Skip to main content
Image coming soon

The Marketplace Fraud Analyst's Rule-Authoring Playbook

$199.00
Adding to cart… The item has been added

A focused course, tailored for you

The Marketplace Fraud Analyst's Rule-Authoring Playbook

Write, tune, and defend chargeback and account-takeover rules on a high-volume marketplace platform, without breaking merchant checkout.

A chargeback that every existing rule passed. A false decline a merchant escalated to your VP. A queue that grew faster than the policy could keep up. The job is rule-authoring under load, and the toolkit you were given on day one stops scaling about six months in.

$199 one-time
Tailored to your situation. Access within 24 hours. 30-day money-back.

Includes a hand-built implementation playbook delivered alongside course access, generated for your specific situation.

Why this course

A fraud and risk analyst on a marketplace platform is the person who decides which transactions go through, which go to manual review, and which get declined outright. The rules ship in production within hours of being written. They affect thousands of merchants who never see the policy text and only see the outcome at their settlement. When a rule is too tight, merchants escalate false declines to account managers who escalate to your director. When a rule is too loose, chargebacks land back at the platform's representment desk and the loss column grows. The craft is finding the policy line that holds both sides, defending it with evidence when either side pushes, and tuning it as the fraud pattern moves. Most analysts learn this by being burned on individual cases. There is no published curriculum because every marketplace's transaction mix is different and the platforms guard their rule logic tightly. This course is the curriculum a senior analyst would teach a peer if they had time to write it down.

What you walk away with

  • Author a fraud rule that names its precondition, decision logic, false-positive tolerance, evidence requirement, and revert criterion before it ships.
  • Build a rule-tuning workbook that lets you defend any production rule in a Monday review without re-doing the analysis.
  • Evidence a false decline back to the affected merchant with a one-page artefact they can forward to their internal team.
  • Instrument a queue-aware policy that adjusts manual-review thresholds without trapping legitimate customers during peak load.
  • Run a representment-ready chargeback case file that the disputes team can submit without going back to you for missing context.

The 12 modules

Module 1. The rule-authoring brief
Every production rule starts as a one-page brief naming the fraud pattern observed, the merchant cohort affected, the false-positive tolerance the merchant team has signed off on, the evidence required to fire the rule, and the revert criterion. This module walks through writing the brief for a velocity rule, a device-reuse rule, and a card-testing rule, and shows the three brief shapes that survive a tuning review versus the two that get rewritten.
Module 2. Reading the chargeback log past the headline reason code
Issuers report a reason code that rarely matches what actually happened. This module covers reading the underlying authorisation trail, the device-and-account history, and the merchant-side settlement record together. You leave with a chargeback-triage routine that classifies each case as friendly-fraud, true-fraud, merchant-error, or rule-miss within twenty minutes, and a documented handoff for each path.
Module 3. Velocity windows that survive a holiday spike
Velocity rules tuned in a quiet week break on the first day of a sale event. This module covers writing velocity logic that respects merchant cohort, time-of-day, and queue depth, including the three velocity shapes (fixed window, rolling window, exponential decay) and which fraud pattern each one catches. The workbook gives you the calibration approach for your own platform's transaction mix.
Module 4. Device fingerprint and the account-takeover signal
Device fingerprints decay. Account-takeover attempts look identical to a legitimate session from a returning customer who replaced a phone. This module covers reading the device signal alongside the password-reset history, the IP geography, and the order-pattern shift, and writing a takeover rule that fires before the first fraudulent order ships rather than after.
Module 5. Card-testing patterns and the merchant tier they target
Card testers pick merchants whose checkout flow lets the test pass quickly and cheaply. This module covers the four card-testing patterns currently active on marketplace platforms, the merchant attributes that make a merchant a target, and the rule shape that stops the test at the first request without breaking the merchant's checkout for legitimate customers.
Module 6. False-decline evidence for the merchant escalation
When a merchant escalates a false decline, the merchant team will ask you for evidence. This module covers the one-page false-decline artefact: the order, the signals the rule read, the customer's full history with the platform, the comparable orders the rule did not decline, and the policy change being considered. The format works for any rule and forwards cleanly to a merchant who does not read policy text.
Module 7. Queue-aware manual review thresholds
The manual review queue depth changes by the hour. A threshold that holds on a Tuesday morning floods the queue on a Friday night. This module covers writing queue-aware policy that scales the manual-review band by current load, the SLA the merchant team has agreed to, and the analyst headcount on shift. The result is fewer cases auto-released at peak and fewer good customers held overnight.
Module 8. The rule-tuning review and how to defend a policy
Every production rule gets reviewed periodically. Trust and Safety wants it widened, Merchant Success wants it narrowed, Finance wants the loss line moved. This module covers the four-part defence: the original brief, the production performance, the affected cohort analysis, and the proposed tuning with a revert criterion. You leave with the review template and the three answers that close the meeting.
Module 9. Friendly fraud and the policy that does not chase it
Some chargeback patterns are not fraud, they are buyer remorse the issuer let through as fraud. Writing a rule to catch friendly fraud burns false-positive budget and rarely recovers the loss. This module covers identifying friendly-fraud cohorts, the merchant-side action that addresses them (returns policy, dispute representment, customer communication), and the policy boundary that keeps the fraud team from chasing them.
Module 10. Representment-ready case files
The disputes team has minutes per chargeback to assemble a representment. If your case file is missing a single artefact, the chargeback is lost. This module covers the representment-ready file: the device and account history at the time of the order, the customer's prior order history, the shipping and tracking trail, the rule trace, and the merchant's communication record. The file template plugs into your disputes team's submission without rework.
Module 11. Communicating policy change to the merchant team
A rule tightening affects merchants who never see the policy. A rule loosening affects the loss line nobody wants to defend. This module covers the three-paragraph policy-change note: the fraud pattern that prompted the change, the cohort of merchants affected, and the metric the change will move with a revert criterion. The note format closes the loop with merchant managers without inviting policy negotiation in the comments.
Module 12. The analyst's quarterly evidence file
At the end of every quarter the manager who reports your chargeback ratio to a VP needs evidence that the analysis you did changed an outcome. This module covers the quarterly evidence file: the rules authored, the rules tuned, the chargeback cohorts moved, the false-decline artefacts you owned, and the policy reviews you defended. The file format makes the case for the senior-analyst conversation that gets had on a Friday afternoon over coffee.

