Blog

Merchant refund guards: stopping anomalous refunds before money leaves

Refund automation with standing keys is a fraud vector. Pre-execution authorization holds anomalous refunds until a named approver authorizes this exact amount.

Support agents and automations issue refunds with API keys. Value spikes go unnoticed until reconciliation — or never.

A merchant refund guard evaluates each proposed refund: actor, amount, merchant context, policy threshold, and behavioral risk. Anomalous spikes route to APPROVAL_REQUIRED.

Not a class of refunds — this €4,800 refund from support-agent-04 under refund-policy-v7. Single-use approval. Evidence preserved whether ALLOW or DENY.

Proof

See it in the Proof Lab

Redacted authority loop demonstrations.