SEONRouteurStable

Assess fraud (SEON)

Assesses fraud risk for an order, checkout, payment, onboarding, or other business operation, then automatically routes the process to approval, manual review, or decline.

Vue d’ensemble

Assess fraud (SEON) assesses risk associated with one precise business action: account creation, sign-in, order, payment attempt, refund, or disbursement. The same company may therefore receive different decisions depending on the assessed action, timing, and available signals.

The subject is the anchor of the assessment. Use an order for an order, a checkout_session during checkout, or an onboarding_case during onboarding. Other parameters add company, person, and operation context.

  • Data already present on Ormuz objects is used automatically when no explicit value overrides it.
  • Email, phone, IP, device, amount, currency, and BIN signals enrich analysis but are not all mandatory.
  • The SEON decision is normalized into an operational route; the process remains responsible for the final action.

Typical scenario

A buyer confirms a EUR 12,000 order. The process supplies the order as subject, the company as company, the contact as contact, plus the IP address and device session collected during checkout. SEON returns review_required: confirmation is suspended and the process opens a fraud review.

Quick start

Two bindings are enough to launch a first assessment. Then add available signals to improve decision quality.

Minimum requis

  • Select an active SEON extension_config_id.
  • Bind subject to the business object being assessed.

Recommended for checkout

  • Choose a coherent action_type, usually purchase for an order.
  • Bind company and contact to buyer context.
  • Pass the actually observed ip_address.
  • Bind the output of Collect device session (SEON) to device_session.
Configuration example
ParameterBindingRole
subjectorderAssessed operation
action_typepurchaseDecision context
companybuyer_companyBuyer company
contactbuyer_contactPerson initiating the action
ip_addresscheckout.ip_addressActually observed IP
device_sessioncollect_device.device_sessionRecommended device signal
Key point Do not map amount, currency, email, or phone when they are already available on linked objects. Check Data resolution first.

Decision routes

approved

Acceptable risk

SEON recommends continuing the operation.

Recommended actionContinue the order, payment, or onboarding.
review_required

Uncertain decision

Available signals are insufficient for a safe automatic approval or decline.

Recommended actionSuspend the operation, open a manual review, or request an additional check.
declined

High risk

SEON recommends not continuing the operation.

Recommended actionBlock or decline the action and retain the result for audit or fraud feedback.
Attention An intermediate or unrecognized SEON decision is always routed to review_required, never to approved.

Process example

Contexte checkout
Collecter une session appareil (SEON)
Évaluer le risque de fraude (SEON)
Approuvé
Revue requise
Refusé
Continue the order
Revue antifraude
Block the operation

Recommended checkout example: collect device signals, assess the order, then continue, request review, or block according to the SEON decision.

Data resolution

An explicitly configured node value always takes precedence. When absent, Ormuz looks for the data on linked business objects.

DataPriority order
Referencetransaction_reference → subject.id
Emailemail → contact.email → subject.email
Phonephone → contact.phone → contact.phone_number → subject.phone
IP addressip_address → subject.ip_address → subject.ip
Session appareildevice_session → subject.device_session
Amountamount → subject.gross_amount → subject.amount → subject.amount_including_tax → subject.total_amount
Currencycurrency → subject.currency
BINcard_bin → subject.card_bin
User identitycontact → company

Parameters 15

Essentiels

Parameters required to obtain a usable decision.

extension_config_idRequisref(extension_config:seon)
Active SEON configuration used for the call. It notably defines processing region, modules enabled by default, maximum response timeout, and allowed custom fields.
subjectRequisobject
Business object whose risk you want to assess. The node accepts platform.company, platform.contact, platform.onboarding_case, platform.checkout_session, platform.order, platform.invoice, and platform.supplier_invoice. Its identifier becomes the default SEON reference. Depending on the object, the node may also reuse available amount, currency, email, phone, IP address, or BIN.
action_typeOptionnelenum
Business context sent to SEON. It lets the appropriate rules and thresholds apply to the journey stage. Default: purchase.
ValueCas d’usage
signupAccount creation
loginConnexion
account_updateSensitive account modification
checkoutOrder journey
purchasePurchase or order confirmation
payment_attemptPayment attempt
paymentCompleted payment
refundRemboursement
payoutDisbursement or outgoing transfer
customSpecific business event

Contexte client

Information about the company or person behind the operation.

companyOptionnelCompany
Company or organization associated with the operation. It lets SEON receive user identifier, legal name, and country when those are not carried directly by the primary subject.
contactOptionnelContact
Person associated with the operation. The node can derive user identifier, full name, email, phone, and country. When both person and company are supplied, person contact details take precedence.
emailOptionnelemail
Email address to analyze. This value overrides contact.email, then subject.email. Returned enrichment depends on Email Intelligence being enabled on the configuration and SEON account.
phoneOptionnelstring
Phone number to analyze. This value overrides contact.phone, contact.phone_number, then subject.phone. Prefer an international E.164 number, for example +33612345678.

