The alert
The whole product is this message, weeks early
Everyone in this category ships a queue. Queues get worked in the order the scores came out, and the scores come from labels that do not exist yet. This arrives on the day the population changed, with the segment named and the corroborating signals already counted.
- 1.Step up verification on affiliate-b registrations from Aug 13 forward.
- 2.Pull the reused device fingerprints and check for a shared ASN or emulator signature.
- 3.Confirm with the affiliate team that no promotion or traffic-source change landed on Aug 13.
- 4.Label the flagged cohort now so the supervised model has training data before the chargebacks arrive.
- 1.Step up verification on affiliate-b registrations from Aug 13 forward.
- 2.Pull the reused device fingerprints and check for a shared ASN or emulator signature.
- 3.Confirm with the affiliate team that no promotion or traffic-source change landed on Aug 13.
- 4.Label the flagged cohort now so the supervised model has training data before the chargebacks arrive.
Nothing worth reading. The detector found no regime change in it at any confidence, and the naive 2.5σ rule fired on it 1 times over the same window, every one of them noise. A dispute on an August 13 transaction is filed in September at the earliest and can arrive as late as December, so the metric the fraud team watches is the one that is structurally last to move.
Statistics decide whether the population changed. Corroboration decides whether it is worth waking someone. Only then does the model write the explanation, and it only ever sees a confirmed changepoint. A drift detector that alerts on one moving signal is a campaign detector, and it gets muted in a month.