# Advocate Fraud Protection Explained

Fraud is a risk in any referral program. You can use Fraud Protection to detect self-referrals and reduce reward abuse.

Your Advocate program has an optional, automated Fraud Protection feature that can be used together with manual actions like [blocking email domains](https://help.impact.com/brand/what-would-you-like-to-learn-about/advocate-program/protect-your-advocate-program/block-an-email-domain-for-advocate) and specific [participants and IP addresses](https://help.impact.com/brand/what-would-you-like-to-learn-about/advocate-program/protect-your-advocate-program/security-features-for-referral-programs) to mitigate the effects of fraudulent behavior. However, keep in mind that the strongest defense against referral program fraud is [effective program design](https://help.impact.com/brand/what-would-you-like-to-learn-about/advocate-program/protect-your-advocate-program/design-a-fraud-proof-referral-program).

If you use Shopify, you can turn on *Enhanced Shopify Fraud Protection*. The system runs extra checks on each referred purchase. It can block suspected self-referrals before rewards are issued.

Referrals are only placed into a pending state after you turn on Fraud Protection for your Advocate account and when your selected *Fraud Protection* level allows manual review.

1. From the top navigation bar, select ![](https://4048883401-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FwMLlMoFBtKJa8ptd3zaw%2Fuploads%2Fgit-blob-1183576591b45997efe4dc81a25024640591d02a%2F245137dc972a7a7f6165b59538fcdbac8fd5bd8fee4ba9f20c1a2982c5b58b57.svg?alt=media) **\[User profile] → Settings**.&#x20;
2. From the *Advocate Settings* section, select **Security**.
3. Select ![](https://4048883401-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FwMLlMoFBtKJa8ptd3zaw%2Fuploads%2Fgit-blob-d0b6669ae76a7bef06a8d6940d7ad5c16bb8d018%2F7cb018d4face8d7cceb880eb5086c812e764fbcfe6f2a0377f88bc7576973070.svg?alt=media) **\[Toggle on] Automatic fraud detection**.
4. Also select  ![](https://4048883401-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FwMLlMoFBtKJa8ptd3zaw%2Fuploads%2Fgit-blob-d0b6669ae76a7bef06a8d6940d7ad5c16bb8d018%2F7cb018d4face8d7cceb880eb5086c812e764fbcfe6f2a0377f88bc7576973070.svg?alt=media) **\[Toggle on] Enhanced Shopify Fraud Protection** for further security checks if you're making use of Shopify.

<details>

<summary>Fraud scoring explained</summary>

When Fraud Protection is turned on, Advocate will evaluate and assign a fraud score to all new referrals.

The fraud score ranges from 0 (no risk detected) to 100 (very high risk). It is calculated by comparing each new referral against previous referrals to look for similarities. The overall score assigned to a referral determines whether it’s automatically approved or denied, or placed into a pending state for manual review.

When fraud protection is enabled for your *Shopify advocate program*, impact.com checks the advocate’s *name*, *billing/shipping address*, and *credit card* details against the referrer’s information used for previous transactions. If any of these fields match, they each contribute equally to the overall fraud score (each one has the same influence on the score as the advocate’s name). If the resulting fraud score exceeds your configured fraud threshold, the transaction is marked as high risk and is automatically treated as unsuccessful.

| Factor                                                                   | Influence on score | Example Referral Information                                                      |
| ------------------------------------------------------------------------ | ------------------ | --------------------------------------------------------------------------------- |
| Same email address                                                       | High               | **<robinbanks@example.com>** and **<robinbanks+test@example.com>**                |
| Same name (exact match only)                                             | High               | **Robin Banks** and **Robin Banks**                                               |
| Same IP address                                                          | Medium             | **192.158.1.38** and **192.158.1.38**                                             |
| Similar email address                                                    | Medium             | **<robinbanks@example.com>** and **<RBanks@example.com>**                         |
| Similar name                                                             | Medium             | **ROBIN BANKS** and **Robby Banks**                                               |
| <p>Same address<br><strong>\[Shopify users]</strong></p>                 | High               | **P. Sherman, 42 Wallaby Way, Sydney** and **P. Sherman, 42 Wallaby Way, Sydney** |
| <p>Same credit card information<br><strong>\[Shopify users]</strong></p> | High               | **5100 1234 5678 9010** and **5100 1234 5678 9010**                               |

</details>

<details>

<summary>Fraud Protection settings</summary>

Advocate supports three Fraud Protection levels: *Relaxed*, *Moderate*, or *Strict*. The level you select applies to all of your referral programs. Legacy referrals won’t be evaluated.

