Merchant refund guards: stopping anomalous refunds before money leaves
Lead
Refund automation with standing keys is a fraud vector. Pre-execution authorization holds anomalous refunds until a named approver authorizes this exact amount.
Opening
Support agents and automations issue refunds with API keys. Value spikes go unnoticed until reconciliation — or never.
A merchant refund guard evaluates each proposed refund: actor, amount, merchant context, policy threshold, and behavioral risk. Anomalous spikes route to APPROVAL_REQUIRED.
What the approver sees
Not a class of refunds — this €4,800 refund from support-agent-04 under refund-policy-v7. Single-use approval. Evidence preserved whether ALLOW or DENY.
Related
