<!-- CANARY: REQ=REQ-DOCS-001; FEATURE="Docs"; ASPECT=Documentation; STATUS=TESTED; OWNER=docs; UPDATED=2026-01-15 --> <h2 id="fraud-and-anomaly-detection" class="position-relative d-flex align-items-center group"> <span>Fraud and Anomaly Detection</span> <button type="button" class="h-share btn btn-link p-0 text-decoration-none link-secondary opacity-50 hover-opacity-100 transition-all ms-1" data-share-target="fraud-and-anomaly-detection" aria-haspopup="dialog" aria-label="Share link: Fraud and Anomaly Detection"> <i class="fa-sharp-duotone fa-solid fa-share-nodes" aria-hidden="true" style="font-size: 0.8em;"></i> <span class="visually-hidden">Share link</span> </button> </h2><div id="headingShareModal" class="heading-share-modal" role="dialog" aria-modal="true" aria-labelledby="headingShareTitle" hidden> <div class="hsm-dialog" role="document"> <div class="hsm-header"> <h2 id="headingShareTitle" class="h6 mb-0 fw-bold">Share this section</h2> <button type="button" class="hsm-close" aria-label="Close"> <i class="fa-solid fa-xmark"></i> </button> </div> <div class="hsm-body"> <label for="headingShareInput" class="form-label small text-muted mb-1 text-uppercase fw-bold" style="font-size: 0.7rem; letter-spacing: 0.5px;">Permalink</label> <div class="input-group mb-4 hsm-url-group"> <input id="headingShareInput" type="text" class="form-control font-monospace" readonly aria-readonly="true" style="font-size: 0.85rem;" /> <button class="btn btn-primary hsm-copy" type="button" aria-label="Copy" title="Copy"> <i class="fa-duotone fa-clipboard" aria-hidden="true"></i> </button> </div> <div class="small fw-bold mb-2 text-muted text-uppercase" style="font-size: 0.7rem; letter-spacing: 0.5px;">Share via</div> <div class="hsm-share-grid"> <a id="share-twitter" class="btn btn-outline-secondary w-100" target="_blank" rel="noopener noreferrer"> <i class="fa-brands fa-twitter me-2"></i>Twitter </a> <a id="share-linkedin" class="btn btn-outline-secondary w-100" target="_blank" rel="noopener noreferrer"> <i class="fa-brands fa-linkedin me-2"></i>LinkedIn </a> <a id="share-facebook" class="btn btn-outline-secondary w-100" target="_blank" rel="noopener noreferrer"> <i class="fa-brands fa-facebook me-2"></i>Facebook </a> </div> </div> </div> </div> <style> .heading-share-modal { position: fixed; inset: 0; display: flex; justify-content: center; align-items: center; background: rgba(0, 0, 0, 0.6); z-index: 1050; padding: 1rem; backdrop-filter: blur(4px); -webkit-backdrop-filter: blur(4px); } .heading-share-modal[hidden] { display: none !important; } .hsm-dialog { max-width: 420px; width: 100%; background: var(--bs-body-bg, #fff); color: var(--bs-body-color, #212529); border: 1px solid var(--bs-border-color, rgba(0,0,0,0.1)); border-radius: 1rem; box-shadow: 0 25px 50px -12px rgba(0, 0, 0, 0.25); overflow: hidden; animation: hsm-fade-in 0.2s ease-out; } @keyframes hsm-fade-in { from { opacity: 0; transform: scale(0.95); } to { opacity: 1; transform: scale(1); } } [data-bs-theme="dark"] .hsm-dialog { background: #1e293b; border-color: rgba(255,255,255,0.1); color: #f8f9fa; } .hsm-header { display: flex; justify-content: space-between; align-items: center; padding: 1rem 1.5rem; border-bottom: 1px solid var(--bs-border-color, rgba(0,0,0,0.1)); background: rgba(0,0,0,0.02); } [data-bs-theme="dark"] .hsm-header { background: rgba(255,255,255,0.02); border-color: rgba(255,255,255,0.1); } .hsm-close { background: transparent; border: none; color: inherit; opacity: 0.5; padding: 0.25rem 0.5rem; border-radius: 0.25rem; font-size: 1.2rem; line-height: 1; transition: opacity 0.2s; } .hsm-close:hover { opacity: 1; } .hsm-body { padding: 1.5rem; } .hsm-url-group { display: flex !important; align-items: stretch; } .hsm-url-group .form-control { flex: 1; min-width: 0; margin: 0; background: var(--bs-secondary-bg, #f8f9fa); border-color: var(--bs-border-color, #dee2e6); border-top-right-radius: 0; border-bottom-right-radius: 0; height: 42px; } .hsm-url-group .btn { flex: 0 0 auto; margin: 0; margin-left: -1px; border-top-left-radius: 0; border-bottom-left-radius: 0; height: 42px; display: flex; align-items: center; justify-content: center; padding: 0 1.25rem; z-index: 2; } [data-bs-theme="dark"] .hsm-url-group .form-control { background: #0f172a; border-color: #334155; color: #e2e8f0; } .hsm-share-grid { display: flex; flex-direction: column; gap: 0.5rem; } .hsm-share-grid .btn { display: flex; align-items: center; justify-content: center; font-size: 0.9rem; padding: 0.6rem; border-color: var(--bs-border-color); width: 100%; } [data-bs-theme="dark"] .hsm-share-grid .btn { color: #e2e8f0; border-color: #475569; } [data-bs-theme="dark"] .hsm-share-grid .btn:hover { background: #334155; border-color: #cbd5e1; } </style> <script> (function(){ const modal = document.getElementById('headingShareModal'); if(!modal) return; const input = modal.querySelector('#headingShareInput'); const copyBtn = modal.querySelector('.hsm-copy'); const twitter = modal.querySelector('#share-twitter'); const linkedin = modal.querySelector('#share-linkedin'); const facebook = modal.querySelector('#share-facebook'); const closeBtn = modal.querySelector('.hsm-close'); let lastFocus=null; let trapBound=false; function buildUrl(id){ return window.location.origin + window.location.pathname + '#' + id; } function isOpen(){ return !modal.hasAttribute('hidden'); } function hydrate(id){ const url=buildUrl(id); input.value=url; const enc=encodeURIComponent(url); const text=encodeURIComponent(document.title); if(twitter) twitter.href=`https://twitter.com/intent/tweet?url=${enc}&text=${text}`; if(linkedin) linkedin.href=`https://www.linkedin.com/sharing/share-offsite/?url=${enc}`; if(facebook) facebook.href=`https://www.facebook.com/sharer/sharer.php?u=${enc}`; } function openModal(id){ lastFocus=document.activeElement; hydrate(id); if(!isOpen()){ modal.removeAttribute('hidden'); } requestAnimationFrame(()=>{ input.focus(); }); trapFocus(); } function closeModal(){ if(!isOpen()) return; modal.setAttribute('hidden',''); if(lastFocus && typeof lastFocus.focus==='function') lastFocus.focus(); } function copyCurrent(){ try{ navigator.clipboard.writeText(input.value).then(()=>feedback(true),()=>fallback()); } catch(e){ fallback(); } } function fallback(){ input.select(); try{ document.execCommand('copy'); feedback(true);}catch(e){ feedback(false);} } function feedback(ok){ if(!copyBtn) return; const icon=copyBtn.querySelector('i'); if(!icon) return; const prev=copyBtn.getAttribute('data-prev')||icon.className; if(!copyBtn.getAttribute('data-prev')) copyBtn.setAttribute('data-prev',prev); icon.className= ok ? 'fa-duotone fa-clipboard-check':'fa-duotone fa-circle-exclamation'; setTimeout(()=>{ icon.className=prev; },1800); } function handleShareClick(e){ e.preventDefault(); const btn=e.currentTarget; const id=btn.getAttribute('data-share-target'); if(id) openModal(id); } function bindShareButtons(){ document.querySelectorAll('.h-share').forEach(btn=>{ if(!btn.dataset.hShareBound){ btn.addEventListener('click', handleShareClick); btn.dataset.hShareBound='1'; } }); } bindShareButtons(); if(document.readyState==='loading'){ document.addEventListener('DOMContentLoaded', bindShareButtons); } else { requestAnimationFrame(bindShareButtons); } document.addEventListener('click', function(e){ const shareBtn=e.target.closest && e.target.closest('.h-share'); if(shareBtn && !shareBtn.dataset.hShareBound){ handleShareClick.call(shareBtn, e); } }, true); document.addEventListener('click', e=>{ if(e.target===modal) closeModal(); if(e.target.closest && e.target.closest('.hsm-close')){ e.preventDefault(); closeModal(); } if(copyBtn && (e.target===copyBtn || (e.target.closest && e.target.closest('.hsm-copy')))) { e.preventDefault(); copyCurrent(); } }); document.addEventListener('keydown', e=>{ if(e.key==='Escape' && isOpen()) closeModal(); }); function trapFocus(){ if(trapBound) return; trapBound=true; modal.addEventListener('keydown', f=>{ if(f.key==='Tab' && isOpen()){ const focusable=[...modal.querySelectorAll('a[href],button,input,textarea,select,[tabindex]:not([tabindex="-1"])')].filter(el=>!el.hasAttribute('disabled')); if(!focusable.length) return; const first=focusable[0]; const last=focusable[focusable.length-1]; if(f.shiftKey && document.activeElement===first){ f.preventDefault(); last.focus(); } else if(!f.shiftKey && document.activeElement===last){ f.preventDefault(); first.focus(); } } }); } if(closeBtn) closeBtn.addEventListener('click', e=>{ e.preventDefault(); closeModal(); }); })(); </script><p>Build a real-time fraud detection system using graph patterns, machine learning embeddings, and change data capture (CDC).</p> <h3 id="problem-statement" class="position-relative d-flex align-items-center group"> <span>Problem Statement</span> <button type="button" class="h-share btn btn-link p-0 text-decoration-none link-secondary opacity-50 hover-opacity-100 transition-all ms-1" data-share-target="problem-statement" aria-haspopup="dialog" aria-label="Share link: Problem Statement"> <i class="fa-sharp-duotone fa-solid fa-share-nodes" aria-hidden="true" style="font-size: 0.8em;"></i> <span class="visually-hidden">Share link</span> </button> </h3><p>Financial fraud is a graph problem:</p> <ul> <li><strong>Transaction rings</strong>: Multiple accounts transferring funds in circles</li> <li><strong>Velocity anomalies</strong>: Unusual transaction patterns (frequency, amount, location)</li> <li><strong>Network effects</strong>: Compromised accounts infecting connected accounts</li> <li><strong>Synthetic identities</strong>: Fabricated identities with suspicious relationship patterns</li> </ul> <p>Traditional rule-based systems miss complex patterns. Graph databases excel at detecting these relationships.