When fraud protection is enabled for your *Shopify advocate program*, impact.com checks the advocate’s *name*, *billing/shipping address*, and *credit card* details against the referrer’s information used for previous transactions. If any of these fields match, they each contribute equally to the overall fraud score. If the resulting fraud score exceeds your configured fraud threshold, the transaction is marked as high risk and is automatically treated as unsuccessful.

**Relaxed**

The *Relaxed* setting is best for brands that want to streamline their referral program and reduce the likelihood of denying legitimate referrals. This level allows more referrals while accepting the possibility of some self-referrals.

Using the *Relaxed* setting, most referrals are automatically approved. If a referral is highly likely to be fraudulent, then it will be automatically denied.

| Fraud Score | Action                 |
| ----------- | ---------------------- |
| 0 to 84     | Automatically approved |
| 85 to 100   | Automatically denied   |

**Moderate**

The Moderate setting is appropriate for brands with capacity for hands-on review of their referrals. This level provides a middle ground, allowing manual review of potential self-referrals for a more accurate referral program.

| Fraud Score | Action                                                                                                                                                                                              |
| ----------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| 0 to 69     | Automatically approved                                                                                                                                                                              |
| 70 to 84    | [Manual review](https://help.impact.com/brand/what-would-you-like-to-learn-about/advocate-program/manage-advocate-participants/referrals-and-events/review-pending-referrals-for-advocate) required |
| 85 to 100   | Automatically denied                                                                                                                                                                                |

{% hint style="info" %}
**Note:** If you turn off fraud protection while any referrals are in a pending state, these referrals will remain pending until manually reviewed.
{% endhint %}

**Strict**

The *Strict* setting is recommended for brands prioritizing highly secure programs. This level may occasionally flag legitimate referrals, but it significantly reduces the likelihood of self-referrals.

| Fraud Score | Action                 |
| ----------- | ---------------------- |
| 0 to 49     | Automatically approved |
| 50 to 100   | Automatically denied   |

</details>

<details>

<summary>Participant experience for instant access widgets</summary>

Typically, programs using [instant access widgets](https://help.impact.com/brand/what-would-you-like-to-learn-about/advocate-program/manage-advocate-participant-experiences/widget-experiences/widget-types-explained) immediately grant a reward to the referred friend. When Fraud Protection is turned on and Advocate detects a suspicious referral attempt, the referral is either denied or placed into a pending state, depending on its fraud score and your settings. Customer advocates see a message within the widget letting them know the referral was either denied or flagged for manual review. For pending referrals, no reward is issued unless you approve the referral.

<div data-with-frame="true"><figure><img src="https://4048883401-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FwMLlMoFBtKJa8ptd3zaw%2Fuploads%2Fgit-blob-84f55c4b6105b7cbc65cbfa1322537a9adb5f1bb%2F4c51869299e992e0efc7ef7040c215ef9682d938a5b1ee6bddd7208be3eba00a.png?alt=media" alt=""><figcaption></figcaption></figure></div>

</details>

#### Learn more

* [Design a Fraud-Proof Referral Program](https://help.impact.com/brand/what-would-you-like-to-learn-about/advocate-program/protect-your-advocate-program/design-a-fraud-proof-referral-program)
* [Review Pending Referrals for Advocate](https://help.impact.com/brand/what-would-you-like-to-learn-about/advocate-program/manage-advocate-participants/referrals-and-events/review-pending-referrals-for-advocate)
