Fraud Detection Rules
Fraud Detection Rules allow you to define conditions that flag guests and employees whose activity may indicate fraudulent behavior. You can configure thresholds to identify suspicious patterns and, where enabled, attach automated actions that respond to violations without requiring manual review.

Configure Fraud Detection Rules
Note: After updating any configuration in Fraud Detection rules, the number of suspects identified will only change on a go-forward basis. This means only new guests who meet the updated criteria will be flagged from that point onward. The rules do not apply retroactively to previously identified suspects.
- Navigate to Fraud > Fraud Detection Rules.
- Click on a rule to expand and view its settings.
- Set the rule parameters according to the config options and according to what values you believe best indicate potential fraudulent activity. (See more details below.
- Click Save to update the rule.
- Repeat steps 2-4 for as many rules as you want to enable.
Once a user has been flagged for fraudulent activity, you can view further details on the Fraud > Fraud Suspects page.
Auto-Action Configuration
Automated actions are an optional feature that must be enabled by your Punchh representative before the configuration fields below are visible in the dashboard.
When automation is enabled, the following fields become available on all supported fraud rules:
| Field | Description |
|---|---|
| Violations | The number of times a guest must breach a rule before the automated action is applied. |
| Violations Lookback (days) | The rolling window (1–365 days) within which violations are counted. Required when an automated action is selected. |
| Automated Action | The action automatically applied once the violation threshold is reached (see options below). |
The following automated actions are available:
| Action | Behavior |
|---|---|
| Ban | The guest is blocked from earning and redeeming points. Login access is retained. |
| Deactivate | The guest cannot log in to their account. Earning and redemption access is also blocked. |
| Ban and Force Redeem | The guest is banned and all available points are force redeemed. Force Redeem actions are not immediate. Points are processed after a configured grace period (default: 2 days). If a guest is unbanned or reactivated within this period, the scheduled redemption is cancelled and their points are retained. If reactivation occurs after the grace period has elapsed, points remain at zero. |
| Deactivate and Force Redeem | The guest cannot log in and all available points are force redeemed. |
Caution: The Ban and Force Redeem and Deactivate and Force Redeem actions are irreversible and irrevocable. Points that have been force redeemed cannot be restored, even if the guest is later unbanned or reactivated. Use these actions carefully.
Any guests that are Banned or Deactivated by one of the auto-action rules will still show up on their respective lists (Banned Guests, Deactivated) and will be labeled as "auto" in the comments column.
Fraud Rule Descriptions and Settings
Select the desired Fraud Detection Rule to configure. It should be noted that Fraud Detection Rules are based on scan time, meaning the time when a guest scans/attempts to scan a receipt, not when the original transaction took place.