</p> <h3 id="graph-model" class="position-relative d-flex align-items-center group"> <span>Graph Model</span> <button type="button" class="h-share btn btn-link p-0 text-decoration-none link-secondary opacity-50 hover-opacity-100 transition-all ms-1" data-share-target="graph-model" aria-haspopup="dialog" aria-label="Share link: Graph Model"> <i class="fa-sharp-duotone fa-solid fa-share-nodes" aria-hidden="true" style="font-size: 0.8em;"></i> <span class="visually-hidden">Share link</span> </button> </h3> <h4 id="schema" class="position-relative d-flex align-items-center group"> <span>Schema</span> <button type="button" class="h-share btn btn-link p-0 text-decoration-none link-secondary opacity-50 hover-opacity-100 transition-all ms-1" data-share-target="schema" aria-haspopup="dialog" aria-label="Share link: Schema"> <i class="fa-sharp-duotone fa-solid fa-share-nodes" aria-hidden="true" style="font-size: 0.8em;"></i> <span class="visually-hidden">Share link</span> </button> </h4><div class="highlight"><pre tabindex="0" class="chroma"><code class="language-gql" data-lang="gql"><span class="line"><span class="cl"><span class="err">--</span><span class="w"> </span><span class="py">Create</span><span class="w"> </span><span class="py">graph</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="py">CREATE</span><span class="w"> </span><span class="py">GRAPH</span><span class="w"> </span><span class="py">PaymentNetwork</span><span class="err">;</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="py">USE</span><span class="w"> </span><span class="py">PaymentNetwork</span><span class="err">;</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="err">--</span><span class="w"> </span><span class="py">Nodes</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="p">(:</span><span class="nc">Account</span><span class="w"> </span><span class="p">{</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="py">id</span><span class="p">:</span><span class="w"> </span><span class="nc">UUID</span><span class="p">,</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="py">holder_name</span><span class="p">:</span><span class="w"> </span><span class="nc">String</span><span class="p">,</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="py">email</span><span class="p">:</span><span class="w"> </span><span class="nc">String</span><span class="p">,</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="py">created_at</span><span class="p">:</span><span class="w"> </span><span class="nc">Timestamp</span><span class="p">,</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="py">risk_score</span><span class="p">:</span><span class="w"> </span><span class="nc">Float</span><span class="p">,</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="py">embedding</span><span class="p">:</span><span class="w"> </span><span class="nc">VectorF32</span><span class="w"> </span><span class="err">--</span><span class="w"> </span><span class="py">For</span><span class="w"> </span><span class="py">ML</span><span class="err">-</span><span class="py">based</span><span class="w"> </span><span class="py">similarity</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="p">})</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="p">(:</span><span class="nc">Transaction</span><span class="w"> </span><span class="p">{</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="py">id</span><span class="p">:</span><span class="w"> </span><span class="nc">UUID</span><span class="p">,</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="py">amount</span><span class="p">:</span><span class="w"> </span><span class="nc">Decimal</span><span class="p">,</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="py">timestamp</span><span class="p">:</span><span class="w"> </span><span class="nc">Timestamp</span><span class="p">,</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="py">status</span><span class="p">:</span><span class="w"> </span><span class="nc">String</span><span class="p">,</span><span class="w"> </span><span class="err">--</span><span class="w"> </span><span class="err">&#39;</span><span class="py">pending</span><span class="err">&#39;</span><span class="p">,</span><span class="w"> </span><span class="err">&#39;</span><span class="py">completed</span><span class="err">&#39;</span><span class="p">,</span><span class="w"> </span><span class="err">&#39;</span><span class="py">flagged</span><span class="err">&#39;</span><span class="p">,</span><span class="w"> </span><span class="err">&#39;</span><span class="py">blocked</span><span class="err">&#39;</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="py">merchant_category</span><span class="p">:</span><span class="w"> </span><span class="nc">String</span><span class="p">,</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="py">location</span><span class="p">:</span><span class="w"> </span><span class="nc">LatLon</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="p">})</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="p">(:</span><span class="nc">Device</span><span class="w"> </span><span class="p">{</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="py">id</span><span class="p">:</span><span class="w"> </span><span class="nc">UUID</span><span class="p">,</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="py">fingerprint</span><span class="p">:</span><span class="w"> </span><span class="nc">String</span><span class="p">,</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="py">ip_addr</span><span class="p">:</span><span class="w"> </span><span class="nc">IpAddr</span><span class="p">,</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="py">first_seen</span><span class="p">:</span><span class="w"> </span><span class="nc">Timestamp</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="p">})</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="err">--</span><span class="w"> </span><span class="py">Relationships</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="p">(:</span><span class="nc">Account</span><span class="p">)</span><span class="err">-</span><span class="p">[:</span><span class="nc">SENT</span><span class="w"> </span><span class="p">{</span><span class="py">timestamp</span><span class="p">:</span><span class="w"> </span><span class="nc">Timestamp</span><span class="p">}]</span><span class="err">-&gt;</span><span class="p">(:</span><span class="nc">Transaction</span><span class="p">)</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="p">(:</span><span class="nc">Transaction</span><span class="p">)</span><span class="err">-</span><span class="p">[:</span><span class="nc">RECEIVED_BY</span><span class="p">]</span><span class="err">-&gt;</span><span class="p">(:</span><span class="nc">Account</span><span class="p">)</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="p">(:</span><span class="nc">Account</span><span class="p">)</span><span class="err">-</span><span class="p">[:</span><span class="nc">USED_DEVICE</span><span class="w"> </span><span class="p">{</span><span class="py">first_used</span><span class="p">:</span><span class="w"> </span><span class="nc">Timestamp</span><span class="p">}]</span><span class="err">-&gt;</span><span class="p">(:</span><span class="nc">Device</span><span class="p">)</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="p">(:</span><span class="nc">Account</span><span class="p">)</span><span class="err">-</span><span class="p">[:</span><span class="nc">SHARES_INFO</span><span class="w"> </span><span class="p">{</span><span class="py">info_type</span><span class="p">:</span><span class="w"> </span><span class="nc">String</span><span class="p">}]</span><span class="err">-&gt;</span><span class="p">(:</span><span class="nc">Account</span><span class="p">)</span><span class="w"> </span><span class="err">--</span><span class="w"> </span><span class="py">email</span><span class="p">,</span><span class="w"> </span><span class="py">phone</span><span class="p">,</span><span class="w"> </span><span class="py">address</span><span class="w"> </span></span></span></code></pre></div> <h4 id="example-data" class="position-relative d-flex align-items-center group"> <span>Example Data</span> <button type="button" class="h-share btn btn-link p-0 text-decoration-none link-secondary opacity-50 hover-opacity-100 transition-all ms-1" data-share-target="example-data" aria-haspopup="dialog" aria-label="Share link: Example Data"> <i class="fa-sharp-duotone fa-solid fa-share-nodes" aria-hidden="true" style="font-size: 0.8em;"></i> <span class="visually-hidden">Share link</span> </button> </h4><div class="highlight"><pre tabindex="0" class="chroma"><code class="language-gql" data-lang="gql"><span class="line"><span class="cl"><span class="err">--</span><span class="w"> </span><span class="py">Create</span><span class="w"> </span><span class="py">accounts</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="py">CREATE</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="p">(:</span><span class="nc">Account</span><span class="w"> </span><span class="p">{</span><span class="py">id</span><span class="p">:</span><span class="w"> </span><span class="nc">gen_random_uuid</span><span class="p">(),</span><span class="w"> </span><span class="py">holder_name</span><span class="p">:</span><span class="w"> </span><span class="s">&#34;Alice Smith&#34;</span><span class="p">,</span><span class="w"> </span><span class="nc">email</span><span class="p">:</span><span class="w"> </span><span class="s">&#34;[email protected]&#34;</span><span class="p">,</span><span class="w"> </span><span class="nc">created_at</span><span class="p">:</span><span class="w"> </span><span class="nc">timestamp</span><span class="p">(),</span><span class="w"> </span><span class="py">risk_score</span><span class="p">:</span><span class="w"> </span><span class="nc">0</span><span class="mf">.1</span><span class="p">}),</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="p">(:</span><span class="nc">Account</span><span class="w"> </span><span class="p">{</span><span class="py">id</span><span class="p">:</span><span class="w"> </span><span class="nc">gen_random_uuid</span><span class="p">(),</span><span class="w"> </span><span class="py">holder_name</span><span class="p">:</span><span class="w"> </span><span class="s">&#34;Bob Jones&#34;</span><span class="p">,</span><span class="w"> </span><span class="nc">email</span><span class="p">:</span><span class="w"> </span><span class="s">&#34;[email protected]&#34;</span><span class="p">,</span><span class="w"> </span><span class="nc">created_at</span><span class="p">:</span><span class="w"> </span><span class="nc">timestamp</span><span class="p">(),</span><span class="w"> </span><span class="py">risk_score</span><span class="p">:</span><span class="w"> </span><span class="nc">0</span><span class="mf">.2</span><span class="p">}),</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="p">(:</span><span class="nc">Account</span><span class="w"> </span><span class="p">{</span><span class="py">id</span><span class="p">:</span><span class="w"> </span><span class="nc">gen_random_uuid</span><span class="p">(),</span><span class="w"> </span><span class="py">holder_name</span><span class="p">:</span><span class="w"> </span><span class="s">&#34;Charlie Wilson&#34;</span><span class="p">,</span><span class="w"> </span><span class="nc">email</span><span class="p">:</span><span class="w"> </span><span class="s">&#34;[email protected]&#34;</span><span class="p">,</span><span class="w"> </span><span class="nc">created_at</span><span class="p">:</span><span class="w"> </span><span class="nc">timestamp</span><span class="p">(),</span><span class="w"> </span><span class="py">risk_score</span><span class="p">:</span><span class="w"> </span><span class="nc">0</span><span class="mf">.8</span><span class="p">})</span><span class="err">;</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="err">--</span><span class="w"> </span><span class="py">Create</span><span class="w"> </span><span class="py">transactions</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="py">MATCH</span><span class="w"> </span><span class="p">(</span><span class="py">alice</span><span class="p">:</span><span class="nc">Account</span><span class="w"> </span><span class="p">{</span><span