Skip to content

Riskified wins · 1111 (23 drawn)

Agentic commerce — stories about agentic commerce in this arenaAgentic commerce

Stories about agentic commerce in this arena

Agent detection

  1. ai-native userThe product distinguishes malicious bots from legitimate AI buying agents, so agent-driven purchases aren't blanket-blocked as fraud

    weight 2 · round drawn
    Siftnone0/10

    Evidence covers general fraud scoring, workflows, and decisions but nothing addresses distinguishing AI shopping agents from malicious bots or agentic-commerce specific handling; missing for 10: any mention of AI agent traffic detection, agent-vs-bot classification, or agentic-commerce policy/whitelisting.

      Riskifiednone0/10

      The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

      Agent identity

      1. developerPass verified agent identity — agentic-payment protocols, signed agent tokens, delegated spending scopes — into the risk decision as a first-class signal

        weight 2 · round drawn
        Siftnone0/10

        No evidence Sift supports ingesting verified agent identity, agentic-payment protocol tokens, signed agent tokens, or delegated spending scopes as risk signals; docs only describe generic user/business event and custom-field ingestion. missing for 10: any mention of agentic-commerce protocols, signed agent tokens, or delegated spending scope support as a risk signal.

          Riskifiednone0/10

          No evidence in the pack mentions agentic-payment protocols, signed agent tokens, or delegated spending scopes as inputs to Riskified's risk decision; the documented signals are customer/order/payment data, HMAC request auth, and Beacon session IDs, none of which represent verified agent identity as a first-class fraud signal.

          Agenticness — how well agents can access and operate the productAgenticness

          How well agents can access and operate the product

          Agent access

          1. ai-native userPoint an agent at llms.txt or agent-oriented docs

            weight 2 · round to Riskified
            Siftnone0/10

            No evidence of an llms.txt file or agent-oriented documentation format; the docs are standard developer API references with no mention of AI-agent consumption. missing for 10: llms.txt file, agent-readable docs format, any mention of AI-agent-targeted documentation.

              Riskifiedfullprobed8/10

              A probe confirms Riskified hosts a working llms.txt at developers.riskified.com/llms.txt returning HTTP 200, and docs explicitly note pages can be fetched as markdown by appending .md — exactly the agent-oriented docs pattern. Missing for 10: no independent/third-party corroboration of an agent successfully consuming it, and no broader agent-specific documentation beyond the llms.txt index.

              • [probe] PROBE llms.txt: HTTP 200 at https://developers.riskified.com/llms.txt # Riskified documentation Documentation > Riskified Documentation Ap…
            • ai-native userRun the product headlessly / in CI for automation

              weight 2 · round drawn

              Sift is fundamentally API-driven (REST Events/Decisions APIs, SDKs) which is inherently 'headless' and can be called from backend or automated systems, but there is no explicit evidence of a CLI, CI pipeline integration, or documented headless automation workflow. Missing for 10: explicit CI/CD examples, CLI tooling, or automation-specific documentation beyond generic API integration.

              • [claimed-docs] Sift easily integrates into your existing systems using modern REST APIs, Javascript snippet, and SDKs for iOS and Android.
              • [claimed-docs] What actions your users are taking, usually key user lifecycle events (e.g., creating an account, placing an order, posting content to other…
              • [claimed-docs] What actions your business is taking in response to users (e.g., approve an order, block and event due to fraud, cancel order due to chargeb…
              • [claimed-docs] Because Sift gets smarter the more data it has about your business, you can jump start your integration by backfilling a few months worth of…
              Riskifiedpartialclaimed4/10

              Riskified is fundamentally an API-first fraud-decision service (decide/submit/advise/chargeback endpoints, SDKs, webhook notifications) that can be called programmatically without a UI, which supports headless/automated integration into checkout pipelines. However, there is no evidence of CI/CD-specific tooling, a CLI, or documented automation-testing workflows — the docs focus on production checkout integration, not build/test automation. Missing for 10: explicit CI/CD examples, a CLI or automation-testing guide, and confirmation of headless operation outside the live transaction flow.