Operation context

Economic value and reference of the assessed event.

amountOptionnelnumber
Operation amount. When absent, the node looks in order for subject.gross_amount, subject.amount, subject.amount_including_tax, then subject.total_amount. The value is sent as-is: use an amount convention consistent with your Ormuz objects and SEON contract.
currencyOptionnelcurrency code
Operation currency, for example EUR, USD, or GBP. When absent, the node uses subject.currency. The value is normalized to uppercase.
transaction_referenceOptional · advancedstring
Unique assessment reference sent to SEON. By default the node uses the subject identifier. Set it when several distinct assessments must exist for the same object, for example ord_123:payment_attempt:2. The node fails when no reference can be determined.

Signaux antifraude

Network, device, and card signals that improve scoring quality.

ip_addressOptionnelstring
IP address observed during the action. It overrides subject.ip_address, then subject.ip. It enables geolocation, proxy, VPN, Tor, datacenter, and reputation signals available from SEON.
device_sessionOptionnelstring
Encrypted session produced by Collect device session (SEON). Bind its device_session output here to enrich the assessment with Device Intelligence. The content remains opaque to the process and may be omitted when no device collection is available.
card_binOptional · advancedstring
Card BIN, usually the first six to eight digits. It can help SEON analyze country, issuer, network, or card type. Never provide the full card number.
Advanced settings

Use these parameters to adjust enrichments or send controlled metadata to SEON.

modulesOptionnelobject
Overrides modules used only for this assessment. Any absent property keeps the setting from SEON configuration.
PropertyEffet
email_apiEmail-address analysis and enrichment
phone_apiPhone analysis and enrichment
ip_apiNetwork, location, and IP-reputation analysis
device_fingerprintingUse of the Device Intelligence session
aml_apiAML enrichment when supported by your SEON plan
custom_fieldsOptional · advancedobject
Additional business metadata, for example sales_channel or customer_segment. Only keys present in custom_fields_allowlist on the SEON configuration are sent. Ormuz automatically adds ormuz_subject_type and ormuz_subject_id. Do not place secrets, full card numbers, or unnecessary personal data here.

Outputs 9

Decision and traceability

Main outputs to use in the process.

fraud_assessmentSeon fraud assessment
Primary assessment result: normalized decision, provider state, fraud score, risk level, applied rules, and computation time. fraud_assessment.decision determines the node route.
selected_routeenum
Route actually selected: approved, review_required, or declined.
seon_transactionSeon transaction
Normalized SEON transaction. It notably exposes provider identifier, reference, state, fraud score, and dates returned by SEON. Keep it for later rereading with Get transaction (SEON) or for feedback.

Enrichissements disponibles

Detailed signals present only when the corresponding modules are enabled and populated.

email_intelligenceOptionnelSeon email intelligence
Email-enrichment signals returned by SEON when available and the relevant module is enabled.
phone_intelligenceOptionnelSeon phone intelligence
Phone-enrichment signals returned by SEON when available and the relevant module is enabled.
ip_intelligenceOptionnelSeon ip intelligence
IP-related signals returned by SEON, for example available network or location information in the provider response.
device_intelligenceOptionnelSeon device intelligence
Device Intelligence signals returned by SEON when a device session was supplied and the module is enabled.
bin_intelligenceOptionnelSeon bin intelligence
Card-BIN information when present in the SEON response.
Binding compatibility

selected_value contains the same normalized decision as selected_route and serves bindings expecting a value rather than a route.

selected_valueenum
Normalized decision value, identical to selected_route, available for bindings and process outputs.

Behavior

Build the risk context

The subject sets the operation being analyzed. company and contact add company/person context, while explicit values override automatically derived data.

Apply enrichments

Email, Phone, IP, and Device modules follow SEON configuration settings unless temporarily overridden through modules. AML is disabled by default.

Assess and normalize

SEON analyzes available signals. Ormuz exposes the provider transaction, normalized assessment, and available enrichments without modifying the assessed business object.

Select the route

Approval states become approved, decline states declined, and review, intermediate, or unknown states review_required.

Reuse the result

When the subject has an identifier, Get transaction (SEON) and Submit fraud feedback (SEON) can resolve the transaction from that same subject.

Limits and responsibilities

  • The node does not collect device signals itself: use Collect device session (SEON) when Device Intelligence is required.
  • It does not modify the assessed order, customer, payment, or case and does not automatically create a risk business object.
  • approved means risk is acceptable according to the received decision; it does not guarantee absence of fraud.
  • declined is a SEON operational recommendation. Process business policy determines the final action.
  • Human review or an additional check remains necessary when context, amount, or internal policy requires it.