class="py">holder_name</span><span class="p">:</span><span class="w"> </span><span class="s">&#34;Alice Smith&#34;</span><span class="p">}),</span><span class="w"> </span><span class="p">(</span><span class="nc">bob</span><span class="p">:</span><span class="nc">Account</span><span class="w"> </span><span class="p">{</span><span class="py">holder_name</span><span class="p">:</span><span class="w"> </span><span class="s">&#34;Bob Jones&#34;</span><span class="p">})</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="nc">CREATE</span><span class="w"> </span><span class="p">(</span><span class="py">tx</span><span class="p">:</span><span class="nc">Transaction</span><span class="w"> </span><span class="p">{</span><span class="py">id</span><span class="p">:</span><span class="w"> </span><span class="nc">gen_random_uuid</span><span class="p">(),</span><span class="w"> </span><span class="py">amount</span><span class="p">:</span><span class="w"> </span><span class="nc">decimal</span><span class="p">(</span><span class="err">&#39;</span><span class="py">1000</span><span class="mf">.00</span><span class="err">&#39;</span><span class="p">),</span><span class="w"> </span><span class="py">timestamp</span><span class="p">:</span><span class="w"> </span><span class="nc">timestamp</span><span class="p">(),</span><span class="w"> </span><span class="py">status</span><span class="p">:</span><span class="w"> </span><span class="err">&#39;</span><span class="nc">completed</span><span class="err">&#39;</span><span class="p">,</span><span class="w"> </span><span class="py">merchant_category</span><span class="p">:</span><span class="w"> </span><span class="err">&#39;</span><span class="nc">retail</span><span class="err">&#39;</span><span class="p">})</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="py">CREATE</span><span class="w"> </span><span class="p">(</span><span class="py">alice</span><span class="p">)</span><span class="err">-</span><span class="p">[:</span><span class="nc">SENT</span><span class="w"> </span><span class="p">{</span><span class="py">timestamp</span><span class="p">:</span><span class="w"> </span><span class="nc">timestamp</span><span class="p">()}]</span><span class="err">-&gt;</span><span class="p">(</span><span class="py">tx</span><span class="p">)</span><span class="err">-</span><span class="p">[:</span><span class="nc">RECEIVED_BY</span><span class="p">]</span><span class="err">-&gt;</span><span class="p">(</span><span class="py">bob</span><span class="p">)</span><span class="err">;</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="err">--</span><span class="w"> </span><span class="py">Shared</span><span class="w"> </span><span class="py">device</span><span class="w"> </span><span class="p">(</span><span class="py">suspicious</span><span class="p">)</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="py">MATCH</span><span class="w"> </span><span class="p">(</span><span class="py">alice</span><span class="p">:</span><span class="nc">Account</span><span class="w"> </span><span class="p">{</span><span class="py">holder_name</span><span class="p">:</span><span class="w"> </span><span class="s">&#34;Alice Smith&#34;</span><span class="p">}),</span><span class="w"> </span><span class="p">(</span><span class="nc">charlie</span><span class="p">:</span><span class="nc">Account</span><span class="w"> </span><span class="p">{</span><span class="py">holder_name</span><span class="p">:</span><span class="w"> </span><span class="s">&#34;Charlie Wilson&#34;</span><span class="p">})</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="nc">CREATE</span><span class="w"> </span><span class="p">(</span><span class="py">dev</span><span class="p">:</span><span class="nc">Device</span><span class="w"> </span><span class="p">{</span><span class="py">id</span><span class="p">:</span><span class="w"> </span><span class="nc">gen_random_uuid</span><span class="p">(),</span><span class="w"> </span><span class="py">fingerprint</span><span class="p">:</span><span class="w"> </span><span class="s">&#34;abc123&#34;</span><span class="p">,</span><span class="w"> </span><span class="nc">ip_addr</span><span class="p">:</span><span class="w"> </span><span class="err">&#39;</span><span class="nc">192</span><span class="mf">.168.1.100</span><span class="err">&#39;</span><span class="p">::</span><span class="nc">ipaddr</span><span class="p">})</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="nc">CREATE</span><span class="w"> </span><span class="p">(</span><span class="py">alice</span><span class="p">)</span><span class="err">-</span><span class="p">[:</span><span class="nc">USED_DEVICE</span><span class="w"> </span><span class="p">{</span><span class="py">first_used</span><span class="p">:</span><span class="w"> </span><span class="nc">timestamp</span><span class="p">()}]</span><span class="err">-&gt;</span><span class="p">(</span><span class="py">dev</span><span class="p">)</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="py">CREATE</span><span class="w"> </span><span class="p">(</span><span class="py">charlie</span><span class="p">)</span><span class="err">-</span><span class="p">[:</span><span class="nc">USED_DEVICE</span><span class="w"> </span><span class="p">{</span><span class="py">first_used</span><span class="p">:</span><span class="w"> </span><span class="nc">timestamp</span><span class="p">()}]</span><span class="err">-&gt;</span><span class="p">(</span><span class="py">dev</span><span class="p">)</span><span class="err">;</span><span class="w"> </span></span></span></code></pre></div> <h3 id="detection-patterns" class="position-relative d-flex align-items-center group"> <span>Detection Patterns</span> <button type="button" class="h-share btn btn-link p-0 text-decoration-none link-secondary opacity-50 hover-opacity-100 transition-all ms-1" data-share-target="detection-patterns" aria-haspopup="dialog" aria-label="Share link: Detection Patterns"> <i class="fa-sharp-duotone fa-solid fa-share-nodes" aria-hidden="true" style="font-size: 0.8em;"></i> <span class="visually-hidden">Share link</span> </button> </h3> <h4 id="1-transaction-ring-detection" class="position-relative d-flex align-items-center group"> <span>1. Transaction Ring Detection</span> <button type="button" class="h-share btn btn-link p-0 text-decoration-none link-secondary opacity-50 hover-opacity-100 transition-all ms-1" data-share-target="1-transaction-ring-detection" aria-haspopup="dialog" aria-label="Share link: 1. Transaction Ring Detection"> <i class="fa-sharp-duotone fa-solid fa-share-nodes" aria-hidden="true" style="font-size: 0.8em;"></i> <span class="visually-hidden">Share link</span> </button> </h4><p>Circular money flows indicating wash trading or money laundering:</p> <div class="highlight"><pre tabindex="0" class="chroma"><code class="language-gql" data-lang="gql"><span class="line"><span class="cl"><span class="err">--</span><span class="w"> </span><span class="py">Find</span><span class="w"> </span><span class="py">transaction</span><span class="w"> </span><span class="py">cycles</span><span class="w"> </span><span class="p">(</span><span class="py">A</span><span class="w"> </span><span class="err">-&gt;</span><span class="w"> </span><span class="py">B</span><span class="w"> </span><span class="err">-&gt;</span><span class="w"> </span><span class="py">C</span><span class="w"> </span><span class="err">-&gt;</span><span class="w"> </span><span class="py">A</span><span class="p">)</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="py">MATCH</span><span class="w"> </span><span class="py">path</span><span class="w"> </span><span class="p">=</span><span class="w"> </span><span class="p">(</span><span class="py">a</span><span class="p">:</span><span class="nc">Account</span><span class="p">)</span><span class="err">-</span><span class="p">[:</span><span class="nc">SENT</span><span class="p">]</span><span class="err">-&gt;</span><span class="p">(:</span><span class="nc">Transaction</span><span class="p">)</span><span class="err">-</span><span class="p">[:</span><span class="nc">RECEIVED_BY</span><span class="p">]</span><span class="err">-&gt;</span><span class="p">(</span><span class="py">b</span><span class="p">:</span><span class="nc">Account</span><span class="p">)</span><span class="err">-</span><span class="p">[:</span><span class="nc">SENT</span><span class="p">]</span><span class="err">-&gt;</span><span class="p">(:</span><span class="nc">Transaction</span><span class="p">)</span><span class="err">-</span><span class="p">[:</span><span class="nc">RECEIVED_BY</span><span class="p">]</span><span class="err">-&gt;</span><span class="p">(</span><span class="py">c</span><span class="p">:</span><span class="nc">Account</span><span class="p">)</span><span class="err">-</span><span class="p">[:</span><span class="nc">SENT</span><span class="p">]</span><span class="err">-&gt;</span><span class="p">(:</span><span class="nc">Transaction</span><span class="p">)</span><span class="err">-</span><span class="p">[:</span><span class="nc">RECEIVED_BY</span><span class="p">]</span><span class="err">-&gt;</span><span class="p">(</span><span class="py">a</span><span class="p">)</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="py">WHERE</span><span class="w"> </span><span class="py">length</span><span class="p">(</span><span class="py">path</span><span class="p">)</span><span class="w"> </span><span class="p">=</span><span class="w"> </span><span class="py">6</span><span class="w"> </span><span class="err">--</span><span class="w"> </span><span class="py">3</span><span class="w"> </span><span class="py">transactions</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="py">RETURN</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="py">a</span><span class="err">.</span><span class="py">holder_name</span><span class="w"> </span><span class="py">AS</span><span class="w"> </span><span class="py">account1</span><span class="p">,</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="py">b</span><span class="err">.</span><span class="py">holder_name</span><span class="w"> </span><span class="py">AS</span><span class="w"> </span><span class="py">account2</span><span class="p">,</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="py">c</span><span class="err">.