Risk & Fraud

Transactions, relationships and decisions on one clock.

Fraud is a relationship pattern, and risk is a decision made under a deadline. Both suffer when the relationships arrive from another system.

A decision under a deadline, made against a network rather than a record.

The workload

Decisions made across transactions, entities and their relationships.

Detection reads transactions, behavioural signals and the links between entities, then writes a case. PLOMID is designed to hold the signals, the relationships and the case record in one layer, so a decision and its justification are produced together.

Trust & deployment · 4 data shapes · 4 stages of the operation.

A decision under a deadline, made against a network rather than a record.

Environment

The transaction

Payments and postings arriving with their behavioural measurements.

SQL · Time series

What one layer changes

Two estates, drawn.

The same shapes, held two ways. The difference is not the storage, it is where the agreement between them lives.

Separate systems Copies kept in step
a copy, and a job to keep it honest
The rule engine sees transactions, the graph sees links, and the case system sees neither. Evidence is assembled by hand after the fact.
One layer One plan · one contract
one layer · one plan read from one place, as one answer
Signals, structure and case data in one layer, so a decision is a query and its explanation is stored with it.
Data shapes

What this workload moves.

Every shape below is a surface of the layer, not a format to be converted into one. They are read and written together.

  • Graph Relationships and traversal
  • Time series Measurements and events in time order
  • SQL Records, keys and joins
  • JSON / documents Documents and nested objects
Architecture

How the workload reaches the data.

The models this workload names, the path a request takes through them, and the surfaces that speak to the layer.

Risk & Fraud · architecture
Workload

The shape of the work itself.

  • Signal
  • Link
  • Decide
  • Record
Data models

The models this workload names.

  • Graph
  • Time series
  • SQL
  • JSON / documents
The layer

One path from a request to the data it names.

  • Planning Predicates narrow the work before it runs
  • Execution Rows, fields and windows answered together
  • Transactions Readers and writers do not block each other
Surfaces

How the workload reaches the layer.

  • SQL surface The query language the layer is documented in
  • Applications Services and jobs reading and writing as they run
  • Analytics & AI clients The same layer, the same access path
Workload map

The work, stage by stage.

Choose a stage to read what happens there, or a shape to see every stage that handles it. Nothing on the map is a private interface.

PLOMID · Risk & Fraud signal · link · decide · record Select a stage
Stage

Signal

Transactional records and behavioural measurements

SQL · Time series

Workload map Risk & Fraud workload map. Each stage names the part of the operation it carries and the shapes present at that point.
01

Signal

Transactional records and behavioural measurements

  • SQL
  • Time series
02

Link

Shared attributes and counterparties as relationships

  • Graph
03

Decide

Rules and models applied to the linked view

  • Graph
  • Time series
04

Record

The case, its evidence and its outcome

  • JSON / documents
  • SQL
Outcomes

What changes when the data is in one place.

Stated as properties of the system rather than as results we cannot measure for you.

Context in the decision

A decision is made against related entities rather than a single record.

Explanation stored

The reasoning and its inputs are written to the same layer that produced them.

Feedback loop

Outcomes become data for the next decision without an export.

One place to audit

A reviewer reads the same layer the model read.