Operations
False positives hiding in checkout queues
12 min read · Schema Designlab Journal
A mid-size United Kingdom retailer came to us with a familiar complaint: conversion dipped on evenings when the fraud queue looked “healthy.” Approvals were up. Customer emails about declined cards were also up. The tension lived between those two dashboards.
Their fraud signal audit app listed forty-one active rules. Only nineteen had a named owner who still worked at the company. The rest had inherited labels like “legacy device” or “promo abuse v2” with no proof claim attached.
Start with decline reasons, not rule names
We asked the team to sample two hundred declined checkouts from a single Thursday and map each decline code back to the signal that contributed most weight. The exercise was tedious. It also revealed that a velocity check tuned for flash sales was still firing on ordinary weekday baskets for loyalty members who shopped after work.
That rule had never been wrong in the abstract. It was simply undernourished: no compensating check on account tenure, no carve-out for known store-and-collect patterns, no owner who reviewed false-positive tickets weekly.
What changed
Within three weeks they narrowed the velocity window, added a tenure gate, and wrote a failure-mode card stating that evening loyalty traffic would still generate residual noise. They did not promise silence. They promised a measured rate and a review date.
Checkout complaints about unexplained declines fell. The queue did not vanish — it became explainable. That is the bar we teach in Signal Audit Desk: can a new analyst defend why this alert still deserves a seat?