Review fraud alerts

Review fraud alerts in Stripe — with the four heights of help laid out: do it now, make it easier for the next person to accept, work out the right move when you are stuck, and learn the pattern so it stops coming back.

4prompt heights
Open it in the interactive atlas →

The four heights

The same task, four distances: today's deadline, the next reviewer, the stuck moment, the pattern.

Execute — do the immediate task

+
We have a pile of fraud alerts from overnight. Review the alerts, prioritize ones showing card…
We have a pile of fraud alerts from overnight. Review the alerts, prioritize ones showing card testing patterns and repeated declines from the same IP, escalate any that hit our merchant threshold to Sam in finance, and clear low‑confidence alerts by noon. Record reasoning for each cleared alert.

Improve — make it easier to accept

+
Before I clear these fraud alerts, make it easy for the reviewer: surface indicators that matter —…
Before I clear these fraud alerts, make it easy for the reviewer: surface indicators that matter — number of attempts, AVS/CVC failures, velocity from same IP, and matching past‑fraud fingerprints. Highlight alerts likely to be false positives (repeat corporate cards, known resellers) and list what would make a reviewer hesitate to clear an alert so we can get a second opinion quickly.

Decide — diagnose the stuck moment

+
Forty fraud alerts arrived during my meetings; some show three attempts from one IP, others are…

Forty fraud alerts piled up while I was in meetings and I don’t know which to escalate.

Forty fraud alerts arrived during my meetings; some show three attempts from one IP, others are single fails with high ticket amounts. I fear missing a real attack or needlessly blocking a customer. What indicators should I use to triage fast and which ones reliably mean escalate to Sam in finance versus clear? Also what quick notes should I leave so the next reviewer understands my decision?

Become — change the pattern

+
Each day the ops team spends hours triaging alerts; we clear many low‑risk ones and only rarely…

We react to daily fraud alerts but never reduce their volume or improve accuracy.

Each day the ops team spends hours triaging alerts; we clear many low‑risk ones and only rarely catch the real attacks. It wastes the engineers’ time and delays product work. What changes in monitoring thresholds, alert grouping, or a simple machine‑learning feedback loop should we adopt so alert volume drops and signal rises — practical steps my team can implement this quarter?

Next to this one

Other payments work people do in Stripe.

Every task here came from the work, not from a feature list — which is why the prompts name what you want done and never the button that does it. The tool changes; the work does not.
Copyright © LLOS.ai · 2026 — original pedagogy, voice, and design — all rights reserved.

The rest of the map

Same library, five ways in.