Operator guideEN

Players / Fraud Detection

Fraud-detection tab inside the player workspace with MaxMind risk assessment, related fraud-account reports, IP analysis, and Identity Graph filtering.

How to use this guide

Start with the main guide

Follow the explanation and examples first. Extra definitions and formulas are available below when you need them.

What this tab shows

Players / Fraud Detection combines several fraud-review tools for one player:

  • stored or on-demand fraud risk assessment
  • related fraud-report rows
  • login IP analysis
  • geolocation and proxy/VPN context
  • MaxMind report archive and raw-response inspection
  • aggregated risk-band, common-risk-factor, and per-IP score summaries built from stored fraud-check history

When to use it

Use this tab when you need to:

  • check whether the player shares suspicious signals with other accounts
  • review IP and geolocation anomalies
  • compare local vs identity-graph matches
  • inspect the MaxMind result behind a stored risk score
  • decide whether the player needs escalation for fraud review

How to read it

The tab has three major blocks:

  1. Fraud Risk Assessment for running or reviewing risk checks.
  2. Related Fraud Reports table with source-mode filtering.
  3. IP Address Analysis and optional map view for the player's login IPs.

Inside Fraud Risk Assessment, the FE renders two distinct read blocks when history exists:

  • Risk Score Analysis: overall average score, risk-band counts, trend, per-IP averages, and common risk factors
  • MaxMind Reports List: stored raw report history behind the same fraud-check flow

Filters and controls

Run New Fraud Check and Run New Check (Uses Credits) are the same action. The tab asks for confirmation before the request because it can call MaxMind and consume provider credits. The action is disabled until the player has at least one login IP.

Load Missing Locations appears only when some login IPs do not already have location data. It enriches missing IPs and stores successful lookups so later tab loads can show cached location and anonymizer context.

View on Map opens a map dialog for IPs that have coordinates. The map requires the Mapbox API key in System Settings. Without that key, the map dialog shows a configuration warning while the IP list remains usable.

The Combined, Local, and Identity Graph buttons affect only the Related Fraud Reports table. They do not change the MaxMind risk history or the IP cards.

The MaxMind Reports Archive has local tabs for all reports, high-risk reports, reports with security flags, and the latest 10 reports. Expanding a report row shows report details, security flags, risk reasons, warnings, and JSON response controls.

Known caveats

  • Combined, Local, and Identity Graph are filter modes on the fraud-report dataset, not separate player statuses.
  • IP analysis can load additional location data after the first render. Operators may see a partial view before enrichment finishes.
  • Running a new fraud check can consume an external risk-check flow; it is not just a UI refresh.
  • Run New Fraud Check and Run New Check (Uses Credits) are the same MaxMind-backed action. The wording explicitly warns operators that a new provider check can consume credits.
  • The risk analysis blocks are computed from stored fraud-check history, not directly from the related-fraud-report table. The table and the risk summary can therefore move independently.
  • Related fraud reports combine local matching, optional Identity Graph matching, and external fraud-database tags. If Identity Graph is not configured or unavailable, local matches can still be shown.
  • The MaxMind history endpoint returns the latest stored checks first. The FE-side risk trend compares the most recent five valid scores with the previous five valid scores only when at least ten history rows exist.
  • The map can be unavailable when Mapbox system settings are missing, even if the IP list itself is present.
More details

Definitions and formulas

Open only the section you need. The relevant section opens automatically when you request help for a specific item on screen.

Filters3 topicsOpen details

Data source

Reloads only the Related Fraud Reports table. It does not change MaxMind history or IP analysis.

Type
segmented
Default
Combined
Options
0: Value: both | Label: Combined | 1: Value: local | Label: Local | 2: Value: identity | Label: Identity Graph

MaxMind archive tab

Local filter for stored MaxMind reports. It does not call backend.

Type
tabs
Default
All Reports
Options
All Reports, High Risk, Security Flags, Latest

Visible IP Count

Controls how many login IP cards are visible. The More IPs card increases the count by five.

Type
incremental
Default
5
Metrics17 topicsOpen details

Overall Risk Assessment

Rounded average fraud risk score across valid stored fraud-check history for the player. When no valid scores exist, the UI shows N/A and NO DATA.

Data Type
score

Total Checks

Number of stored fraud checks loaded into the current risk analysis.

Data Type
integer

Risk Trend

Directional change in average score between the most recent five valid checks and the previous five valid checks when enough history exists.

Data Type
delta

High Risk

Count of stored checks with risk score >= 80.

Data Type
integer

Medium Risk

Count of stored checks with risk score >= 50 and < 80.

Data Type
integer

Low Risk

Count of stored checks with risk score >= 20 and < 50.

Data Type
integer

Minimal Risk

Count of stored checks with risk score < 20.

Data Type
integer

Avg Score

Rounded average risk score for one IP address across its stored fraud-check records.

Data Type
score

IP Check Count

Number of stored fraud checks that contributed to one IP's average risk summary.

Data Type
integer

Common Risk Factor Count

Occurrence count for one normalized common risk factor in the Common Risk Factors block.

Data Type
integer

Stored Reports

Count of stored MaxMind reports that include full provider response or fraud-analysis payload data.

Data Type
integer

MaxMind Risk Reasons

Count of provider risk reason entries on one expanded stored MaxMind report.

Data Type
integer

MaxMind Input Warnings

Count of provider warnings on one expanded stored MaxMind report.

Data Type
integer

Login IP Count

Number of unique login IPs found for the player from user activity records.

Data Type
integer

Used N times

Number of player activity rows grouped into one login IP card.

Data Type
integer

Location enrichment summary

Batch enrichment result counts total, successful, failed, cached, and newly fetched IP location results.

Data Type
result-summary

Related Fraud Report Rows

Number of related rows returned for the selected Combined, Local, or Identity Graph source mode.

Data Type
integer
More help

Related pages

Players / Banking

Banking tab inside the player workspace with transaction filters, a paginated banking grid, analytics cards, CSV export, and automatic-withdrawal availability.

Players / Detail Workspace

Main player workbench at `/player/[playerId]` with tabbed sections, player-level actions, and modal-based operator workflows.

Players / Game Report

Per-player game or provider report inside the player workspace, filtered by date option and grouped either by game or by provider.

Players / Inbox

Inbox tab inside the player workspace for reviewing delivered notifications, filtering by read state or notification type, and resending or soft-deleting message deliveries.

Players / KPI Summary

Grouped player-level KPI snapshot inside the player workspace, covering player info, deposits, withdrawals, casino totals, bonus cost, and predictive metrics.

Players / KYC Status

KYC tab inside the player workspace for browsing user documents, checking third-party verification state, and approving, rejecting, or re-requesting documents.