              • [claimed-docs] The `/decide` endpoint is used to request that Riskified review an order for fraud after the customer has input their payment data and compl…
              • [claimed-docs] The `/submit` endpoint sends transaction data to Riskified after the gateway authorizes the transaction for fraud analysis... the fraud deci…
              • [claimed-docs] For each order reviewed by advise we provide a synchronous decision if it is clear fraud... CVV/3DS recommendations can be provided... TRA/S…
              • [claimed-docs] Riskified provides SDKs for several languages to simplify API integration. SDK usage is optional, and all API endpoints can also be accessed…
              • [claimed-docs] Riskified can send automated decision notifications to a merchant-defined endpoint when an order is approved or declined... If the endpoint …
            • ai-native userConnect an agent via an official MCP server

              weight 3 · round drawn
              Siftnone0/10

              Sift is a fraud-detection SaaS with REST/Decisions APIs and SDKs, but no evidence of an official MCP server for agent connectivity. missing for 10: any mention of MCP, agent integration protocol, or official MCP server endpoint.

              • [claimed-docs] Sift easily integrates into your existing systems using modern REST APIs, Javascript snippet, and SDKs for iOS and Android.
              Riskifiednone0/10

              The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

              • ai-native userUse an official CLI

                weight 2 · round drawn
                Siftnone0/10

                Sift's evidence pack covers REST APIs, SDKs, JS snippet, and Decisions/Workflows APIs, but no official CLI tool is mentioned anywhere in docs or community sources.

                  Riskifiednone0/10

                  The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                  • ai-native userDrive the product through a documented public API

                    weight 3 · round to Riskified

                    Sift documents REST APIs (Events, Decisions, Score, Workflows) that let developers programmatically drive fraud scoring and decisioning, which supports an AI-native integration story. However, this is a traditional fraud-ops API, not one purpose-built for AI agent orchestration, and there's no evidence of agent-specific tooling like an MCP server, function-calling schemas, or SDKs for LLM agents. missing for 10: agent-oriented API framing (e.g., MCP server, function-calling schema), independent hands-on validation of API usability beyond one user noting confusing docs.

                    • [claimed-docs] Sift easily integrates into your existing systems using modern REST APIs, Javascript snippet, and SDKs for iOS and Android.
                    • [claimed-docs] What actions your users are taking, usually key user lifecycle events (e.g., creating an account, placing an order, posting content to other…
                    • [claimed-docs] What actions your business is taking in response to users (e.g., approve an order, block and event due to fraud, cancel order due to chargeb…
                    • [claimed-docs] Sift represents this risk with a score between 0 and 100, where risky events have higher scores.
                    • [claimed-docs] Workflows enable you to make risk-based decisions in real time during key events. Follow this guide to create your own custom Workflow.
                    • [community] Early user feedback: 'I have been integrating it for a day or so. The documentation is slightly confusing and they've had a few minor bugs i…
                    Riskifiedfullprobed8/10

                    Riskified exposes a comprehensive documented REST API (decide, submit, advise, chargeback, notifications, login) with authentication (HMAC), synchronous/asynchronous flows, and optional SDKs, all directly callable via HTTP — clearly a documented public API an AI-native user could drive. The docs site also exposes an llms.txt for AI-friendly consumption, though no machine-readable OpenAPI/Swagger spec was found (404s on standard paths). Missing for 10: a discoverable OpenAPI/swagger schema and explicit rate-limit/versioning documentation.

                    • [claimed-docs] The `/decide` endpoint is used to request that Riskified review an order for fraud after the customer has input their payment data and compl…
                    • [claimed-docs] The `/submit` endpoint sends transaction data to Riskified after the gateway authorizes the transaction for fraud analysis... the fraud deci…
                    • [claimed-docs] For each order reviewed by advise we provide a synchronous decision if it is clear fraud... CVV/3DS recommendations can be provided... TRA/S…
                    • [claimed-docs] Riskified provides SDKs for several languages to simplify API integration. SDK usage is optional, and all API endpoints can also be accessed…
                    • [claimed-docs] X-RISKIFIED-HMAC-SHA256 | Verification hash for the Request. Generated by performing an SHA256 encryption on the request's POST body and cal…
                    • [claimed-docs] Riskified can send automated decision notifications to a merchant-defined endpoint when an order is approved or declined... If the endpoint …
                    • [claimed-docs] Riskified supports different integration types:\n- **Pre-authorization Synchronous**: Review orders before payment authorization\n- **Post-a…
                    • [probe] PROBE llms.txt: HTTP 200 at https://developers.riskified.com/llms.txt # Riskified documentation Documentation > Riskified Documentation Ap…
                    • [probe] PROBE openapi: all candidate paths 404 (https://developers.riskified.com/openapi.json, https://developers.riskified.com/swagger.json, https:…
                  • ai-native userBuild against official SDKs

