Fraud / abuse control pack — 不正損失・正当 conversion・appeal・AI 原価を閉じる14書式
この pack は、決済 fraud、card testing、trial / promo / referral abuse、credential stuffing、account takeover、API key 盗用、AI / infra resource abuse を、同じ control decision へ結ぶコピー用書式である。使い方と根拠は25章、状態・制約の架空実装はSQLite companionを参照する。
全書式の値、ID、件数、金額、人物、incident は fully synthetic である。実績、fraud score、攻撃手順、検知 benchmark、推奨閾値ではない。
raw card data、password、session token、API secret、本人確認書類、完全な IP / device fingerprint、support 添付をこの pack、public issue、生成 AI prompt へ記録しない。opaque ID、coarse signal category、access-controlled evidence reference を使う。
出力権限は
NEXT_CONTROL_PROPOSAL_ONLY、live_action_authority = NONE。live block、account suspend / delete、refund、dispute submission、commission clawback、customer / provider / authority への連絡、key revoke を自動実行しない。
pack の不変条件
Section titled “pack の不変条件”decision unit: abuse_control_contract_id / contract_version
minimum grain: risk_exposure_id = one pre-outcome eligible business action retry = business_action_id + attempt_sequence
event spine: ELIGIBLE_EXPOSURE_FROZEN → SIGNALS_OBSERVED_AS_OF → POLICY_ACTION_RECORDED → BUSINESS / PROVIDER OUTCOME → CASE REVIEW → APPEAL / REMEDIATION / RESTORE → SETTLEMENT / DISPUTE / CASH / COST RECONCILIATION → MATURITY_SNAPSHOT → CONTROL DECISION
exposure action: ALLOW | STEP_UP | LIMIT | HOLD | DENY | RESTORE
decision priority: STOP > PAUSE > UNKNOWN > REMEDIATE > PROPOSE_BOUNDED_CONTROL- risk / bot score、IP、device、3DS result、CAPTCHA pass、provider decline は
signalであり、fraud label や人物同一性ではない。 - missing、pending、unmatured、unreconciled、unattributed は0や
NOT_APPLICABLEへ丸めない。 - payment authorization、settlement、provider balance、payout、bank cash、accepted product outcome を分ける。
- blocked attempt を realized savings と呼ばない。counterfactual がない場合は avoided exposure とする。
- refund、chargeback、fraud write-off の同一 principal loss は排他的に一度だけ計上する。
- control が利益を増やしても、secret compromise、cross-tenant exposure、hard-cost breach、privacy / legal veto を相殺しない。
- accepted appeal は entitlement、access、cash / credit、case label、customer communication を correction event で戻す。
書式 1 — Abuse control contract
Section titled “書式 1 — Abuse control contract”abuse_control_contract_id:contract_version:contract_status: DRAFT | FROZEN | SUPERSEDED
seller / business:product / offer_version:protected_action_class:route / jurisdiction / environment:
eligible exposure definition:explicit exclusions:legitimate exceptions:time_zero / exposure_start / exposure_end:follow_up_end / maturity_rule_version:
reference_policy_id / revision / digest:candidate_policy_id / revision / digest:assignment_method / assignment_key:policy_frozen_at:
maximum principal loss:maximum AI / infra cost:maximum review minutes / queue:maximum false-positive harm:maximum restore delay:minimum maturity / label / reconciliation coverage:minimum matured_risk_adjusted_contribution_delta:
incident_owner / case_owner / appeal_owner:provider_reconciliation_owner / cash_owner:rollback_owner / rollback_artifact:independent_reviewer:
authority_cap: NEXT_CONTROL_PROPOSAL_ONLYlive_action_authority: NONEfrozen_at / frozen_by / signature_ref:protected_action_class は SIGNUP / LOGIN / RECOVERY / PROMO_REDEMPTION / PAYMENT_ATTEMPT / REFERRAL_CLAIM / API_AI_JOB / ENTITLEMENT_USE 等から一つに絞る。複数 action を束ねる場合も各 exposure は分け、contract が relation を明示する。
書式 2 — Entity / relation boundary
Section titled “書式 2 — Entity / relation boundary”推定 relation は risk signal であり、本人確定や destructive merge ではない。
| entity_ref | entity_class | controller / owner state | source | retention | access | merge prohibited? |
|---|---|---|---|---|---|---|
[opaque] |
