Scores you can explain, cases you can close.
Configurable rules produce a 0–100 score and a risk level for every player, recalculated nightly and on events. Analysts see the score move, open a case, assign it, escalate it and resolve it against an SLA. Auto-actions ship report-only until you switch them on.
- 0–100
- risk score from configurable rules, nightly and on events
- Report-only
- auto-actions ship off until you switch them on
- Device · ID · location
- signals behind duplicate-account detection
- Graded
- suspension reasons, timed blocks and surgical action blocks
- Safe by default
- payments stop when a signature or secret is missing
Identity, behavior, geography and the player's own limits.
Risk is a workflow here, not a verdict. Signals feed a score, the score feeds a case, and the case ends in a documented, logged action.
Risk scoring and cases
- Score 0–100 from configurable rules, mapped to risk levels
- Nightly recalculation plus event-driven updates when something changes
- Whitelist and manual override, both audited
- Auto-actions are report-only until enabled, so the team sees what would have happened first
- Cases: open → investigate → resolve, with assignment, escalation, SLA and notes
- Risky Players, Duplicate Accounts and in-house fraud scoring Lookup screens in the Risk group of the console
Identity and device
- Duplicate Accounts across email, phone, device, address, name, IP and location
- in-house fraud scoring at registration and login, with device fingerprinting through the native plugins and block-on-decline
- ID document and selfie with liveness; callbacks hardened
- MaxMind GeoIP as a second opinion on location
- Admin 2FA with an authenticator app, backup codes and lockout
Geo and responsible gaming
- Country and state allow/deny lists, a restricted-region page and GPS re-check for state-level rules
- Deposit, loss, wager, single-bet and session limits with per-brand defaults
- Reality checks, cooling off and self-exclusion from one day to permanent
- Consent matrix: Email, SMS, Push, Phone, Post and Partner × Casino and Sports, with one-click unsubscribe
- Suppressions for bounces, complaints, SMS STOP, invalid and manual, global or per brand, with audited lift
- GDPR purge with typed confirmation; every admin action in the Activity Log
Bonus abuse controls
- Five limits enforced on every grant path: per player, per day, global, budget and cooldown
- Velocity checks at bonus time
- Duplicate Accounts review before a redeem is approved
- in-house fraud scoring block-on-decline at registration keeps declined signups out of the player base
- Referral program with eligibility rules and fraud blocking
The rulebook is a brand setting.
Business model is chosen per brand. Sweepstakes gates AMOE and the Store-plus-Redeem cashier mapping; Real Money and Crypto switch to Deposit and Withdraw. The same console runs both.
- AMOE mail-in entries with 8-character barcode postcards and an admin queue for Requests and Settings
- Gold Coins (GC) for play and Sweeps Coins (SC) for prizes, redeemable after playthrough and KYC, on one ledger
- Sweepstakes rules pages served per brand
- Country and state allow/deny with a restricted-region page
State-level geo with GPS re-check where a country lookup is not enough.
Signal, score, case, resolution.
- Step 1Signal
Registration and login pass in-house fraud scoring; ID and selfie are verified with liveness; MaxMind and GPS confirm location; duplicate-account matching runs across device, identity and location signals.
- Step 2Score
Configurable rules produce the 0–100 score and a level. Nightly recalculation catches slow drift; event-driven updates catch sudden change.
- Step 3Case
An analyst opens or is assigned a case, investigates with notes, escalates if needed and works against an SLA. Report-only auto-actions show what an enabled rule would have done.
- Step 4Resolution
Resolve with a documented outcome: whitelist, manual override, a graded suspension reason, a timed block or a surgical action block. All of it lands in the Activity Log.
Compliance, fraud and support work the same case.
Evidence you can hand to an auditor.
- Activity Log for every admin action
- Consent matrix and suppressions enforced on every send
- Responsible-gaming limits, reality checks, cooling off and self-exclusion
- Certification-ready RNG dossier for GLI-11/19, BMM and iTech Labs submissions
Signals in one place, decisions in one workflow.
- Risk score from configurable rules and levels
- Duplicate Accounts across device, identity and location signals
- in-house fraud scoring Lookup and block-on-decline
- Cases with assignment, escalation and SLA
Act on a player without breaking their account.
- Graded suspension reasons and timed blocks with auto-release
- Surgical blocks on deposits, bets or withdrawals
- GDPR purge with typed confirmation
- Complete player profile, including Responsible Gaming
What compliance teams ask first.
Does the platform block fraud automatically?
Are you GLI-certified?
Can we detect one person running several accounts?
Which KYC vendor is integrated?
How is responsible gaming handled for real-money brands?
How do you handle state-by-state rules in the US?
Systems on either side of a case.
Payments and ledger
Payout queue for redeems and withdrawals, enriched with lifetime deposits, GGR and a payout-to-deposit risk level.
Saber maisOperator console
role-based permissions with action permissions on every money-moving operation, admin 2FA and an Activity Log for everything.
Saber maisMarkets
Regional orientation on licensing routes and geo controls, not legal advice.
Saber mais