                    weight 2 · round to Riskified
                    Siftnone0/10

                    Evidence shows Sift has REST APIs, JS snippet, and mobile SDKs for iOS/Android, but there's no mention of SDKs oriented toward AI-native development (e.g., LLM/agent SDKs, official Python/Node/AI framework SDKs). This story concerns AI-native developer tooling, which is not addressed anywhere in the pack. missing for 10: any evidence of AI-agent-oriented SDKs, LLM integration libraries, or agent framework support.

                      Riskifiedpartialclaimed5/10

                      Riskified's docs explicitly state that SDKs are provided for several languages to simplify API integration, confirming official SDK support (riskified-docs-5). However, the evidence lacks specifics such as which languages are covered, links to SDK repositories, or independent/community corroboration of SDK quality. Missing for 10: list of supported languages, links to SDK repos/package registries, hands-on developer feedback on SDK usability.

                      • [claimed-docs] Riskified provides SDKs for several languages to simplify API integration. SDK usage is optional, and all API endpoints can also be accessed…
                    • ai-native userSubscribe to events via webhooks

                      weight 2 · round to Riskified
                      Siftnone0/10

                      Sift's documented integration model is inbound REST APIs (Events, Decisions, Score, Workflows) for sending data to Sift, not outbound webhooks for subscribing to events from Sift. No evidence pack item mentions webhook subscriptions or event push notifications to external consumers.

                        Riskifiedpartialclaimed6/10

                        Riskified documents a webhook-style notification mechanism: decision outcomes are pushed to a merchant-defined endpoint with retries on non-2xx and HMAC-SHA256 signature verification, which functions as an event webhook for fraud decisions and chargebacks. However, this is a fixed set of built-in notification types (order decision, chargeback) rather than a general-purpose subscribable event system with selectable event topics or a dashboard for managing webhook subscriptions. Missing for 10: a documented event catalog/subscription model letting users choose which event types to receive, and any UI/API for creating or managing multiple webhook subscriptions.

                        • [claimed-docs] Riskified can send automated decision notifications to a merchant-defined endpoint when an order is approved or declined... If the endpoint …
                        • [claimed-docs] Riskified can send automated decision notifications to a merchant-defined endpoint when an order is approved or declined.
                        • [claimed-docs] X-RISKIFIED-HMAC-SHA256 | Verification hash for the Request. Generated by performing an SHA256 encryption on the request's POST body and cal…
                        • [claimed-docs] The `/submit` endpoint sends transaction data to Riskified after the gateway authorizes the transaction for fraud analysis... the fraud deci…
                        • [claimed-docs] Notifies Riskified that a chargeback has been submitted for a specific order.

                      Agentic features

                      1. ai-native userGet AI-generated insights and suggestions from my data inside the product

                        weight 2 · round drawn
                        Siftnone0/10

                        Sift provides risk scores and rule-based Workflows/Decisions derived from ML models, but there is no evidence of AI-generated natural-language insights or suggestions surfaced to users inside a product UI—everything is API-driven scoring and automation rather than generative/agentic insight delivery. Missing for 10: any documented AI-generated narrative insights, recommendations, or conversational/agentic assistant surfaced in-product, and any independent confirmation of such a feature.

                        • [claimed-docs] Sift represents this risk with a score between 0 and 100, where risky events have higher scores.
                        • [claimed-docs] Workflows enable you to make risk-based decisions in real time during key events. Follow this guide to create your own custom Workflow.
                        • [claimed-docs] Sift offers Workflows, a powerful rules automation platform, and Review Queues.
                        Riskifiednone0/10

                        The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                        • ai-native userSet up automations that run autonomously in the background

                          weight 2 · round to Sift

                          Sift's Workflows feature is described as a 'rules automation platform' that runs risk-based decisions autonomously in real time on incoming events, which fits the general notion of background automations. However, this is traditional rules/ML-based fraud automation, not an AI-native/agentic automation-building experience tailored to an 'AI-native user.' Missing for 10: evidence of AI-native automation authoring (e.g., natural-language or agent-driven workflow creation), broader use-case automations beyond fraud decisioning, and independent confirmation of autonomous operation quality.