ACCOUNT / TENANT / CREDENTIAL / SESSION / PAYMENT_INSTRUMENT / BENEFICIARY / REFERRER / DEVICE_SIGNAL / NETWORK_SIGNAL | VERIFIED / CLAIMED / UNKNOWN / COMPROMISED | [controlled ref] |
[date/rule] |
[role] |
YES |
| relation_id | left_ref | right_ref | relation_type | confidence class | observed_as_of | purpose | reviewer | expires_at |
|---|---|---|---|---|---|---|---|---|
[id] |
[opaque] |
[opaque] |
SHARED_TENANT / SHARED_BENEFIT / SHARED_INSTRUMENT / COARSE_NETWORK / SUPPORT_LINK / OTHER | OBSERVED / INFERRED / UNKNOWN | [ts] |
[protected action] |
[human/system] |
[ts] |
禁止事項:
- raw PAN、CVV、password、token、secret、本人確認画像を記載しない。
- shared IP、language、timezone、device family だけで同一人物としない。
- inferred relation で victim account と abuser account を統合・削除しない。
- purpose が消えた relation と signal を無期限保存しない。
書式 3 — Protected action / eligibility cohort
Section titled “書式 3 — Protected action / eligibility cohort”protected_action_class:business value delivered:worst-case irreversible loss per action:downstream entitlement / payment / AI / partner effects:
eligibility source fields available before outcome:eligibility SQL / rule digest:exclusion rule and reason:legitimate exception path:cohort cutoff / time zero:
business_action_id construction:attempt_sequence construction:risk_exposure_id construction:assignment written before action?: YES | NOfuture outcome used in eligibility?: MUST_BE_NONegative tests:
- retry が新しい unique customer / sale / referral へ膨らまない。
- outcome を見てから reference / candidate を選び直せない。
- alias、invite、複数 tenant、法人 NAT、travel 等の legitimate exception が appeal 可能である。
eligible = observed after successful paymentのような immortal-time selection を拒む。
書式 4 — Signal catalog
Section titled “書式 4 — Signal catalog”| signal_id / version | signal class | source / observed_at / recorded_at | exact meaning | missing state | privacy purpose | retention | prohibited inference |
|---|---|---|---|---|---|---|---|
[id] |
VELOCITY / RELATION / AUTH / PAYMENT / BOT / RESOURCE / RECOVERY / PROVIDER | [source] |
[what was measured] |
UNKNOWN / NOT_OBSERVED | [purpose] |
[rule] |
fraud label / identity / protected trait |
Checklist:
- feature は outcome 前に取得可能か。
- timestamp と policy revision に束縛されているか。
- score
0、missing、not evaluated、safe を混同していないか。 - signal source outage / plan change / schema drift を検出できるか。
- coarse signal で十分か。raw value を保持する必要があるか。
- groupwise harm、accessibility、shared network、travel を review したか。
書式 5 — Policy / control matrix
Section titled “書式 5 — Policy / control matrix”| control_id / revision | lane | precondition | action | duration | scope | owner | observe-before-block | fail mode | rollback |
|---|---|---|---|---|---|---|---|---|---|
[id] |
IDENTITY / INCENTIVE / PAYMENT / ENTITLEMENT / API_AI / REVIEW | [signals + state] |
ALLOW / STEP_UP / LIMIT / HOLD / DENY | [ttl] |
[action/tenant] |
[owner] |
YES / N/A | FAIL_OPEN / FAIL_CLOSED / PAUSE | [artifact] |
DENY の前に STEP_UP / LIMIT / HOLD で可逆性を保てるか検討する。ただし active secret compromise、cross-tenant exposure、hard cost breach 等は即時 containment が必要になり得る。fail mode は availability、privacy、安全、最大損失を踏まえて人が決める。
Policy binding:
expected edge config digest:expected origin auth / quota digest:expected offer / payment config digest:expected AI routing / budget digest:observed digests:drift state: MATCH | DRIFT | UNKNOWN書式 6 — Identity / session / recovery control
Section titled “書式 6 — Identity / session / recovery control”login identifier class / storage:password / passkey / MFA policy:failed-attempt and stuffing control:trusted-session / reauthentication rule:session expiry / revoke-all path:
recovery entry points:high-risk changes protected:operator authority split:out-of-band notice:cooling-off / delay:victim-safe trusted-session path:account / entitlement restore path:
