The question this workflow owns
Can an authorized reviewer reconstruct the evidence, reasons, uncertainty, decisions, actions, and later corrections behind an incident? This page is written for fraud investigators, paid-media operators, analysts, agency reviewers, managers, auditors, and teams responsible for explaining why a traffic decision was made. Its owner is the versioned incident, evidence timeline, human review, decision rationale, and attributable case history, so adjacent product surfaces can reference the result without silently changing its meaning or authority.
The supported decision is whether an incident needs more evidence, remains unclassified, can be dismissed, meets an approved policy classification, supports a governed next action, or requires correction or reversal. That decision remains qualified by the selected property or client, eligible population, time window, filters, definitions, coverage, freshness, permissions, and evidence available when the workflow runs.
- Workflow owner: the versioned incident, evidence timeline, human review, decision rationale, and attributable case history
- Audience: fraud investigators, paid-media operators, analysts, agency reviewers, managers, auditors, and teams responsible for explaining why a traffic decision was made
- Supported decision: an incident needs more evidence, remains unclassified, can be dismissed, meets an approved policy classification, supports a governed next action, or requires correction or reversal
Inputs retain their original meaning
Inputs include a versioned risk incident, eligible signal and assessment snapshots, linked acquisition and website evidence, visitor and session context, recordings, conversions, leads, tracking state, assignments, notes, external facts, and prior decisions. An observed event, calculated metric, inferred relationship, customer-provided field, provider-reported state, and human decision are different evidence types. The workflow records which type produced each value instead of flattening all of them into a generic fact.
Every reason, annotation, assignment, evidence link, decision, approval, request, provider response, verification, correction, and reversal retains source or actor, time, scope, version, and relationship to the incident. Source identity, event time, ingestion time, calculation time, definition or model version, eligible scope, confidence, coverage, freshness, and correction history travel with the result wherever the interface presents it.
Boundaries remain visible
The investigation record interprets and links evidence but does not mutate raw observations, manufacture unavailable context, replace provider state, or prove a commercial outcome from reviewer judgment. This distinction prevents collection from being treated as acceptance, a signal as confirmation, a recommendation as execution, an attempt as provider application, or an applied state as a verified business result.
When a required input, permission, provider capability, identity link, outcome, or correction path is missing, the method narrows the supported result or returns unavailable, incomplete, unclassified, needs-review, failed, expired, or unknown. It does not replace missing evidence with an authoritative-looking estimate.