# FraudAlert

object type

A FraudAlert — the merchant TRIAGE register over the derived fraud-signal layer: a signal crossing a policy threshold raises an alert naming the signal family (void_no_sale · return_refund_abuse · discount_override_abuse · override_pattern · cash_over_short · dispute_chargeback), the normalized score (0..100) vs the crossed threshold, the implicated staff principal and/or facility, the scoring window, and the triggering records. SIGNALS, NOT ENFORCEMENT: the / authority layer enforces; an alert only records and asks. SYSTEM-RAISED end to end — no create surface exists; the merchant triages: acknowledge (open → acknowledged — investigating; disarms the age-out), then confirm (a KEPT immutable finding — terminal but NOT doomed) or dismiss (a false positive — the reason is REQUIRED). Untriaged alerts age out after 30 days (open → expired, the scheduled lane). Triage identity/notes are the revision causes (History + the org-bus render actor + reason + instant — never duplicated fields). NOT searchable (sensitive review data — reached via the A17_FRAUD-gated paginated listing, never name-found); the listing pages NEWEST-first and drops doomed (dismissed/expired) per the - law while confirmed findings stay listed.

## Fields

| Field | Type | Notes |
| --- | --- | --- |
| `id` | [ID](/types/#scalars) `ID!` | The record’s id — a UUID the platform assigned when the record was created; every reference to this record uses it. |
| `sysId` | [String](/types/#scalars) `String!` | The group-scoped human-facing system id (FA-…). |
| `type` | [String](/types/#scalars) `String!` | The kind of record — always `FraudAlert` here. |
| `caption` | [String](/types/#scalars) `String!` | The record’s display name — what people see it called. |
| `status` | [String](/types/#scalars) `String!` | The FSM state: open \| acknowledged \| confirmed \| dismissed \| expired. |
| `parentId` | [ID](/types/#scalars) `ID!` | The parent = the org GROUP; parentId === rootId always (the WebhookSubscription class — the register is group custody). |
| `rootId` | [ID](/types/#scalars) `ID!` | The org-group family root. |
| `createdAt` | [String](/types/#scalars) `String!` | When the record was created, as a UTC timestamp. |
| `updatedAt` | [String](/types/#scalars) `String!` | When the record last changed, as a UTC timestamp. |
| `revisionNum` | [Int](/types/#scalars) `Int!` | How many times this record has been edited; the first save is 0. |
| `revision` | [ID](/types/#scalars) `ID!` | The OCC revision token — supply it on every mutation of this record; rotates on every write. |
| `refCaptions` | [RefCaption](/types/RefCaption/) `[RefCaption!]!` | The server-composed captions of this record's declared references (the referenced-caption rule) — one row per referenced id; see RefCaption. |
| `signalKind` | [String](/types/#scalars) `String!` | WHICH derived-signal family fired (void_no_sale · return_refund_abuse · discount_override_abuse · override_pattern · cash_over_short · dispute_chargeback — the two-layer law: the canon's six, membership IS the vocabulary). |
| `score` | [Int](/types/#scalars) `Int!` | The scorer's normalized score for the window (0..100). |
| `threshold` | [Int](/types/#scalars) `Int!` | The policy bound the score crossed (the same scale — v1 canned consts; the policy layer composes real merchant thresholds later, disclosed). |
| `reason` | [String](/types/#scalars) `String!` | The scorer's bounded human explanation (≤500) — never raw event data. |
| `periodKey` | [String](/types/#scalars) `String!` | The scoring window — a UTC month (YYYY-MM) or day (YYYY-MM-DD); the scorer picks the grain per signal kind. |
| `implicatedUserId` | [ID](/types/#scalars) | The implicated staff principal (scored per cashier); in-group-gated at raise, ANY status (the review judges PAST conduct); null when the signal implicates a facility/period only. |
| `logicalFacilityId` | [ID](/types/#scalars) | The implicated facility (scored per LF); in-group-gated at raise; null when the signal implicates a person/period only. |
| `constructRefs` | [TaskConstructRef](/types/TaskConstructRef/) `[TaskConstructRef!]!` | The triggering records (≤20 — the Task {type, id} structured-ref shape reused, the Suggestion evidenceRefs precedent): advisory evidence the scorer derived from the lake; nothing gates on them, a purged target renders as a tombstone. |
| `expiresAt` | [String](/types/#scalars) `String!` | WHEN an untriaged (open) alert ages out (raise + 30 days — the scheduled lane fires open → expired; acknowledging disarms it). |

## Used by

- [acknowledgeFraudAlert](/reference/fraud-alert/acknowledgeFraudAlert/)
- [confirmFraudAlert](/reference/fraud-alert/confirmFraudAlert/)
- [dismissFraudAlert](/reference/fraud-alert/dismissFraudAlert/)
- [fraudAlert](/reference/fraud-alert/fraudAlert/)