synthetic drills:[ ] credential stuffing across many accounts[ ] password spray / distributed source[ ] session theft after password change[ ] reset-link replay / expiry[ ] support social engineering[ ] email + MFA + API key + payout simultaneous change rejected[ ] victim can recover without permanent lockout書式 7 — Trial / promo / referral eligibility
Section titled “書式 7 — Trial / promo / referral eligibility”offer_version / benefit:eligible actor / tenant / benefit owner:one-time / period / region / channel rule:server-recomputed eligibility fields:prior redemption source:legitimate multi-tenant / invite exception:
referrer / beneficiary / order relation:self-referral / related-party review rule:conversion maturity definition:refund / dispute / cash maturity:commission holdback / reversal event:appeal / correction path:Adversarial cases:
- email alias、new customer record、device reset、new payment instrument。
- concurrent redemption、coupon stacking、replay、client-side price override。
- duplicate referral claim、code / cookie stuffing、self-referral、related party。
- stolen-card conversion が commission 確定前に dispute になる。
- benefit 取消と commission reversal で同じ principal を二重控除する。
書式 8 — Payment / dispute / cash spine
Section titled “書式 8 — Payment / dispute / cash spine”| payment_event_id | business_action_id / attempt | provider object / event | state | amount / currency | idempotency ref | occurred_at | received_at | correction_of |
|---|---|---|---|---|---|---|---|---|
[id] |
[id]/[n] |
[opaque] |
INTENT / REQUIRES_ACTION / AUTHORIZED / CAPTURED / FAILED / REFUNDED / DISPUTED / WON / LOST / SETTLED / PAID_OUT / BANK_CASH | [minor units] |
[ref] |
[ts] |
[ts] |
[id/null] |
Webhook signature verified:duplicate provider event handled:out-of-order transition handled:business idempotency and provider idempotency bound:EMV 3-D Secure integration / applicable baseline / exception evidence:PSP / acquirer confirmation and coverage:issuer frictionless / challenge result and availability:additional step-up cohort / authority:challenge completion and legitimate conversion:
dispute reason / deadline / evidence owner:dispute_stream_id / sequence / supersedes / recorded_at:one evidence submission rule checked:reserve / provider balance / payout / bank cash:principal loss group:provider / region / contract snapshot:決済 page を iframe / provider へ委託しても、自社 page、script、account、Webhook、access control、app-side eligibility の責任が自動で消えるとは限らない。PCI scope / SAQ、acquirer / PSP 要件は current integration で確認する。
書式 9 — Credential / API / AI cost guard
Section titled “書式 9 — Credential / API / AI cost guard”credential_id / project_id / environment:owner / tenant / feature authorization:candidate policy id / digest / frozen_at:resource guard checked_at / freshness cutoff:least privilege / allowed models / endpoints:created_at / expires_at / last_rotated_at:secret manager / client exposure MUST_BE_NONE:
provider alert / soft threshold:provider enforced limit / lag / scope:app tenant hard ceiling:credential / project hard ceiling:per-job worst-case reservation:token / time / payload / batch / concurrency / tool-depth ceiling:cancellation / timeout / partial result policy:
usage export source / cutoff:project / key / model / tenant attribution coverage:invoice / credit / cost reconciliation:unmatched usage amount / work order:kill switch owner / rollback:Incident drills:
- repo、frontend bundle、log、support attachment からの synthetic leak。
- key を別 tenant / region / model で使う。
- multi-key / account、retry fan-out、large payload、recursive tool で上限回避を試す。
- provider alert が遅れる、soft、scope違い、usage export が遅れる。
