In short. Short answer: watch for the shape of a proposal, never for the type of person. Flag, do not accuse — a human makes the decision. Warn the user in the moment. Look at as little as the job requires. And never publish the specifics.

We should start with the obvious limitation of this article: it will not tell you what our monitoring looks for, how it decides, or where its thresholds sit. That is not coyness. Publishing the specifics of a detection system is the fastest way to make it useless, because the only people who study such a document closely are the people trying to get around it.

So this is about the principles, which are worth far more to anyone building something similar than the rules would be.

The pattern, not the person

Fraud on a marketplace is depressingly consistent. It almost always involves moving the conversation somewhere the platform cannot see, or restructuring the payment so that the protection everybody agreed to no longer applies. The specific words change constantly. The shape does not.

That is what makes the problem tractable, and it is also what keeps it fair: the system reacts to the shape of a proposal, not to who is making it. Nobody is scored on where they are from or what they look like.

The only people who read a published detection rule carefully are the people trying to get around it.

A paraglider over a mountain range

It flags. A person decides.

This is the part we would argue hardest for. Monitoring should raise its hand, not pass judgement. An automated accusation against a real customer is a serious thing to get wrong, and any system operating at scale will get some wrong.

So a flag is an invitation for a human to look, with the context attached and the decision left open. Some flagged behaviour turns out to be completely legitimate — arrangements that are perfectly acceptable when the platform knows about them and has agreed to them in advance. A system that cannot tell the difference between "against the rules" and "needs a decision" will punish honest people.

Warn the person in front of you

The most useful moment in the whole process is not the alert to the operator. It is the quiet word to the user, at the moment it matters, explaining why the thing being suggested to them removes their protection.

Most people being talked into an unsafe arrangement are not reckless. They simply do not know that the change being proposed is the whole scam. Told plainly and early, most of them stop.

Watch less than you are able to

There is a real ethical line here and it is easy to cross without noticing. Monitoring for safety is defensible. Building a general surveillance capability because you happen to have the data is not, and it will eventually be discovered.

The discipline is to look at as little as the job requires, keep as little as possible, and be able to explain the whole arrangement to a user without embarrassment. If a design would be uncomfortable to describe honestly in a privacy policy, that is the design telling you something.

Assume it will be wrong sometimes

Any monitoring worth running produces false positives, and a system that never does is simply not looking hard enough. That is an argument for making review cheap and reversible, not for switching it off.

It is also an argument for humility about what such a system is. It reduces harm. It does not eliminate it. Anyone claiming their platform has solved fraud is describing a marketing position rather than a technical one.

Why any of this matters commercially

Trust is the product. A marketplace where a buyer has been cheated once does not lose one transaction; it loses that person, everyone they tell, and the assumption of safety that made the next stranger willing to try. Protecting that is not a feature bolted on at the end. It is most of what the platform is for.

Common questions

Why not publish how your scam monitoring works?

Because the only people who read a published detection rule carefully are the people trying to get around it. Describing the principles helps anyone building something similar; describing the specifics would help only the people the system exists to catch.

Does monitoring mean reading private messages?

It means looking at as little as the job requires, keeping as little as possible, and being able to describe the whole arrangement to a user without embarrassment. Monitoring for safety is defensible; building a general surveillance capability because the data happens to be there is not.

Can automated monitoring stop fraud completely?

No, and anybody claiming otherwise is describing a marketing position rather than a technical one. It reduces harm. Any system worth running produces some false positives, which is an argument for making human review cheap and reversible — not for switching it off.

Related reading

Tell us what you need built →