</span><span class="py">holder_name</span><span class="w"> </span><span class="py">AS</span><span class="w"> </span><span class="py">account3</span><span class="p">,</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="py">length</span><span class="p">(</span><span class="py">path</span><span class="p">)</span><span class="w"> </span><span class="py">AS</span><span class="w"> </span><span class="py">cycle_length</span><span class="err">;</span><span class="w"> </span></span></span></code></pre></div> <h4 id="2-velocity-anomaly-detection" class="position-relative d-flex align-items-center group"> <span>2. Velocity Anomaly Detection</span> <button type="button" class="h-share btn btn-link p-0 text-decoration-none link-secondary opacity-50 hover-opacity-100 transition-all ms-1" data-share-target="2-velocity-anomaly-detection" aria-haspopup="dialog" aria-label="Share link: 2. Velocity Anomaly Detection"> <i class="fa-sharp-duotone fa-solid fa-share-nodes" aria-hidden="true" style="font-size: 0.8em;"></i> <span class="visually-hidden">Share link</span> </button> </h4><p>Accounts with unusual transaction frequency or amounts:</p> <div class="highlight"><pre tabindex="0" class="chroma"><code class="language-gql" data-lang="gql"><span class="line"><span class="cl"><span class="err">--</span><span class="w"> </span><span class="py">High</span><span class="err">-</span><span class="py">velocity</span><span class="w"> </span><span class="py">accounts</span><span class="w"> </span><span class="p">(</span><span class="err">&gt;</span><span class="py">10</span><span class="w"> </span><span class="py">transactions</span><span class="w"> </span><span class="py">in</span><span class="w"> </span><span class="py">1</span><span class="w"> </span><span class="py">hour</span><span class="p">)</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="py">MATCH</span><span class="w"> </span><span class="p">(</span><span class="py">a</span><span class="p">:</span><span class="nc">Account</span><span class="p">)</span><span class="err">-</span><span class="p">[:</span><span class="nc">SENT</span><span class="p">]</span><span class="err">-&gt;</span><span class="p">(</span><span class="py">tx</span><span class="p">:</span><span class="nc">Transaction</span><span class="p">)</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="py">WHERE</span><span class="w"> </span><span class="py">tx</span><span class="err">.</span><span class="py">timestamp</span><span class="w"> </span><span class="err">&gt;</span><span class="w"> </span><span class="py">timestamp</span><span class="p">()</span><span class="w"> </span><span class="err">-</span><span class="w"> </span><span class="py">interval</span><span class="p">(</span><span class="err">&#39;</span><span class="py">PT1H</span><span class="err">&#39;</span><span class="p">)</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="py">WITH</span><span class="w"> </span><span class="py">a</span><span class="p">,</span><span class="w"> </span><span class="py">COUNT</span><span class="p">(</span><span class="py">tx</span><span class="p">)</span><span class="w"> </span><span class="py">AS</span><span class="w"> </span><span class="py">tx_count</span><span class="p">,</span><span class="w"> </span><span class="py">SUM</span><span class="p">(</span><span class="py">tx</span><span class="err">.</span><span class="py">amount</span><span class="p">)</span><span class="w"> </span><span class="py">AS</span><span class="w"> </span><span class="py">total_amount</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="py">WHERE</span><span class="w"> </span><span class="py">tx_count</span><span class="w"> </span><span class="err">&gt;</span><span class="w"> </span><span class="py">10</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="py">RETURN</span><span class="w"> </span><span class="py">a</span><span class="err">.</span><span class="py">holder_name</span><span class="p">,</span><span class="w"> </span><span class="py">tx_count</span><span class="p">,</span><span class="w"> </span><span class="py">total_amount</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="py">ORDER</span><span class="w"> </span><span class="py">BY</span><span class="w"> </span><span class="py">tx_count</span><span class="w"> </span><span class="py">DESC</span><span class="err">;</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="err">--</span><span class="w"> </span><span class="py">Large</span><span class="w"> </span><span class="py">transaction</span><span class="w"> </span><span class="py">anomaly</span><span class="w"> </span><span class="p">(</span><span class="err">&gt;</span><span class="py">3</span><span class="w"> </span><span class="py">standard</span><span class="w"> </span><span class="py">deviations</span><span class="p">)</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="py">MATCH</span><span class="w"> </span><span class="p">(</span><span class="py">a</span><span class="p">:</span><span class="nc">Account</span><span class="p">)</span><span class="err">-</span><span class="p">[:</span><span class="nc">SENT</span><span class="p">]</span><span class="err">-&gt;</span><span class="p">(</span><span class="py">tx</span><span class="p">:</span><span class="nc">Transaction</span><span class="p">)</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="py">WITH</span><span class="w"> </span><span class="py">AVG</span><span class="p">(</span><span class="py">tx</span><span class="err">.</span><span class="py">amount</span><span class="p">)</span><span class="w"> </span><span class="py">AS</span><span class="w"> </span><span class="py">avg_amount</span><span class="p">,</span><span class="w"> </span><span class="py">STDDEV</span><span class="p">(</span><span class="py">tx</span><span class="err">.</span><span class="py">amount</span><span class="p">)</span><span class="w"> </span><span class="py">AS</span><span class="w"> </span><span class="py">stddev_amount</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="py">MATCH</span><span class="w"> </span><span class="p">(</span><span class="py">a</span><span class="p">:</span><span class="nc">Account</span><span class="p">)</span><span class="err">-</span><span class="p">[:</span><span class="nc">SENT</span><span class="p">]</span><span class="err">-&gt;</span><span class="p">(</span><span class="py">tx</span><span class="p">:</span><span class="nc">Transaction</span><span class="p">)</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="py">WHERE</span><span class="w"> </span><span class="py">tx</span><span class="err">.</span><span class="py">amount</span><span class="w"> </span><span class="err">&gt;</span><span class="w"> </span><span class="py">avg_amount</span><span class="w"> </span><span class="err">+</span><span class="w"> </span><span class="p">(</span><span class="py">3</span><span class="w"> </span><span class="err">*</span><span class="w"> </span><span class="py">stddev_amount</span><span class="p">)</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="py">RETURN</span><span class="w"> </span><span class="py">a</span><span class="err">.</span><span class="py">holder_name</span><span class="p">,</span><span class="w"> </span><span class="py">tx</span><span class="err">.</span><span class="py">amount</span><span class="p">,</span><span class="w"> </span><span class="py">avg_amount</span><span class="p">,</span><span class="w"> </span><span class="py">stddev_amount</span><span class="err">;</span><span class="w"> </span></span></span></code></pre></div> <h4 id="3-shared-deviceip-detection" class="position-relative d-flex align-items-center group"> <span>3. Shared Device/IP Detection</span> <button type="button" class="h-share btn btn-link p-0 text-decoration-none link-secondary opacity-50 hover-opacity-100 transition-all ms-1" data-share-target="3-shared-deviceip-detection" aria-haspopup="dialog" aria-label="Share link: 3. Shared Device/IP Detection"> <i class="fa-sharp-duotone fa-solid fa-share-nodes" aria-hidden="true" style="font-size: 0.8em;"></i> <span class="visually-hidden">Share link</span> </button> </h4><p>Multiple accounts using the same device or IP address:</p> <div class="highlight"><pre tabindex="0" class="chroma"><code class="language-gql" data-lang="gql"><span class="line"><span class="cl"><span class="err">--</span><span class="w"> </span><span class="py">Find</span><span class="w"> </span><span class="py">accounts</span><span class="w"> </span><span class="py">sharing</span><span class="w"> </span><span class="py">devices</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="py">MATCH</span><span class="w"> </span><span class="p">(</span><span class="py">a1</span><span class="p">:</span><span class="nc">Account</span><span class="p">)</span><span class="err">-</span><span class="p">[:</span><span class="nc">USED_DEVICE</span><span class="p">]</span><span class="err">-&gt;</span><span class="p">(</span><span class="py">d</span><span class="p">:</span><span class="nc">Device</span><span class="p">)</span><span class="err">&lt;-</span><span class="p">[:</span><span class="nc">USED_DEVICE</span><span class="p">]</span><span class="err">-</span><span class="p">(</span><span class="py">a2</span><span class="p">:</span><span class="nc">Account</span><span class="p">)</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="py">WHERE</span><span class="w"> </span><span class="py">a1</span><span class="err">.</span><span class="py">id</span><span class="w"> </span><span class="err">&lt;</span><span class="w"> </span><span class="py">a2</span><span class="err">.</span><span class="py">id</span><span class="w"> </span><span class="err">--</span><span class="w"> </span><span class="py">Avoid</span><span class="w"> </span><span class="py">duplicates</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="py">RETURN</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="py">d</span><span class="err">.</span><span class="py">fingerprint</span><span class="p">,</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="py">d</span><span class="err">.</span><span class="py">ip_addr</span><span class="p">,</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="py">COLLECT</span><span class="p">(</span><span class="py">a1</span><span class="err">.</span><span class="py">holder_name</span><span class="p">)</span><span class="w"> </span><span class="py">AS</span><span class="w"> </span><span class="py">account1</span><span class="p">,</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="py">COLLECT</span><span class="p">(</span><span class="py">a2</span><span class="err">.</span><span class="py">holder_name</span><span class="p">)</span><span class="w"> </span><span class="py">AS</span><span class="w"> </span><span class="py">account2</span><span class="err">;</span><span class="w"> </span></span></span></code></pre></div> <h4 id="4-network-centrality-mule-accounts" class="position-relative d-flex align-items-center group"> <span>4. Network Centrality (Mule Accounts)</span> <button type="button" class="h-share btn btn-link p-0 text-decoration-none link-secondary opacity-50 hover-opacity-100 transition-all ms-1" data-share-target="4-network-centrality-mule-accounts" aria-haspopup="dialog" aria-label="Share link: 4. Network Centrality (Mule Accounts)"> <i class="fa-sharp-duotone fa-solid fa-share-nodes" aria-hidden="true" style="font-size: 0.8em;"></i> <span class="visually-hidden">Share link</span> </button> </h4><p>Accounts acting as hubs (receiving/sending to many accounts):</p> <div class="highlight"><pre tabindex="0" class="chroma"><code class="language-gql" data-lang="gql"><span class="line"><span class="cl"><span class="err">--</span><span class="w"> </span><span class="py">Compute</span><span class="w"> </span><span class="py">betweenness</span><span class="w"> </span><span class="py">centrality</span><span class="w"> </span><span class="py">to</span><span class="w"> </span><span class="py">find</span><span class="w"> </span><span class="py">mule</span><span class="w"> </span><span class="py">accounts</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="py">CALL</span><span class="w"> </span><span class="py">graph</span><span class="err">.