Skip to content

[Spike] Define the canonical model for sequence-based fraud scenarios #72

Description

@knytcomics-ui

Category

Spike

Question

Should fraud evaluation use ordered XDR bundles, event streams, state snapshots, graph relationships, or independent fixtures?

Context

Current fixtures are point-based while documented patterns depend on multiple transactions and relationships.

Why This Matters

The representation determines whether future consumers can evaluate timing and state transitions.

Areas to Investigate

Ordered bundles, event snapshots, participant graphs, state machines, warning checkpoints, and deterministic replay.

Evaluation Criteria

Expressiveness, reproducibility, validator complexity, storage, consumer usability, and synthetic-data compatibility.

Expected Deliverables

Proposed schema, one proof of concept, comparison, replay semantics, and migration path.

Acceptance Criteria

  • Three approaches are compared.
  • One sweep or phishing sequence is modeled.
  • Required metadata and validation rules are documented.
  • Follow-up implementation work is decomposed.

Follow-Up Opportunities

May lead to scenario bundles and a replay runner.

Cross-Repository Impact

All four repositories, especially testkit and research.

Complexity

Spike

Impact

Critical — establishes behavior-level evaluation architecture.

Suggested Labels

spike, area: fixtures, area: evaluation, area: cross-repo

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions