# Fraud alert

The `FraudAlert` family — 5 operations.

A fraud alert is the platform flagging a suspicious pattern — voids, refunds, overrides, cash variances — with a score, the window it scored, and the implicated person or location. It signals, never enforces: acknowledge it to investigate, then confirm the finding (kept forever) or dismiss it with a reason. Untriaged alerts age out after 30 days.

## Operations

| Operation | Kind | What it does |
| --- | --- | --- |
| [acknowledgeFraudAlert](/reference/fraud-alert/acknowledgeFraudAlert/) | mutation | Take a fraud alert under investigation. |
| [confirmFraudAlert](/reference/fraud-alert/confirmFraudAlert/) | mutation | Record a fraud alert as a CONFIRMED finding. |
| [dismissFraudAlert](/reference/fraud-alert/dismissFraudAlert/) | mutation | Dismiss a fraud alert as a false positive — the reason is required. |
| [fraudAlert](/reference/fraud-alert/fraudAlert/) | query | One fraud alert — which signal fired, the score, who or where it implicates, and the evidence records. |
| [fraudAlerts](/reference/fraud-alert/fraudAlerts/) | query | Your group’s fraud alerts, newest first — dismissed and expired ones drop off the list (each stays reachable by id). |