- revoke / rotate 後に old key、session、queued job が継続しないか確認する。
書式 10 — Exposure event record
Section titled “書式 10 — Exposure event record”risk_exposure_id:abuse_control_contract_id / contract_version:business_action_id / attempt_sequence:protected_action_class:eligible_as_of / eligibility_snapshot_ref:assigned_arm / policy_id / revision / digest:
opaque account / tenant / credential refs:signal_observation_ids / observed_as_of / recorded_at:policy_action: ALLOW | STEP_UP | LIMIT | HOLD | DENY | RESTOREaction_reason_category / applied_at / recorded_at / expires_at:
business_outcome / occurred_at / recorded_at:provider_outcome / occurred_at / received_at / recorded_at:case_id / label state / reviewed_at / recorded_at:appeal_id / decision_at / restore receipt / recorded_at:cash / cost reconciliation refs:maturity snapshot ref:Event-order assertions:
eligible_frozen_at <= signals_observed_at <= policy_action_atpolicy_action_at <= business/provider outcome observationcase reviewed_at <= appeal decision <= restore completed_atall required outcomes <= maturity snapshot <= control decisionincluded event observed/occurred_at <= recorded_at <= decision snapshot cutoffpost-snapshot backdated correction is excluded and enters the next snapshot書式 11 — Case / appeal / restore
Section titled “書式 11 — Case / appeal / restore”case_id / risk_exposure_id:opened_reason / opened_at:victim / malicious-owner state: VICTIM_POSSIBLE | OWNER_ABUSE_POSSIBLE | MIXED | UNKNOWNevidence_as_of / evidence refs:case recorded_at:reviewer / independent reviewer:reviewed label: LEGITIMATE | ABUSE | COMPROMISED | UNKNOWNdecision / reason category / expiry:
notice channel / notice receipt:appeal available / accessible alternative:appeal_id / received_at / grounds:appeal reviewer different from first reviewer?:appeal decision / decided_at:appeal recorded_at:
restore target time:session / credential / account correction:entitlement / promo / referral / payment correction:customer credit / refund human approval:restored_at / restore_receipt:late-label correction event:appeal denied も完了ではない。reason、evidence cutoff、independence、contactability、retention、再審条件を残す。accepted appeal は元 row を書き換えず、correction / restore event で閉じる。
書式 12 — Reconciliation / matured economics
Section titled “書式 12 — Reconciliation / matured economics”cohort snapshot as_of:reference / candidate eligible exposure:maturity coverage:reviewed label coverage:provider usage reconciliation coverage:payment / settlement / cash coverage:case / appeal / restore coverage:unmatched / pending / stale count:provider invoice cost sum = resource variable cost component?:principal-loss unique by economic principal and source transaction?:| economic component | reference | candidate | source / cutoff | exclusive group | completeness |
|---|---|---|---|---|---|
| legitimate settled contribution | COMPLETE / UNKNOWN | ||||
| fraud / refund / chargeback principal loss | PRINCIPAL_LOSS | ||||
| dispute fee | |||||
| unearned promo / referral / trial | BENEFIT_COST | ||||
| AI / infra / edge / PSP variable cost | |||||
| review / support / remediation / restore | |||||
| false-positive lost contribution | OBSERVED / ESTIMATED / UNKNOWN |
matured_risk_adjusted_contribution_reference:matured_risk_adjusted_contribution_candidate:
matured_risk_adjusted_contribution_delta= candidate per eligible exposure - reference per eligible exposure
sensitivity / plausible range:counterfactual limitations:Prohibited arithmetic:
- blocked attempt count × average fraud loss を realized savings とする。
- authorization amount を settled / bank cash とする。
- unmatured dispute、unmatched provider usage、founder review time を0にする。