</span><span class="py">betweenness</span><span class="p">(</span><span class="err">&#39;</span><span class="py">PaymentNetwork</span><span class="err">&#39;</span><span class="p">,</span><span class="w"> </span><span class="p">{</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="py">relationship_type</span><span class="p">:</span><span class="w"> </span><span class="err">&#39;</span><span class="nc">SENT</span><span class="err">&#39;</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="p">})</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="py">YIELD</span><span class="w"> </span><span class="py">node</span><span class="p">,</span><span class="w"> </span><span class="py">score</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="py">WITH</span><span class="w"> </span><span class="py">node</span><span class="p">,</span><span class="w"> </span><span class="py">score</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="py">WHERE</span><span class="w"> </span><span class="py">score</span><span class="w"> </span><span class="err">&gt;</span><span class="w"> </span><span class="py">10</span><span class="mf">.0</span><span class="w"> </span><span class="err">--</span><span class="w"> </span><span class="py">High</span><span class="w"> </span><span class="py">betweenness</span><span class="w"> </span><span class="p">=</span><span class="w"> </span><span class="py">hub</span><span class="w"> </span><span class="py">account</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="py">MATCH</span><span class="w"> </span><span class="p">(</span><span class="py">a</span><span class="p">:</span><span class="nc">Account</span><span class="p">)</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="py">WHERE</span><span class="w"> </span><span class="py">a</span><span class="err">.</span><span class="py">id</span><span class="w"> </span><span class="p">=</span><span class="w"> </span><span class="py">node</span><span class="err">.</span><span class="py">id</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="py">RETURN</span><span class="w"> </span><span class="py">a</span><span class="err">.</span><span class="py">holder_name</span><span class="p">,</span><span class="w"> </span><span class="py">a</span><span class="err">.</span><span class="py">risk_score</span><span class="p">,</span><span class="w"> </span><span class="py">score</span><span class="w"> </span><span class="py">AS</span><span class="w"> </span><span class="py">betweenness</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="py">ORDER</span><span class="w"> </span><span class="py">BY</span><span class="w"> </span><span class="py">score</span><span class="w"> </span><span class="py">DESC</span><span class="err">;</span><span class="w"> </span></span></span></code></pre></div> <h3 id="ml-based-anomaly-detection" class="position-relative d-flex align-items-center group"> <span>ML-Based Anomaly Detection</span> <button type="button" class="h-share btn btn-link p-0 text-decoration-none link-secondary opacity-50 hover-opacity-100 transition-all ms-1" data-share-target="ml-based-anomaly-detection" aria-haspopup="dialog" aria-label="Share link: ML-Based Anomaly Detection"> <i class="fa-sharp-duotone fa-solid fa-share-nodes" aria-hidden="true" style="font-size: 0.8em;"></i> <span class="visually-hidden">Share link</span> </button> </h3> <h4 id="generate-embeddings" class="position-relative d-flex align-items-center group"> <span>Generate Embeddings</span> <button type="button" class="h-share btn btn-link p-0 text-decoration-none link-secondary opacity-50 hover-opacity-100 transition-all ms-1" data-share-target="generate-embeddings" aria-haspopup="dialog" aria-label="Share link: Generate Embeddings"> <i class="fa-sharp-duotone fa-solid fa-share-nodes" aria-hidden="true" style="font-size: 0.8em;"></i> <span class="visually-hidden">Share link</span> </button> </h4><p>Use Node2Vec to create account embeddings capturing behavioral patterns:</p> <div class="highlight"><pre tabindex="0" class="chroma"><code class="language-gql" data-lang="gql"><span class="line"><span class="cl"><span class="err">--</span><span class="w"> </span><span class="py">Generate</span><span class="w"> </span><span class="py">account</span><span class="w"> </span><span class="py">embeddings</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="py">CALL</span><span class="w"> </span><span class="py">graph</span><span class="err">.</span><span class="py">node2vec</span><span class="p">(</span><span class="err">&#39;</span><span class="py">PaymentNetwork</span><span class="err">&#39;</span><span class="p">,</span><span class="w"> </span><span class="p">{</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="py">relationship_type</span><span class="p">:</span><span class="w"> </span><span class="err">&#39;</span><span class="nc">SENT</span><span class="err">&#39;</span><span class="p">,</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="py">dimensions</span><span class="p">:</span><span class="w"> </span><span class="nc">128</span><span class="p">,</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="py">walk_length</span><span class="p">:</span><span class="w"> </span><span class="nc">80</span><span class="p">,</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="py">num_walks</span><span class="p">:</span><span class="w"> </span><span class="nc">10</span><span class="p">,</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="py">p</span><span class="p">:</span><span class="w"> </span><span class="nc">1</span><span class="mf">.0</span><span class="p">,</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="py">q</span><span class="p">:</span><span class="w"> </span><span class="nc">1</span><span class="mf">.0</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="p">})</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="py">YIELD</span><span class="w"> </span><span class="py">node</span><span class="p">,</span><span class="w"> </span><span class="py">embedding</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="py">WITH</span><span class="w"> </span><span class="py">node</span><span class="p">,</span><span class="w"> </span><span class="py">embedding</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="py">MATCH</span><span class="w"> </span><span class="p">(</span><span class="py">a</span><span class="p">:</span><span class="nc">Account</span><span class="p">)</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="py">WHERE</span><span class="w"> </span><span class="py">a</span><span class="err">.</span><span class="py">id</span><span class="w"> </span><span class="p">=</span><span class="w"> </span><span class="py">node</span><span class="err">.</span><span class="py">id</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="py">SET</span><span class="w"> </span><span class="py">a</span><span class="err">.</span><span class="py">embedding</span><span class="w"> </span><span class="p">=</span><span class="w"> </span><span class="py">embedding</span><span class="err">;</span><span class="w"> </span></span></span></code></pre></div> <h4 id="detect-anomalies-with-vector-similarity" class="position-relative d-flex align-items-center group"> <span>Detect Anomalies with Vector Similarity</span> <button type="button" class="h-share btn btn-link p-0 text-decoration-none link-secondary opacity-50 hover-opacity-100 transition-all ms-1" data-share-target="detect-anomalies-with-vector-similarity" aria-haspopup="dialog" aria-label="Share link: Detect Anomalies with Vector Similarity"> <i class="fa-sharp-duotone fa-solid fa-share-nodes" aria-hidden="true" style="font-size: 0.8em;"></i> <span class="visually-hidden">Share link</span> </button> </h4><p>Find accounts with unusual behavior (outliers):</p> <div class="highlight"><pre tabindex="0" class="chroma"><code class="language-gql" data-lang="gql"><span class="line"><span class="cl"><span class="err">--</span><span class="w"> </span><span class="py">For</span><span class="w"> </span><span class="py">each</span><span class="w"> </span><span class="py">account</span><span class="p">,</span><span class="w"> </span><span class="py">find</span><span class="w"> </span><span class="py">nearest</span><span class="w"> </span><span class="py">neighbors</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="py">MATCH</span><span class="w"> </span><span class="p">(</span><span class="py">a</span><span class="p">:</span><span class="nc">Account</span><span class="p">)</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="py">MATCH</span><span class="w"> </span><span class="p">(</span><span class="py">neighbor</span><span class="p">:</span><span class="nc">Account</span><span class="p">)</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="py">WHERE</span><span class="w"> </span><span class="py">neighbor</span><span class="err">.</span><span class="py">id</span><span class="w"> </span><span class="err">&lt;&gt;</span><span class="w"> </span><span class="py">a</span><span class="err">.</span><span class="py">id</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="py">AND</span><span class="w"> </span><span class="py">vector_distance_cosine</span><span class="p">(</span><span class="py">a</span><span class="err">.</span><span class="py">embedding</span><span class="p">,</span><span class="w"> </span><span class="py">neighbor</span><span class="err">.</span><span class="py">embedding</span><span class="p">)</span><span class="w"> </span><span class="err">&lt;</span><span class="w"> </span><span class="py">0</span><span class="mf">.8</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="py">WITH</span><span class="w"> </span><span class="py">a</span><span class="p">,</span><span class="w"> </span><span class="py">COUNT</span><span class="p">(</span><span class="py">neighbor</span><span class="p">)</span><span class="w"> </span><span class="py">AS</span><span class="w"> </span><span class="py">neighbor_count</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="py">WHERE</span><span class="w"> </span><span class="py">neighbor_count</span><span class="w"> </span><span class="err">&lt;</span><span class="w"> </span><span class="py">3</span><span class="w"> </span><span class="err">--</span><span class="w"> </span><span class="py">Fewer</span><span class="w"> </span><span class="py">than</span><span class="w"> </span><span class="py">3</span><span class="w"> </span><span class="py">similar</span><span class="w"> </span><span class="py">accounts</span><span class="w"> </span><span class="p">=</span><span class="w"> </span><span class="py">anomaly</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="py">RETURN</span><span class="w"> </span><span class="py">a</span><span class="err">.