1. Rowfire
  2. Use cases

Send flagged orders to a fraud service

Post high-risk orders from MySQL to your fraud-review service's API, once per order, without changing checkout code. Trigger SQL and request shape included.

  • MySQL
  • Any REST API
  • Slack
  • Risk
  • once per order

The trigger

One read-only SELECT against MySQL. Rowfire polls it for new rows, and the rule fires once per order.

SELECT o.id AS order_id,
       o.customer_id,
       o.total_amount,
       o.currency,
       o.risk_score,
       o.shipping_country,
       o.created_at
FROM orders o
WHERE o.risk_score >= 80
  AND o.is_test = 0

The clock is created_at and the key is order_id. The query runs in MySQL’s own dialect, read-only. Table and column names are a sketch; adapt them to your schema.

The request

Configure the fraud service as an integration: its base URL, its auth and a review action. Templates fill the body from the row:

POST /reviews
{"order_id": "{{ order_id }}", "amount": "{{ total_amount }}", "currency": "{{ currency }}", "score": {{ risk_score }}, "country": "{{ shipping_country }}"}

The threshold lives in the query, so changing 80 to 70 is a trigger edit, not a release. Editing a trigger with live rules on it sends them back to shadow, so you see the effect of the new threshold before it sends.

For another order problem that a query catches, see orders paid but not fulfilled.

Questions

Does this replace checking fraud during checkout?

No. Blocking a payment belongs in the checkout request. This sends orders for review after they're placed, within a minute by default.

Can the risk team see them in Slack too?

Yes. Add a second rule on the same trigger that posts to a Slack channel. Each rule has its own cadence and actions.