Canonical URL: https://chargezen.com/docs/spark/ai-agents/fraud-agent

# Fraud Agent

AI-powered fraud detection preventing $4,200+ in fraudulent commissions quarterly

Last updated: 2026-01-19

The Fraud Agent monitors every conversion for suspicious activity and prevents commission fraud before payouts are made. It protects your program from self-referrals, click fraud, coupon abuse, and other schemes that cost affiliate programs thousands of dollars.

##### $4,200+ Saved Quarterly

On average, the Fraud Agent prevents over $4,200 in fraudulent commissions per quarter. It catches suspicious patterns that manual review would miss, protecting your bottom line.

## What It Detects

The Fraud Agent identifies multiple types of affiliate fraud:

### Self-Referrals

*   **Pattern:** Affiliates purchasing through their own tracking links
*   **Detection:** IP matching, device fingerprinting, email correlation
*   **Common tactics:** Multiple devices, VPNs, using family members
*   **Risk level:** High—often the most common fraud type

### Family & Friend Fraud

*   **Pattern:** Purchases from known associates of the affiliate
*   **Detection:** Shared addresses, similar email domains, network analysis
*   **Indicators:** Same shipping address, similar IP range, related email patterns

### Click Fraud

*   **Pattern:** Artificially inflated clicks to manipulate metrics
*   **Detection:** Click pattern analysis, bot detection, velocity monitoring
*   **Indicators:** Unusual click timing, consistent patterns, no conversions

### Coupon/Last-Click Hijacking

*   **Pattern:** Coupon sites claiming last-click credit on existing sales
*   **Detection:** Customer journey analysis, time-to-conversion, referrer patterns
*   **Indicators:** Short time between click and purchase, customer already on checkout

### Return Fraud

*   **Pattern:** High return rates suggesting gaming commission system
*   **Detection:** Return rate monitoring, pattern matching across affiliates
*   **Indicators:** Return rate 3x above average, systematic return timing

### Fake Accounts

*   **Pattern:** Multiple affiliate accounts controlled by same person
*   **Detection:** Device fingerprint, IP analysis, payment method overlap
*   **Indicators:** Similar application data, shared payout methods

### Cookie Stuffing

*   **Pattern:** Unauthorized cookie placement without actual referral
*   **Detection:** Click source analysis, referrer validation, timing anomalies
*   **Indicators:** No inbound traffic, iframe-based tracking, hidden images

## Detection Methods

The Fraud Agent uses multiple signals to identify suspicious activity:

### IP & Network Analysis

*   **IP Matching** — Same IP for affiliate and customer
*   **Network Proximity** — IPs in same range or subnet
*   **VPN/Proxy Detection** — Identifies masked connections
*   **Datacenter IPs** — Flags non-residential traffic

### Device Fingerprinting

*   **Browser Fingerprint** — Unique browser configuration signature
*   **Device Characteristics** — Screen, timezone, fonts, plugins
*   **Cross-Device Linking** — Identifies same user across devices

### Behavioral Analysis

*   **Click Patterns** — Timing, frequency, consistency
*   **Conversion Velocity** — Time from click to purchase
*   **Navigation Patterns** — How users move through site
*   **Return Behavior** — Post-purchase actions

### Data Correlation

*   **Email Analysis** — Domain patterns, similarity scoring
*   **Address Matching** — Billing/shipping correlation
*   **Payment Methods** — Shared payment instruments
*   **Historical Data** — Past fraud patterns

## Risk Scoring System

Every conversion receives a risk score from 0-100 based on detected signals:

### Low Risk (0-30)

*   **Characteristics:** Clean signals, no red flags
*   **Action:** Processed normally, commission approved
*   **Review:** No manual review needed

### Medium Risk (31-70)

*   **Characteristics:** Some suspicious signals, inconclusive
*   **Action:** Flagged for review before commission approval
*   **Review:** Appears in review queue for manual decision

### High Risk (71-100)

*   **Characteristics:** Multiple strong fraud indicators
*   **Action:** Commission held pending investigation
*   **Review:** Requires manual approval to proceed

##### False Positives

The Fraud Agent errs on the side of caution. You'll occasionally see legitimate transactions flagged—for example, an affiliate who genuinely wants to buy your product. Review these quickly to maintain trust while protecting your program.

## Automated Actions

Configure how the Fraud Agent responds to detected fraud:

### Hold Commission

*   **Trigger:** Risk score above threshold (default: 50)
*   **Action:** Commission status set to "Held" pending review
*   **Notification:** Added to fraud review queue
*   **Resolution:** Manual approve or reject required

### Alert Admin

*   **Trigger:** High-risk conversion or pattern detected
*   **Action:** Real-time notification via configured channels
*   **Channels:** Email, Slack, SMS, in-app
*   **Priority:** Based on risk score and potential loss

### Warn Affiliate

*   **Trigger:** Suspicious activity detected (configurable threshold)
*   **Action:** Automated warning email to affiliate
*   **Content:** Explains policy violation without accusing
*   **Escalation:** Multiple warnings can trigger suspension

### Suspend Account

*   **Trigger:** Confirmed fraud or repeated violations
*   **Action:** Disable affiliate account immediately
*   **Commissions:** All pending commissions held for review
*   **Notification:** Email explaining suspension reason

### Block IP/Device

*   **Trigger:** Confirmed fraud from specific source
*   **Action:** Block IP or device fingerprint from future tracking
*   **Scope:** Applies to clicks and conversions
*   **Management:** Blocklist can be reviewed and updated

## Configuration Settings

Access settings at **AI → Agent Insights → Fraud Agent → Settings**.