</span><span class="py">holder_name</span><span class="p">,</span><span class="w"> </span><span class="py">a</span><span class="err">.</span><span class="py">risk_score</span><span class="p">,</span><span class="w"> </span><span class="py">neighbor_count</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="py">ORDER</span><span class="w"> </span><span class="py">BY</span><span class="w"> </span><span class="py">neighbor_count</span><span class="w"> </span><span class="py">ASC</span><span class="err">;</span><span class="w"> </span></span></span></code></pre></div> <h3 id="real-time-fraud-detection" class="position-relative d-flex align-items-center group"> <span>Real-Time Fraud Detection</span> <button type="button" class="h-share btn btn-link p-0 text-decoration-none link-secondary opacity-50 hover-opacity-100 transition-all ms-1" data-share-target="real-time-fraud-detection" aria-haspopup="dialog" aria-label="Share link: Real-Time Fraud Detection"> <i class="fa-sharp-duotone fa-solid fa-share-nodes" aria-hidden="true" style="font-size: 0.8em;"></i> <span class="visually-hidden">Share link</span> </button> </h3><p>From <code>REAL_TIME_ANALYTICS.md</code>:</p> <h4 id="cdc-configuration" class="position-relative d-flex align-items-center group"> <span>CDC Configuration</span> <button type="button" class="h-share btn btn-link p-0 text-decoration-none link-secondary opacity-50 hover-opacity-100 transition-all ms-1" data-share-target="cdc-configuration" aria-haspopup="dialog" aria-label="Share link: CDC Configuration"> <i class="fa-sharp-duotone fa-solid fa-share-nodes" aria-hidden="true" style="font-size: 0.8em;"></i> <span class="visually-hidden">Share link</span> </button> </h4><p>Capture transaction events and trigger real-time analysis:</p> <div class="highlight"><pre tabindex="0" class="chroma"><code class="language-yaml" data-lang="yaml"><span class="line"><span class="cl"><span class="c"># cdc-config.yaml</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="nt">cdc</span><span class="p">:</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="nt">enabled</span><span class="p">:</span><span class="w"> </span><span class="kc">true</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="nt">webhooks</span><span class="p">:</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"> </span>- <span class="nt">url</span><span class="p">:</span><span class="w"> </span><span class="s2">&#34;https://fraud-detection.example.com/webhook&#34;</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="nt">events</span><span class="p">:</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"> </span>- <span class="l">node.created</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"> </span>- <span class="l">edge.created</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="nt">filter</span><span class="p">:</span><span class="w"> </span><span class="s2">&#34;label = &#39;Transaction&#39; OR type = &#39;SENT&#39;&#34;</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="nt">retry</span><span class="p">:</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="nt">max_attempts</span><span class="p">:</span><span class="w"> </span><span class="m">3</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="nt">backoff</span><span class="p">:</span><span class="w"> </span><span class="l">exponential</span><span class="w"> </span></span></span></code></pre></div> <h4 id="webhook-processing" class="position-relative d-flex align-items-center group"> <span>Webhook Processing</span> <button type="button" class="h-share btn btn-link p-0 text-decoration-none link-secondary opacity-50 hover-opacity-100 transition-all ms-1" data-share-target="webhook-processing" aria-haspopup="dialog" aria-label="Share link: Webhook Processing"> <i class="fa-sharp-duotone fa-solid fa-share-nodes" aria-hidden="true" style="font-size: 0.8em;"></i> <span class="visually-hidden">Share link</span> </button> </h4><p><strong>Webhook receives transaction event</strong>:</p> <div class="highlight"><pre tabindex="0" class="chroma"><code class="language-json" data-lang="json"><span class="line"><span class="cl"><span class="p">{</span> </span></span><span class="line"><span class="cl"> <span class="nt">&#34;event&#34;</span><span class="p">:</span> <span class="s2">&#34;node.created&#34;</span><span class="p">,</span> </span></span><span class="line"><span class="cl"> <span class="nt">&#34;graph&#34;</span><span class="p">:</span> <span class="s2">&#34;PaymentNetwork&#34;</span><span class="p">,</span> </span></span><span class="line"><span class="cl"> <span class="nt">&#34;node&#34;</span><span class="p">:</span> <span class="p">{</span> </span></span><span class="line"><span class="cl"> <span class="nt">&#34;id&#34;</span><span class="p">:</span> <span class="mi">123456</span><span class="p">,</span> </span></span><span class="line"><span class="cl"> <span class="nt">&#34;labels&#34;</span><span class="p">:</span> <span class="p">[</span><span class="s2">&#34;Transaction&#34;</span><span class="p">],</span> </span></span><span class="line"><span class="cl"> <span class="nt">&#34;properties&#34;</span><span class="p">:</span> <span class="p">{</span> </span></span><span class="line"><span class="cl"> <span class="nt">&#34;amount&#34;</span><span class="p">:</span> <span class="s2">&#34;5000.00&#34;</span><span class="p">,</span> </span></span><span class="line"><span class="cl"> <span class="nt">&#34;timestamp&#34;</span><span class="p">:</span> <span class="s2">&#34;2024-01-15T14:30:00Z&#34;</span><span class="p">,</span> </span></span><span class="line"><span class="cl"> <span class="nt">&#34;merchant_category&#34;</span><span class="p">:</span> <span class="s2">&#34;wire_transfer&#34;</span> </span></span><span class="line"><span class="cl"> <span class="p">}</span> </span></span><span class="line"><span class="cl"> <span class="p">},</span> </span></span><span class="line"><span class="cl"> <span class="nt">&#34;trace_id&#34;</span><span class="p">:</span> <span class="s2">&#34;7c9e8d6f-5b4a-3c2d-1e0f-9a8b7c6d5e4f&#34;</span> </span></span><span class="line"><span class="cl"><span class="p">}</span> </span></span></code></pre></div><p><strong>Fraud detection service</strong>:</p> <div class="highlight"><pre tabindex="0" class="chroma"><code class="language-python" data-lang="python"><span class="line"><span class="cl"><span class="c1"># Pseudo-code</span> </span></span><span class="line"><span class="cl"><span class="k">async</span> <span class="k">def</span> <span class="nf">process_transaction</span><span class="p">(</span><span class="n">event</span><span class="p">):</span> </span></span><span class="line"><span class="cl"> <span class="n">tx_id</span> <span class="o">=</span> <span class="n">event</span><span class="p">[</span><span class="s1">&#39;node&#39;</span><span class="p">][</span><span class="s1">&#39;id&#39;</span><span class="p">]</span> </span></span><span class="line"><span class="cl"> <span class="n">amount</span> <span class="o">=</span> <span class="n">Decimal</span><span class="p">(</span><span class="n">event</span><span class="p">[</span><span class="s1">&#39;node&#39;</span><span class="p">][</span><span class="s1">&#39;properties&#39;</span><span class="p">][</span><span class="s1">&#39;amount&#39;</span><span class="p">])</span> </span></span><span class="line"><span class="cl"> </span></span><span class="line"><span class="cl"> <span class="c1"># Query graph for context</span> </span></span><span class="line"><span class="cl"> <span class="n">sender</span> <span class="o">=</span> <span class="k">await</span> <span class="n">get_sender_account</span><span class="p">(</span><span class="n">tx_id</span><span class="p">)</span> </span></span><span class="line"><span class="cl"> <span class="n">receiver</span> <span class="o">=</span> <span class="k">await</span> <span class="n">get_receiver_account</span><span class="p">(</span><span class="n">tx_id</span><span class="p">)</span> </span></span><span class="line"><span class="cl"> </span></span><span class="line"><span class="cl"> <span class="c1"># Compute risk score</span> </span></span><span class="line"><span class="cl"> <span class="n">risk_score</span> <span class="o">=</span> <span class="mf">0.0</span> </span></span><span class="line"><span class="cl"> </span></span><span class="line"><span class="cl"> <span class="c1"># Check velocity</span> </span></span><span class="line"><span class="cl"> <span class="n">recent_tx_count</span> <span class="o">=</span> <span class="k">await</span> <span class="n">count_recent_transactions</span><span class="p">(</span><span class="n">sender</span><span class="o">.</span><span class="n">id</span><span class="p">,</span> <span class="n">hours</span><span class="o">=</span><span class="mi">1</span><span class="p">)</span> </span></span><span class="line"><span class="cl"> <span class="k">if</span> <span class="n">recent_tx_count</span> <span class="o">&gt;</span> <span class="mi">10</span><span class="p">:</span> </span></span><span class="line"><span class="cl"> <span class="n">risk_score</span> <span class="o">+=</span> <span class="mf">0.3</span> </span></span><span class="line"><span class="cl"> </span></span><span class="line"><span class="cl"> <span class="c1"># Check amount anomaly</span> </span></span><span class="line"><span class="cl"> <span class="n">avg_amount</span> <span class="o">=</span> <span class="k">await</span> <span class="n">get_avg_transaction_amount</span><span class="p">(</span><span class="n">sender</span><span class="o">.</span><span class="n">id</span><span class="p">)</span> </span></span><span class="line"><span class="cl"> <span class="k">if</span> <span class="n">amount</span> <span class="o">&gt;</span> <span class="n">avg_amount</span> <span class="o">*</span> <span class="mi">3</span><span class="p">:</span> </span></span><span class="line"><span class="cl"> <span class="n">risk_score</span> <span class="o">+=</span> <span class="mf">0.4</span> </span></span><span class="line"><span class="cl"> </span></span><span class="line"><span class="cl"> <span class="c1"># Check for transaction ring</span> </span></span><span class="line"><span class="cl"> <span class="n">in_ring</span> <span class="o">=</span> <span class="k">await</span> <span class="n">is_part_of_ring</span><span class="p">(</span><span class="n">sender</span><span class="o">.</span><span class="n">id</span><span class="p">,</span> <span class="n">receiver</span><span class="o">.