                          • [claimed-docs] Workflows enable you to make risk-based decisions in real time during key events. Follow this guide to create your own custom Workflow.
                          • [claimed-docs] Sift offers Workflows, a powerful rules automation platform, and Review Queues.
                          • [claimed-docs] Learn to set up custom Decisions, like Ban Account or Cancel Order, that are connected to real business actions in your backend.
                          Riskifiednone0/10

                          The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                          • ai-native userDelegate tasks to a built-in AI assistant inside the product

                            weight 3 · round drawn
                            Siftnone0/10

                            The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                              Riskifiednone0/10

                              The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                              • ai-native userOperate the product with natural-language commands

                                weight 2 · round drawn
                                Siftnone0/10

                                The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                                  Riskifiednone0/10

                                  The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                                  Api quality

                                  1. ai-native userExplore an interactive API reference with runnable examples

                                    weight 2 · round drawn
                                    Siftnone0/10

                                    Evidence shows REST/Decisions/Events API docs exist but nothing describes an interactive API reference with runnable examples (e.g., embedded sandbox, try-it console). Missing for 10: interactive API explorer, runnable code examples, sandbox/try-it functionality.

                                      Riskifiednone0/10

                                      Evidence shows only static API reference docs (endpoints, parameters, notifications) with no mention of an interactive console, runnable examples, or live API explorer; the openapi.json/swagger.json probe returned 404s, indicating no machine-readable spec to power an interactive reference.

                                      • [probe] PROBE openapi: all candidate paths 404 (https://developers.riskified.com/openapi.json, https://developers.riskified.com/swagger.json, https:…
                                      • [claimed-docs] The `/decide` endpoint is used to request that Riskified review an order for fraud after the customer has input their payment data and compl…
                                      • [claimed-docs] Riskified supports different integration types:\n- **Pre-authorization Synchronous**: Review orders before payment authorization\n- **Post-a…
                                    • ai-native userDownload a machine-readable API spec (OpenAPI or equivalent)

                                      weight 2 · round drawn
                                      Siftnone0/10

                                      Evidence shows Sift has REST APIs (Events, Decisions, Score, Workflows) with docs, but no mention of a downloadable OpenAPI spec or other machine-readable API schema anywhere in the pack.

                                      • [claimed-docs] Sift easily integrates into your existing systems using modern REST APIs, Javascript snippet, and SDKs for iOS and Android.
                                      • [claimed-docs] What actions your users are taking, usually key user lifecycle events (e.g., creating an account, placing an order, posting content to other…
                                      • [claimed-docs] What actions your business is taking in response to users (e.g., approve an order, block and event due to fraud, cancel order due to chargeb…
                                      • [claimed-docs] Workflows enable you to make risk-based decisions in real time during key events. Follow this guide to create your own custom Workflow.
                                      Riskifiednone0/10

                                      A probe explicitly checked common OpenAPI/swagger spec locations and all returned 404, and no evidence pack item references a downloadable machine-readable API spec; only human-readable docs and an llms.txt are present.

                                      • [probe] PROBE openapi: all candidate paths 404 (https://developers.riskified.com/openapi.json, https://developers.riskified.com/swagger.json, https:…
                                      • [probe] PROBE llms.txt: HTTP 200 at https://developers.riskified.com/llms.txt # Riskified documentation Documentation > Riskified Documentation Ap…
                                    • ai-native userTest against a sandbox environment without touching production data

                                      weight 1 · round drawn
                                      Siftnone0/10

                                      No evidence pack item mentions a sandbox environment, test mode, or any way to test Sift integrations without touching production data; all docs reference live Events/Decisions/Score APIs. Missing for 10: sandbox/test environment docs, test API keys or staging mode, any mention of separating test vs production data.

                                        Riskifiednone0/10

                                        No evidence of a sandbox or test environment separate from production; docs describe live API endpoints, integration flows, and Shopify onboarding but never mention a sandbox/test mode for AI-native or developer testing.

                                        • ai-native userRely on versioned APIs with a documented deprecation policy

                                          weight 2 · round drawn
                                          Siftnone0/10

                                          Evidence shows Sift has REST APIs, SDKs, and docs but no mention of API versioning scheme or a documented deprecation policy anywhere in the pack. Missing for 10: explicit API versioning documentation, deprecation policy or changelog, migration timelines for breaking changes.