### Risk Thresholds

*   **Auto-Approve Threshold** — Max score for automatic approval (default: 30)
*   **Review Threshold** — Score to trigger review queue (default: 50)
*   **Auto-Hold Threshold** — Score to automatically hold (default: 70)
*   **Suspend Threshold** — Score to trigger suspension consideration

### Detection Rules

*   **Self-Referral Detection** — Enable/disable, sensitivity
*   **IP Proximity** — How close IPs trigger flags
*   **Return Rate Threshold** — What return rate triggers alerts
*   **Click Velocity** — Maximum clicks per time period

### Action Settings

*   **Auto-Hold** — Automatically hold high-risk commissions
*   **Auto-Warn** — Send warning emails automatically
*   **Auto-Suspend** — Suspend after X confirmed violations
*   **Alert Recipients** — Who receives fraud notifications

## Fraud Review Queue

Access the fraud review queue at **Affiliates → Fraud Review**. Each flagged conversion shows:

*   **Risk Score** — Overall score with breakdown
*   **Triggered Rules** — Which detection rules fired
*   **Evidence** — Specific data points that caused flags
*   **Affiliate Context** — History, past flags, overall performance
*   **Actions** — Approve, reject, investigate further, suspend

##### Batch Review

Use bulk actions to process similar flagged items quickly. For example, if multiple conversions are flagged due to a temporary VPN issue, you can approve them all at once.

## Allowlists & Blocklists

### Allowlists

*   **Trusted Affiliates** — Skip fraud checks for verified partners
*   **IP Allowlist** — Known good IPs (e.g., office networks)
*   **Email Domains** — Corporate domains to trust

### Blocklists

*   **IP Blocklist** — Known fraudulent IPs
*   **Device Blocklist** — Blocked device fingerprints
*   **Email Blocklist** — Blocked email addresses or domains

## Performance Metrics

Track fraud detection effectiveness:

#### Key Metrics

*   Fraud Prevented ($) — Estimated value of blocked fraudulent commissions
*   Flagged Conversions — Total conversions flagged for review
*   Confirmed Fraud — Conversions confirmed as fraudulent
*   False Positive Rate — % of flagged conversions that were legitimate
*   Detection by Type — Breakdown by fraud category
*   Affiliate Suspensions — Accounts suspended for fraud
*   Avg. Review Time — Time to resolve flagged items

## Integration with Payout Agent

The Fraud Agent works closely with the Payout Agent:

*   **Pre-Payout Check** — All pending commissions checked before payout
*   **Risk Score Threshold** — Payout Agent respects fraud holds
*   **Batch Review** — Bulk review before payout processing
*   **Audit Trail** — Full logging for compliance

## Best Practices

### Review Regularly

*   Check fraud queue daily or before each payout run
*   Don't let flagged items sit—affiliates notice delayed commissions
*   Document decisions for future reference

### Calibrate Thresholds

*   Start with defaults, adjust based on your false positive rate
*   If reviewing too many legitimate conversions, raise thresholds
*   If fraud is slipping through, lower thresholds

### Communicate with Affiliates

*   Clear terms of service about prohibited behavior
*   Quick response to affiliate questions about held commissions
*   Fair appeals process for disputed flags

## Troubleshooting

### Too Many False Positives

*   Raise risk thresholds for flagging
*   Add trusted affiliates to allowlist
*   Review which rules trigger most flags and adjust

### Missed Fraud

*   Lower detection thresholds
*   Enable additional detection methods
*   Review patterns from confirmed fraud cases

## Next Steps

[

### Payout Agent

Commission processing and payments

Learn more



](https://chargezen.com/docs/spark/ai-agents/payout-agent)[

### Approval Workflows

Configure affiliate vetting

Learn more



](https://chargezen.com/docs/spark/affiliate-management/approval-workflows)

### Related Articles

[

#### Approval Workflows

Review affiliate applications



](https://chargezen.com/docs/spark/affiliate-management/approval-workflows)[

#### Payout Agent

Commission processing



](https://chargezen.com/docs/spark/ai-agents/payout-agent)[

#### AI Agents Overview

All agents



](https://chargezen.com/docs/spark/ai-agents/overview)

Was this page helpful?

Need more help? [Contact support](https://chargezen.com/docs/checkoutos/troubleshooting/support)