</span><span class="n">id</span><span class="p">)</span> </span></span><span class="line"><span class="cl"> <span class="k">if</span> <span class="n">in_ring</span><span class="p">:</span> </span></span><span class="line"><span class="cl"> <span class="n">risk_score</span> <span class="o">+=</span> <span class="mf">0.5</span> </span></span><span class="line"><span class="cl"> </span></span><span class="line"><span class="cl"> <span class="c1"># Flag if high risk</span> </span></span><span class="line"><span class="cl"> <span class="k">if</span> <span class="n">risk_score</span> <span class="o">&gt;</span> <span class="mf">0.7</span><span class="p">:</span> </span></span><span class="line"><span class="cl"> <span class="k">await</span> <span class="n">flag_transaction</span><span class="p">(</span><span class="n">tx_id</span><span class="p">,</span> <span class="n">risk_score</span><span class="p">)</span> </span></span><span class="line"><span class="cl"> <span class="k">await</span> <span class="n">send_alert</span><span class="p">(</span><span class="n">sender</span><span class="p">,</span> <span class="n">receiver</span><span class="p">,</span> <span class="n">risk_score</span><span class="p">)</span> </span></span><span class="line"><span class="cl"> </span></span><span class="line"><span class="cl"> <span class="k">return</span> <span class="n">risk_score</span> </span></span></code></pre></div> <h3 id="row-level-security-for-multi-tenant-isolation" class="position-relative d-flex align-items-center group"> <span>Row-Level Security for Multi-Tenant Isolation</span> <button type="button" class="h-share btn btn-link p-0 text-decoration-none link-secondary opacity-50 hover-opacity-100 transition-all ms-1" data-share-target="row-level-security-for-multi-tenant-isolation" aria-haspopup="dialog" aria-label="Share link: Row-Level Security for Multi-Tenant Isolation"> <i class="fa-sharp-duotone fa-solid fa-share-nodes" aria-hidden="true" style="font-size: 0.8em;"></i> <span class="visually-hidden">Share link</span> </button> </h3><p>From <code>ADVANCED_SECURITY_FEATURES_OCTOBER_2025.md</code>:</p> <p>Financial institutions need tenant isolation:</p> <div class="highlight"><pre tabindex="0" class="chroma"><code class="language-gql" data-lang="gql"><span class="line"><span class="cl"><span class="err">--</span><span class="w"> </span><span class="py">Create</span><span class="w"> </span><span class="py">RLS</span><span class="w"> </span><span class="py">policy</span><span class="p">:</span><span class="w"> </span><span class="nc">users</span><span class="w"> </span><span class="kd">on</span><span class="py">ly</span><span class="w"> </span><span class="py">see</span><span class="w"> </span><span class="py">their</span><span class="w"> </span><span class="py">organization</span><span class="err">&#39;</span><span class="py">s</span><span class="w"> </span><span class="py">data</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="py">CREATE</span><span class="w"> </span><span class="py">POLICY</span><span class="w"> </span><span class="py">org_isolation</span><span class="w"> </span><span class="py">ON</span><span class="w"> </span><span class="py">Account</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="py">FOR</span><span class="w"> </span><span class="py">SELECT</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="py">USING</span><span class="w"> </span><span class="p">(</span><span class="py">organization_id</span><span class="w"> </span><span class="p">=</span><span class="w"> </span><span class="py">current_user_org_id</span><span class="p">())</span><span class="err">;</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="py">CREATE</span><span class="w"> </span><span class="py">POLICY</span><span class="w"> </span><span class="py">org_isolation_tx</span><span class="w"> </span><span class="py">ON</span><span class="w"> </span><span class="py">Transaction</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="py">FOR</span><span class="w"> </span><span class="py">SELECT</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="py">USING</span><span class="w"> </span><span class="p">(</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="py">EXISTS</span><span class="w"> </span><span class="p">(</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="py">MATCH</span><span class="w"> </span><span class="p">(</span><span class="py">a</span><span class="p">:</span><span class="nc">Account</span><span class="p">)</span><span class="err">-</span><span class="p">[:</span><span class="nc">SENT</span><span class="p">|</span><span class="py">RECEIVED_BY</span><span class="p">]</span><span class="err">-&gt;</span><span class="p">(</span><span class="py">tx</span><span class="p">:</span><span class="nc">Transaction</span><span class="p">)</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="py">WHERE</span><span class="w"> </span><span class="py">tx</span><span class="err">.</span><span class="py">id</span><span class="w"> </span><span class="p">=</span><span class="w"> </span><span class="py">this</span><span class="err">.</span><span class="py">id</span><span class="w"> </span><span class="py">AND</span><span class="w"> </span><span class="py">a</span><span class="err">.</span><span class="py">organization_id</span><span class="w"> </span><span class="p">=</span><span class="w"> </span><span class="py">current_user_org_id</span><span class="p">()</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="p">)</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="p">)</span><span class="err">;</span><span class="w"> </span></span></span></code></pre></div><p><strong>Benefit</strong>: Analysts at Bank A cannot see Bank B&rsquo;s data, even with direct database access.</p> <h3 id="audit-logging-for-compliance" class="position-relative d-flex align-items-center group"> <span>Audit Logging for Compliance</span> <button type="button" class="h-share btn btn-link p-0 text-decoration-none link-secondary opacity-50 hover-opacity-100 transition-all ms-1" data-share-target="audit-logging-for-compliance" aria-haspopup="dialog" aria-label="Share link: Audit Logging for Compliance"> <i class="fa-sharp-duotone fa-solid fa-share-nodes" aria-hidden="true" style="font-size: 0.8em;"></i> <span class="visually-hidden">Share link</span> </button> </h3><p>From <code>AUDIT_LOGGING.md</code>:</p> <p>Track all fraud investigations for regulatory compliance:</p> <div class="highlight"><pre tabindex="0" class="chroma"><code class="language-yaml" data-lang="yaml"><span class="line"><span class="cl"><span class="nt">security</span><span class="p">:</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="nt">audit</span><span class="p">:</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="nt">enabled</span><span class="p">:</span><span class="w"> </span><span class="kc">true</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="nt">log_path</span><span class="p">:</span><span class="w"> </span><span class="s2">&#34;/var/log/geode/fraud-audit.jsonl&#34;</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="nt">syslog</span><span class="p">:</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="nt">enabled</span><span class="p">:</span><span class="w"> </span><span class="kc">true</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="nt">address</span><span class="p">:</span><span class="w"> </span><span class="s2">&#34;siem.example.com:514&#34;</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="nt">format</span><span class="p">:</span><span class="w"> </span><span class="s2">&#34;CEF&#34;</span><span class="w"> </span></span></span></code></pre></div><p><strong>Audit log entry</strong>:</p> <div class="highlight"><pre tabindex="0" class="chroma"><code class="language-json" data-lang="json"><span class="line"><span class="cl"><span class="p">{</span> </span></span><span class="line"><span class="cl"> <span class="nt">&#34;timestamp&#34;</span><span class="p">:</span> <span class="s2">&#34;2024-01-15T14:30:00.123Z&#34;</span><span class="p">,</span> </span></span><span class="line"><span class="cl"> <span class="nt">&#34;event_type&#34;</span><span class="p">:</span> <span class="s2">&#34;query_executed&#34;</span><span class="p">,</span> </span></span><span class="line"><span class="cl"> <span class="nt">&#34;user&#34;</span><span class="p">:</span> <span class="s2">&#34;fraud_analyst_alice&#34;</span><span class="p">,</span> </span></span><span class="line"><span class="cl"> <span class="nt">&#34;graph&#34;</span><span class="p">:</span> <span class="s2">&#34;PaymentNetwork&#34;</span><span class="p">,</span> </span></span><span class="line"><span class="cl"> <span class="nt">&#34;execution_time_ms&#34;</span><span class="p">:</span> <span class="mf">45.2</span><span class="p">,</span> </span></span><span class="line"><span class="cl"> <span class="nt">&#34;rows_returned&#34;</span><span class="p">:</span> <span class="mi">3</span><span class="p">,</span> </span></span><span class="line"><span class="cl"> <span class="nt">&#34;trace_id&#34;</span><span class="p">:</span> <span class="s2">&#34;...&#34;</span><span class="p">,</span> </span></span><span class="line"><span class="cl"> <span class="nt">&#34;prev_log_hash&#34;</span><span class="p">:</span> <span class="s2">&#34;...&#34;</span><span class="p">,</span> </span></span><span class="line"><span class="cl"> <span class="nt">&#34;signature&#34;</span><span class="p">:</span> <span class="s2">&#34;...&#34;</span> </span></span><span class="line"><span class="cl"><span class="p">}</span> </span></span></code></pre></div> <h3 id="performance-optimization" class="position-relative d-flex align-items-center group"> <span>Performance Optimization</span> <button type="button" class="h-share btn btn-link p-0 text-decoration-none link-secondary opacity-50 hover-opacity-100 transition-all ms-1" data-share-target="performance-optimization" aria-haspopup="dialog" aria-label="Share link: Performance Optimization"> <i class="fa-sharp-duotone fa-solid fa-share-nodes" aria-hidden="true" style="font-size: 0.8em;"></i> <span class="visually-hidden">Share link</span> </button> </h3> <h4 id="index-strategy" class="position-relative d-flex align-items-center group"> <span>Index Strategy</span> <button type="button" class="h-share btn btn-link p-0 text-decoration-none link-secondary opacity-50 hover-opacity-100 transition-all ms-1" data-share-target="index-strategy" aria-haspopup="dialog" aria-label="Share link: Index Strategy"> <i class="fa-sharp-duotone fa-solid fa-share-nodes" aria-hidden="true" style="font-size: 0.8em;"></i> <span class="visually-hidden">Share link</span> </button> </h4><div class="highlight"><pre tabindex="0" class="chroma"><code class="language-gql" data-lang="gql"><span class="line"><span class="cl"><span class="err">--</span><span class="w"> </span><span class="py">Index</span><span class="w"> </span><span class="py">frequently</span><span class="w"> </span><span class="py">queried</span><span class="w"> </span><span class="py">properties</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="py">CREATE</span><span class="w"> </span><span class="py">INDEX</span><span class="w"> </span><span class="py">account_risk_score_idx</span><span class="w"> </span><span class="py">ON</span><span class="w"> </span><span class="py">Account</span><span class="p">(</span><span class="py">risk_score</span><span class="p">)</span><span class="w"> </span><span