Linked-entity review
A case is opened on a network of related entities rather than one account, because the relationships are stored as data.
- SQL
- Time series
Signals, relationships and decisions in one loop.
Fraud is rarely a single record. It is a pattern across parties, devices, timing and history, which means the relationship data is the analysis.
A fraud pattern caught as a network, decided under a deadline, kept as evidence.
Velocity, device, channel and behavioural measurements. It is the first of 4 workloads running in Risk & Fraud.
A case is opened on a network of related entities rather than one account, because the relationships are stored as data.
Risk & Fraud data moves through 5 stages — Ingest → Link → Score → Review → Learn. The shapes in play are Graph, Time series, SQL, JSON / documents, and answering one question means reading across all of them.
Detection is a relationship problem with a deadline. These are the parts that decide how fast it can be answered.
Detection reads transactions, behavioural measurements and relationship structure, then writes cases and decisions. Those pieces usually live in four systems and are joined by exports. PLOMID holds the signals, the relationships and the case record in one layer, so a decision and its evidence are one artefact.
Each one reads records, and where it must, the relationships between them — from the same layer, not an extract.
A case is opened on a network of related entities rather than one account, because the relationships are stored as data.
Behavioural measurements are read against the account’s full history in one request.
Notes, attachments and the underlying records stay queryable beside the case.
Dispositions are records in the same layer that produced the alert, so the loop is closed without an export.
Walk the path the data takes, from the environment that produces it to the questions it answers. Select a station, or a shape, to read each step.
A fraud pattern caught as a network, decided under a deadline, kept as evidence.
The transaction stream
Payments and postings arriving continuously with their behavioural measurements.
SQL · Time series
4 shapes carry this domain. Choose a stage to read the operation, or a shape to see every stage that handles it.
Ingest
Transactional records and behavioural measurements
SQL · Time series
4 workload families over one set of shapes. Choose one to see what it moves and where it lands.
Velocity, device, channel and behavioural measurements.
Accounts, devices, payees, merchants and shared attributes.
Alerts, reviews, notes, attachments and outcomes.
Confirmed fraud, false positives and disposition measurements.
Records first, relationships where the question needs them — every path a request can take through this data.
What runs against this data.
The shapes those workloads read and write.
One path from a request to the data it names.
How the work reaches the layer.
Detection runs where the data is, which makes placement and latency part of the question rather than an afterthought.
Deployment, residency and control