cancellation / timeout / partial result policy:
usage export source / cutoff:
project / key / model / tenant attribution coverage:
invoice / credit / cost reconciliation:
unmatched usage amount / work order:
kill switch owner / rollback:

Incident drills:

  • repo、frontend bundle、log、support attachment からの synthetic leak。
  • key を別 tenant / region / model で使う。
  • multi-key / account、retry fan-out、large payload、recursive tool で上限回避を試す。
  • provider alert が遅れる、soft、scope違い、usage export が遅れる。
  • revoke / rotate 後に old key、session、queued job が継続しないか確認する。
risk_exposure_id:
abuse_control_contract_id / contract_version:
business_action_id / attempt_sequence:
protected_action_class:
eligible_as_of / eligibility_snapshot_ref:
assigned_arm / policy_id / revision / digest:
opaque account / tenant / credential refs:
signal_observation_ids / observed_as_of / recorded_at:
policy_action: ALLOW | STEP_UP | LIMIT | HOLD | DENY | RESTORE
action_reason_category / applied_at / recorded_at / expires_at:
business_outcome / occurred_at / recorded_at:
provider_outcome / occurred_at / received_at / recorded_at:
case_id / label state / reviewed_at / recorded_at:
appeal_id / decision_at / restore receipt / recorded_at:
cash / cost reconciliation refs:
maturity snapshot ref:

Event-order assertions:

eligible_frozen_at <= signals_observed_at <= policy_action_at
policy_action_at <= business/provider outcome observation
case reviewed_at <= appeal decision <= restore completed_at
all required outcomes <= maturity snapshot <= control decision
included event observed/occurred_at <= recorded_at <= decision snapshot cutoff
post-snapshot backdated correction is excluded and enters the next snapshot
case_id / risk_exposure_id:
opened_reason / opened_at:
victim / malicious-owner state: VICTIM_POSSIBLE | OWNER_ABUSE_POSSIBLE | MIXED | UNKNOWN
evidence_as_of / evidence refs:
case recorded_at:
reviewer / independent reviewer:
reviewed label: LEGITIMATE | ABUSE | COMPROMISED | UNKNOWN
decision / reason category / expiry:
notice channel / notice receipt:
appeal available / accessible alternative:
appeal_id / received_at / grounds:
appeal reviewer different from first reviewer?:
appeal decision / decided_at:
appeal recorded_at:
restore target time:
session / credential / account correction:
entitlement / promo / referral / payment correction:
customer credit / refund human approval:
restored_at / restore_receipt:
late-label correction event:

appeal denied も完了ではない。reason、evidence cutoff、independence、contactability、retention、再審条件を残す。accepted appeal は元 row を書き換えず、correction / restore event で閉じる。

書式 12 — Reconciliation / matured economics

Section titled “書式 12 — Reconciliation / matured economics”
cohort snapshot as_of:
reference / candidate eligible exposure:
maturity coverage:
reviewed label coverage:
provider usage reconciliation coverage:
payment / settlement / cash coverage:
case / appeal / restore coverage:
unmatched / pending / stale count:
provider invoice cost sum = resource variable cost component?:
principal-loss unique by economic principal and source transaction?:
economic component reference candidate source / cutoff exclusive group completeness
legitimate settled contribution COMPLETE / UNKNOWN
fraud / refund / chargeback principal loss PRINCIPAL_LOSS
dispute fee
unearned promo / referral / trial BENEFIT_COST
AI / infra / edge / PSP variable cost
review / support / remediation / restore
false-positive lost contribution OBSERVED / ESTIMATED / UNKNOWN
matured_risk_adjusted_contribution_reference:
matured_risk_adjusted_contribution_candidate:
matured_risk_adjusted_contribution_delta
= candidate per eligible exposure - reference per eligible exposure
sensitivity / plausible range:
counterfactual limitations:

Prohibited arithmetic:

  • blocked attempt count × average fraud loss を realized savings とする。
  • authorization amount を settled / bank cash とする。
  • unmatured dispute、unmatched provider usage、founder review time を0にする。
  • refund と chargeback と fraud write-off で同じ principal を複数回引く。
  • candidate の absolute profit だけを比べ、eligible denominator / assignment drift を隠す。