- refund と chargeback と fraud write-off で同じ principal を複数回引く。
- candidate の absolute profit だけを比べ、eligible denominator / assignment drift を隠す。
書式 13 — Incident / containment evidence
Section titled “書式 13 — Incident / containment evidence”incident_id / incident_stream_id / sequence / supersedes:detected_at / declared_at / recorded_at:incident kind: CREDENTIAL_COMPROMISE | ACCOUNT_TAKEOVER | CARD_TESTING | CROSS_TENANT | RESOURCE_COST | PAYMENT_INTEGRITY | OTHERaffected contract / policy / artifact:known / suspected scope:active exposure state:
containment decision / owner / approved_at:key / session / route / payment / entitlement action:evidence preservation ref:provider / customer / authority coordination decision:privacy / legal / PCI escalation:contained_at / containment receipt:
victim-safe recovery / customer remedy:root cause / control gap:late labels expected through:reconciliation complete at:reopen criteria:State mapping:
- uncontained credential compromise、cross-tenant exposure、hard cost ceiling breach、unauthorized live action →
STOP_AND_CONTAIN。 - active incident で new exposure を安全に受けられない、dispute deadline / review capacity が危険 →
PAUSE_NEW_EXPOSURE。 - containment 完了後も label / cash / cost が未成熟なら
UNKNOWNのままにする。
書式 14 — Control decision / Codex handoff
Section titled “書式 14 — Control decision / Codex handoff”abuse_control_contract_id / contract_version:decision_snapshot_id / sha256:reference_policy / candidate_policy digests:eligible / matured / labeled / reconciled counts:
stop_flag / evidence:pause_flag / evidence:unknown_flag / missing evidence:remediate_flag / cap breached:proposal_ready_flag:
decision_state:work_order: STOP_AND_CONTAIN | PAUSE_NEW_EXPOSURE | COLLECT_MISSING_EVIDENCE | REMEDIATE_CONTROL | PROPOSE_NEXT_CONTROL_VERSION
matured_risk_adjusted_contribution_delta:false-positive harm / restore result:principal-loss exclusivity result:provider / cash / cost reconciliation result:privacy / accessibility / legal review result:
independent reviewer:reviewed snapshot sha256:review decision / reviewed_at:accountable human signature ref:
authority_cap: NEXT_CONTROL_PROPOSAL_ONLYlive_action_authority: NONEnext owner / due_at:rollback artifact:Codex task brief:
You may:- validate schema, event order, idempotency, reconciliation and synthetic fixtures;- compute arm-level counts and matured economics from approved opaque records;- flag missing/stale/cross-tenant/principal-duplication/authority failures;- draft NEXT_CONTROL_PROPOSAL_ONLY.
You must not:- ingest raw card, password, session, API secret, identity document or support attachment;- infer a person's fraud status from a score, IP, device, geography or language;- change live rules, revoke keys, suspend accounts, refund, submit disputes, contact customers/providers/authorities or execute a proposal;- convert missing, pending, unmatured or unreconciled states to zero;- exceed live_action_authority = NONE.fully synthetic decision example
Section titled “fully synthetic decision example”abuse_control_contract_id: SYN-ABUSE-001contract_version: 1.0.0decision_snapshot_id: SYN-SNAPSHOT-001
stop_flag: 0pause_flag: 0unknown_flag: 0remediate_flag: 0proposal_ready_flag: 1
decision_state: PROPOSE_BOUNDED_CONTROLwork_order: PROPOSE_NEXT_CONTROL_VERSIONmatured_risk_adjusted_contribution_delta: +54,000 JPY
independent reviewer: SYNTHETIC_REVIEWER_Breview decision: APPROVED_FOR_PROPOSAL_ONLYauthority_cap: NEXT_CONTROL_PROPOSAL_ONLYlive_action_authority: NONEこの出力は live control を変えない。accountable human は、exact policy / artifact、provider / plan、legal / privacy / PCI scope、rollback、review capacity を再確認し、別の change / release approval でのみ実行する。