                                            Riskifiednone0/10

                                            No evidence of API versioning scheme (e.g., v1/v2 paths, version headers) or any documented deprecation policy; OpenAPI spec probes all returned 404. missing for 10: versioned endpoint scheme, deprecation/sunset policy documentation, changelog or migration guides.

                                            • [probe] PROBE openapi: all candidate paths 404 (https://developers.riskified.com/openapi.json, https://developers.riskified.com/swagger.json, https:…

                                          Automation depth — how much of the product can run unattendedAutomation depth

                                          How much of the product can run unattended

                                          1. ai-native userPerform bulk operations across many items at once

                                            weight 2 · round to Sift

                                            Sift documents backfilling months of historical data as a bulk-load capability, but there is no evidence of a dedicated bulk API for batch-scoring, batch-deciding, or bulk-updating many items at once (e.g., no batch endpoint documentation). Missing for 10: explicit bulk/batch API documentation, batch decision or batch scoring examples, and any hands-on evidence of bulk workflows being used successfully.

                                            • [claimed-docs] Because Sift gets smarter the more data it has about your business, you can jump start your integration by backfilling a few months worth of…
                                            • [claimed-docs] What actions your users are taking, usually key user lifecycle events (e.g., creating an account, placing an order, posting content to other…
                                            • [claimed-docs] What actions your business is taking in response to users (e.g., approve an order, block and event due to fraud, cancel order due to chargeb…
                                            Riskifiednone0/10

                                            Riskified's API is order-by-order (decide/submit/advise per transaction), with no evidence of a batch or bulk endpoint for processing many orders/items in a single call, nor any bulk chargeback or data-export operation.

                                            • ai-native userDefine rules that trigger actions automatically on events

                                              weight 3 · round to Riskified

                                              Sift's docs clearly describe a 'Workflows' rules automation platform that triggers real-time Decisions (Ban Account, Cancel Order) based on event risk scores, directly matching the story. However, a Sift co-founder is quoted saying 'we do not have any rules in our product... rules are rather easy for fraudsters to circumvent,' directly contradicting the vendor's later rules-automation framing. missing for 10: reconciliation of this contradiction and independent hands-on confirmation that customer-defined Workflow rules reliably trigger automated actions in production.

                                              • [claimed-docs] Workflows enable you to make risk-based decisions in real time during key events. Follow this guide to create your own custom Workflow.
                                              • [claimed-docs] Learn to set up custom Decisions, like Ban Account or Cancel Order, that are connected to real business actions in your backend.
                                              • [claimed-docs] Sift offers Workflows, a powerful rules automation platform, and Review Queues.
                                              • [community] CEO explains no-rules ML approach: 'we do not have any rules in our product... rules are rather easy for fraudsters to circumvent, and they …
                                              Riskifiedpartialclaimed3/10

                                              Riskified automatically triggers fixed actions on fraud-decision events (webhook notifications, Shopify integration auto-voiding/restocking/capturing on approve/decline) but there is no evidence of a user-configurable rules engine where an AI-native user can define custom conditions/actions themselves — the automation is built-in and non-customizable rather than rule-definable. Missing for 10: a rules/condition-authoring API or UI, examples of custom trigger logic, and any AI-native/agentic rule-configuration workflow.

                                              • [claimed-docs] Riskified can send automated decision notifications to a merchant-defined endpoint when an order is approved or declined... If the endpoint …
                                              • [claimed-docs] Riskified can send automated decision notifications to a merchant-defined endpoint when an order is approved or declined.
                                              • [claimed-docs] Voids authorization on orders declined by Riskified. Enables automatic restocking of orders declined by Riskified. Captures funds for orders…
                                              • [claimed-docs] Voids authorization on orders declined by Riskified. Enables automatic restocking of orders declined by Riskified. Captures funds for orders…

                                            Chargeback disputes — stories about chargeback disputes in this arenaChargeback disputes

                                            Stories about chargeback disputes in this arena

                                            Guarantee

                                            1. finance leadShift fraud liability to the vendor — a chargeback guarantee that reimburses approved-then-disputed orders, with clear coverage terms

                                              weight 2 · round to Riskified
                                              Siftnone0/10

                                              No evidence anywhere in the pack mentions a chargeback guarantee, liability shift, reimbursement for approved-then-disputed orders, or coverage terms — Sift is documented only as a fraud-scoring/risk-decision API, not an insurance-backed guarantee product.