How this addresses your situation

Specific modules that map to what you said you are dealing with.

Modules 1, 8, 11 cover the rule-authoring craft: brief, defence, change communication.
Modules 2, 3, 4, 5 cover the four fraud-pattern families and the rule shape each one requires.
Modules 6, 7, 9, 10 cover the operational surface: false-decline evidence, queue-awareness, friendly-fraud boundary, representment files.
Module 12 covers the quarterly self-evidence file that makes the case for the next analyst conversation.

What you get with this course

  • Twelve written modules in the Art of Service learning environment, each with worked examples drawn from marketplace and payments platform fraud operations.
  • Downloadable rule-authoring brief template, false-decline merchant artefact template, representment-ready case file template, quarterly evidence file template, and tuning-review defence template.
  • Hand-built implementation playbook tailored to your platform's transaction mix, merchant cohort structure, and current rule inventory, delivered alongside course access.
  • Thirty-day money-back guarantee on course access.
  • Single-user licence.

What you will have in hand by Day 1, Week 1, Month 1

Within twenty-four hours of purchase: full course access in the Art of Service learning environment, every template available for download.

Within twenty-four hours of purchase: hand-built implementation playbook delivered to the email on file, tailored to the buyer's platform context.

Self-paced through the twelve modules, suggested cadence of one module per working day for a two-and-a-half week run.

Before and after

Before

Rules go to production with a one-line description. Tuning reviews turn into debates because nobody has the original brief. False-decline escalations land on your desk without evidence and you rebuild the analysis from scratch every time. The quarterly conversation with your manager is about ratios, not about the work you did.

After

Every rule ships with a written brief that names its tolerance and revert criterion. Tuning reviews close in one meeting because the defence is pre-assembled. False-decline escalations are answered with a one-page artefact the merchant team can forward. The quarterly conversation names the cohorts you moved and the policy decisions you owned.

What happens if you do not address this

The rule-authoring craft is not in any vendor curriculum and most platforms do not write it down. Without a deliberate brief, defence, and evidence routine, a marketplace fraud analyst stays in case-by-case mode. Chargeback ratios move, but the analyst does not have the artefact trail that names which decisions moved them. The senior-analyst conversation gets had with someone who can show that trail.

Who it is for

Mid-level fraud and risk analyst at a marketplace, payments, or e-commerce platform. Writes production rules in a policy engine. Sits between Trust and Safety, Merchant Success, and Finance. Reports a chargeback ratio and a false-decline rate to a manager who reports both to a VP. Has been in role twelve to thirty months, knows the engine, wants the senior-analyst rule-authoring craft.

Who this is NOT for. Not for someone who has never written a production fraud rule. Not for compliance generalists who do not own policy outcomes. Not for engineers who build the policy engine but do not author the rules. Not for executives who set the chargeback target but do not tune the policy.

How it arrives

Text-based course in the Art of Service learning environment, plus downloadable templates and worked examples for every module, plus the hand-built implementation playbook delivered alongside course access.

Time investment. Forty-five to seventy minutes per module. Roughly twelve hours total across twelve modules, plus one to two hours adapting each template to your platform's rule engine and merchant cohort structure.

Why $199 is the right number

Vendor fraud-engine training covers the engine, not the rule-authoring craft. Industry conferences cover war stories, not the brief-and-defence routine. Internal mentoring depends on who happens to be senior on your team and whether they have time to write it down. This course is the written craft, the templates, and an implementation playbook tuned to your platform's transaction mix.

FAQ

Is this tied to one specific fraud-engine vendor?
No. The rule-authoring brief, the false-decline artefact, the representment file, and the defence template work in any policy engine. The implementation playbook is hand-built against the engine and cohort structure of the platform the buyer names at purchase.
Will this work for an analyst who owns both fraud and abuse policy?
Yes. The brief, the evidence artefact, and the defence template extend to abuse-policy rules with minor adaptation noted in the implementation playbook.
Can I share access with a teammate?
The licence is single-user. Team licences and a workshop format are available on request.
How is this delivered?
Written modules in the Art of Service learning environment plus downloadable templates plus the hand-built implementation playbook delivered alongside course access. Self-paced, no live sessions, no audio narration.
What if it does not fit my platform's setup?
Thirty-day money-back guarantee on course access. The implementation playbook is hand-built per buyer, so any context mismatch is resolved during delivery.

30-day money-back guarantee. If after a week of working through the materials this is not what you needed, reply to the receipt email and a full refund is processed. No questions, no forms.

Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.