書式 13 — Incident / containment evidence

Section titled “書式 13 — Incident / containment evidence”
incident_id / incident_stream_id / sequence / supersedes:
detected_at / declared_at / recorded_at:
incident kind: CREDENTIAL_COMPROMISE | ACCOUNT_TAKEOVER | CARD_TESTING |
CROSS_TENANT | RESOURCE_COST | PAYMENT_INTEGRITY | OTHER
affected contract / policy / artifact:
known / suspected scope:
active exposure state:
containment decision / owner / approved_at:
key / session / route / payment / entitlement action:
evidence preservation ref:
provider / customer / authority coordination decision:
privacy / legal / PCI escalation:
contained_at / containment receipt:
victim-safe recovery / customer remedy:
root cause / control gap:
late labels expected through:
reconciliation complete at:
reopen criteria:

State mapping:

  • uncontained credential compromise、cross-tenant exposure、hard cost ceiling breach、unauthorized live action → STOP_AND_CONTAIN。
  • active incident で new exposure を安全に受けられない、dispute deadline / review capacity が危険 → PAUSE_NEW_EXPOSURE。
  • containment 完了後も label / cash / cost が未成熟なら UNKNOWN のままにする。

書式 14 — Control decision / Codex handoff

Section titled “書式 14 — Control decision / Codex handoff”
abuse_control_contract_id / contract_version:
decision_snapshot_id / sha256:
reference_policy / candidate_policy digests:
eligible / matured / labeled / reconciled counts:
stop_flag / evidence:
pause_flag / evidence:
unknown_flag / missing evidence:
remediate_flag / cap breached:
proposal_ready_flag:
decision_state:
work_order:
STOP_AND_CONTAIN
| PAUSE_NEW_EXPOSURE
| COLLECT_MISSING_EVIDENCE
| REMEDIATE_CONTROL
| PROPOSE_NEXT_CONTROL_VERSION
matured_risk_adjusted_contribution_delta:
false-positive harm / restore result:
principal-loss exclusivity result:
provider / cash / cost reconciliation result:
privacy / accessibility / legal review result:
independent reviewer:
reviewed snapshot sha256:
review decision / reviewed_at:
accountable human signature ref:
authority_cap: NEXT_CONTROL_PROPOSAL_ONLY
live_action_authority: NONE
next owner / due_at:
rollback artifact:

Codex task brief:

You may:
- validate schema, event order, idempotency, reconciliation and synthetic fixtures;
- compute arm-level counts and matured economics from approved opaque records;
- flag missing/stale/cross-tenant/principal-duplication/authority failures;
- draft NEXT_CONTROL_PROPOSAL_ONLY.
You must not:
- ingest raw card, password, session, API secret, identity document or support attachment;
- infer a person's fraud status from a score, IP, device, geography or language;
- change live rules, revoke keys, suspend accounts, refund, submit disputes,
contact customers/providers/authorities or execute a proposal;
- convert missing, pending, unmatured or unreconciled states to zero;
- exceed live_action_authority = NONE.
abuse_control_contract_id: SYN-ABUSE-001
contract_version: 1.0.0
decision_snapshot_id: SYN-SNAPSHOT-001
stop_flag: 0
pause_flag: 0
unknown_flag: 0
remediate_flag: 0
proposal_ready_flag: 1
decision_state: PROPOSE_BOUNDED_CONTROL
work_order: PROPOSE_NEXT_CONTROL_VERSION
matured_risk_adjusted_contribution_delta: +54,000 JPY
independent reviewer: SYNTHETIC_REVIEWER_B
review decision: APPROVED_FOR_PROPOSAL_ONLY
authority_cap: NEXT_CONTROL_PROPOSAL_ONLY
live_action_authority: NONE

この出力は live control を変えない。accountable human は、exact policy / artifact、provider / plan、legal / privacy / PCI scope、rollback、review capacity を再確認し、別の change / release approval でのみ実行する。