class="py">USING</span><span class="w"> </span><span class="py">btree</span><span class="err">;</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="py">CREATE</span><span class="w"> </span><span class="py">INDEX</span><span class="w"> </span><span class="py">tx_timestamp_idx</span><span class="w"> </span><span class="py">ON</span><span class="w"> </span><span class="py">Transaction</span><span class="p">(</span><span class="py">timestamp</span><span class="p">)</span><span class="w"> </span><span class="py">USING</span><span class="w"> </span><span class="py">btree</span><span class="err">;</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="py">CREATE</span><span class="w"> </span><span class="py">INDEX</span><span class="w"> </span><span class="py">tx_amount_idx</span><span class="w"> </span><span class="py">ON</span><span class="w"> </span><span class="py">Transaction</span><span class="p">(</span><span class="py">amount</span><span class="p">)</span><span class="w"> </span><span class="py">USING</span><span class="w"> </span><span class="py">btree</span><span class="err">;</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="err">--</span><span class="w"> </span><span class="py">Vector</span><span class="w"> </span><span class="py">index</span><span class="w"> </span><span class="py">for</span><span class="w"> </span><span class="py">similarity</span><span class="w"> </span><span class="py">queries</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="py">CREATE</span><span class="w"> </span><span class="py">INDEX</span><span class="w"> </span><span class="py">account_embedding_idx</span><span class="w"> </span><span class="py">ON</span><span class="w"> </span><span class="py">Account</span><span class="p">(</span><span class="py">embedding</span><span class="p">)</span><span class="w"> </span><span class="py">USING</span><span class="w"> </span><span class="py">vector</span><span class="err">;</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="err">--</span><span class="w"> </span><span class="py">Spatial</span><span class="w"> </span><span class="py">index</span><span class="w"> </span><span class="py">for</span><span class="w"> </span><span class="py">location</span><span class="err">-</span><span class="py">based</span><span class="w"> </span><span class="py">fraud</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="py">CREATE</span><span class="w"> </span><span class="py">INDEX</span><span class="w"> </span><span class="py">tx_location_idx</span><span class="w"> </span><span class="py">ON</span><span class="w"> </span><span class="py">Transaction</span><span class="p">(</span><span class="py">location</span><span class="p">)</span><span class="w"> </span><span class="py">USING</span><span class="w"> </span><span class="py">spatial</span><span class="err">;</span><span class="w"> </span></span></span></code></pre></div> <h4 id="materialized-risk-scores" class="position-relative d-flex align-items-center group"> <span>Materialized Risk Scores</span> <button type="button" class="h-share btn btn-link p-0 text-decoration-none link-secondary opacity-50 hover-opacity-100 transition-all ms-1" data-share-target="materialized-risk-scores" aria-haspopup="dialog" aria-label="Share link: Materialized Risk Scores"> <i class="fa-sharp-duotone fa-solid fa-share-nodes" aria-hidden="true" style="font-size: 0.8em;"></i> <span class="visually-hidden">Share link</span> </button> </h4><p>Pre-compute risk scores for fast lookups:</p> <div class="highlight"><pre tabindex="0" class="chroma"><code class="language-gql" data-lang="gql"><span class="line"><span class="cl"><span class="err">--</span><span class="w"> </span><span class="py">Batch</span><span class="w"> </span><span class="py">job</span><span class="w"> </span><span class="p">(</span><span class="py">run</span><span class="w"> </span><span class="py">hourly</span><span class="p">)</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="py">MATCH</span><span class="w"> </span><span class="p">(</span><span class="py">a</span><span class="p">:</span><span class="nc">Account</span><span class="p">)</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="py">WITH</span><span class="w"> </span><span class="py">a</span><span class="p">,</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="err">--</span><span class="w"> </span><span class="py">Compute</span><span class="w"> </span><span class="py">risk</span><span class="w"> </span><span class="py">factors</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="py">COUNT</span><span class="w"> </span><span class="p">{</span><span class="py">MATCH</span><span class="w"> </span><span class="p">(</span><span class="py">a</span><span class="p">)</span><span class="err">-</span><span class="p">[:</span><span class="nc">SENT</span><span class="p">]</span><span class="err">-&gt;</span><span class="p">(:</span><span class="nc">Transaction</span><span class="p">)</span><span class="w"> </span><span class="py">WHERE</span><span class="w"> </span><span class="py">timestamp</span><span class="w"> </span><span class="err">&gt;</span><span class="w"> </span><span class="py">timestamp</span><span class="p">()</span><span class="w"> </span><span class="err">-</span><span class="w"> </span><span class="py">interval</span><span class="p">(</span><span class="err">&#39;</span><span class="py">P1D</span><span class="err">&#39;</span><span class="p">)}</span><span class="w"> </span><span class="py">AS</span><span class="w"> </span><span class="py">daily_tx_count</span><span class="p">,</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="py">AVG</span><span class="w"> </span><span class="p">{</span><span class="py">MATCH</span><span class="w"> </span><span class="p">(</span><span class="py">a</span><span class="p">)</span><span class="err">-</span><span class="p">[:</span><span class="nc">SENT</span><span class="p">]</span><span class="err">-&gt;</span><span class="p">(</span><span class="py">tx</span><span class="p">:</span><span class="nc">Transaction</span><span class="p">)</span><span class="w"> </span><span class="py">RETURN</span><span class="w"> </span><span class="py">tx</span><span class="err">.</span><span class="py">amount</span><span class="p">}</span><span class="w"> </span><span class="py">AS</span><span class="w"> </span><span class="py">avg_tx_amount</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="py">SET</span><span class="w"> </span><span class="py">a</span><span class="err">.</span><span class="py">risk_score</span><span class="w"> </span><span class="p">=</span><span class="w"> </span><span class="py">CASE</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="py">WHEN</span><span class="w"> </span><span class="py">daily_tx_count</span><span class="w"> </span><span class="err">&gt;</span><span class="w"> </span><span class="py">50</span><span class="w"> </span><span class="py">THEN</span><span class="w"> </span><span class="py">0</span><span class="mf">.8</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="py">WHEN</span><span class="w"> </span><span class="py">avg_tx_amount</span><span class="w"> </span><span class="err">&gt;</span><span class="w"> </span><span class="py">10000</span><span class="w"> </span><span class="py">THEN</span><span class="w"> </span><span class="py">0</span><span class="mf">.6</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="py">ELSE</span><span class="w"> </span><span class="py">0</span><span class="mf">.2</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="py">END</span><span class="err">;</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="err">--</span><span class="w"> </span><span class="py">Queries</span><span class="w"> </span><span class="py">use</span><span class="w"> </span><span class="py">cached</span><span class="w"> </span><span class="py">risk_score</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="py">MATCH</span><span class="w"> </span><span class="p">(</span><span class="py">a</span><span class="p">:</span><span class="nc">Account</span><span class="p">)</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="py">WHERE</span><span class="w"> </span><span class="py">a</span><span class="err">.</span><span class="py">risk_score</span><span class="w"> </span><span class="err">&gt;</span><span class="w"> </span><span class="py">0</span><span class="mf">.7</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="py">RETURN</span><span class="w"> </span><span class="py">a</span><span class="err">.</span><span class="py">holder_name</span><span class="p">,</span><span class="w"> </span><span class="py">a</span><span class="err">.</span><span class="py">risk_score</span><span class="w"> </span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="py">ORDER</span><span class="w"> </span><span class="py">BY</span><span class="w"> </span><span class="py">a</span><span class="err">.</span><span class="py">risk_score</span><span class="w"> </span><span class="py">DESC</span><span class="err">;</span><span class="w"> </span></span></span></code></pre></div> <h3 id="complete-workflow" class="position-relative d-flex align-items-center group"> <span>Complete Workflow</span> <button type="button" class="h-share btn btn-link p-0 text-decoration-none link-secondary opacity-50 hover-opacity-100 transition-all ms-1" data-share-target="complete-workflow" aria-haspopup="dialog" aria-label="Share link: Complete Workflow"> <i class="fa-sharp-duotone fa-solid fa-share-nodes" aria-hidden="true" style="font-size: 0.8em;"></i> <span class="visually-hidden">Share link</span> </button> </h3><ol> <li><strong>Ingest transactions</strong> via application or bulk load</li> <li><strong>CDC triggers</strong> webhook to fraud detection service</li> <li><strong>Service queries graph</strong> for context (velocity, rings, centrality)</li> <li><strong>ML model scores</strong> transaction using embeddings</li> <li><strong>High-risk transactions</strong> flagged automatically</li> <li><strong>Analysts investigate</strong> using GQL queries</li> <li><strong>Audit logs</strong> capture all investigations for compliance</li> </ol> <h3 id="next-steps" class="position-relative d-flex align-items-center group"> <span>Next Steps</span> <button type="button" class="h-share btn btn-link p-0 text-decoration-none link-secondary opacity-50 hover-opacity-100 transition-all ms-1" data-share-target="next-steps" aria-haspopup="dialog" aria-label="Share link: Next Steps"> <i class="fa-sharp-duotone fa-solid fa-share-nodes" aria-hidden="true" style="font-size: 0.8em;"></i> <span class="visually-hidden">Share link</span> </button> </h3><ul> <li><a href="/docs/analytics/real-time-analytics/" >Real-Time Analytics</a> - CDC and streaming integration</li> <li><a href="/docs/analytics/graph-algorithms" >Graph Algorithms</a> - Centrality and embeddings</li> <li><a href="/docs/security/overview" >Security Guide</a> - RLS and audit logging</li> <li><a href="/docs/query/indexing-and-optimization" >Indexing and Optimization</a> - Performance tuning</li> </ul>