                                                Riskifiedpartialclaimed5/10

                                                The evidence pack documents Riskified's API decisioning, chargeback notification, and chargeback gateway integration (automating chargeback reporting/disputing) but never states explicit financial liability-shift terms, reimbursement guarantees, coverage limits, or exclusions that a finance lead would need to evaluate a chargeback guarantee. Chargeback automation is a workflow/process feature, not proof of a monetary guarantee. missing for 10: explicit guarantee/reimbursement terms, coverage scope and exclusions, contractual liability-shift language, any evidence of actual reimbursement payouts.

                                                • [claimed-docs] Riskified offers fully automated chargeback gateway integrations for major gateways: Braintree, Stripe, Adyen, PayPal; this process automate…
                                                • [claimed-docs] Notifies Riskified that a chargeback has been submitted for a specific order.
                                                • [claimed-docs] The Chargeback Gateway Integration (CGI) framework enables seamless connectivity with leading payment gateways, including Adyen, Stripe, Bra…
                                                • [claimed-docs] Riskified can send automated decision notifications to a merchant-defined endpoint when an order is approved or declined... If the endpoint …

                                              Outcome reporting

                                              1. finance leadSee the numbers that matter — dispute rate, false-positive rate, approval-rate lift, review workload — and export them for the board

                                                weight 2 · round drawn
                                                Siftnone0/10

                                                Evidence covers APIs, scoring, workflows, and general product sentiment, but there is no mention of finance-lead dashboards, dispute-rate/false-positive/approval-lift metrics, review workload reporting, or board-ready export capability. missing for 10: dispute-rate and false-positive-rate metrics reporting, approval-rate lift analytics, review workload/queue metrics, export or reporting functionality for finance/board consumption.

                                                  Riskifiednone0/10

                                                  Evidence covers API/integration mechanics (decide, submit, chargeback automation, notifications) but nothing about a finance/reporting dashboard, KPI metrics (dispute rate, false-positive rate, approval-rate lift, review workload), or board-ready export functionality.

                                                  Representment

                                                  1. ops userChargeback responses are automated — evidence compiled from order, delivery, and session data and submitted to the issuer without manual copy-paste

                                                    weight 3 · round to Riskified
                                                    Siftnone0/10

                                                    The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                                                      Riskifiedpartialclaimed6/10

                                                      Riskified's Chargeback Gateway Integration (CGI) is documented as automating 'end-to-end chargeback handling from chargeback reporting to the disputing process' across major gateways, implying dispute evidence submission without manual copy-paste, and Riskified already ingests order, session (Beacon), and decision data through its APIs. However, the docs don't explicitly describe compiling delivery data or detail the specific evidence package sent to issuers during disputes. Missing for 10: explicit description of delivery-data inclusion in chargeback evidence, detail on the dispute evidence package format submitted to issuers, and independent/hands-on confirmation that submission is fully automated end-to-end.

                                                      • [claimed-docs] Riskified offers fully automated chargeback gateway integrations for major gateways: Braintree, Stripe, Adyen, PayPal; this process automate…
                                                      • [claimed-docs] Notifies Riskified that a chargeback has been submitted for a specific order.
                                                      • [claimed-docs] The Chargeback Gateway Integration (CGI) framework enables seamless connectivity with leading payment gateways, including Adyen, Stripe, Bra…
                                                      • [claimed-docs] Riskfied's Beacon is a JavaScript snippet that merchants embed on their website. It collects fundamental data required to decide on the legi…
                                                      • [claimed-docs] The `/submit` endpoint sends transaction data to Riskified after the gateway authorizes the transaction for fraud analysis... the fraud deci…

                                                    Fraud agent access — stories about fraud agent access in this arenaFraud agent access

                                                    Stories about fraud agent access in this arena

                                                    Agent operations

                                                    1. ai-native userAn agent can read my fraud posture and manage rules and lists programmatically — propose a velocity rule, update a blocklist — with human approval gates

                                                      weight 3 · round drawn
                                                      Siftnone0/10

                                                      Evidence shows REST/Decisions/Workflows APIs for events, scoring, and rules automation, but nothing describes an AI agent reading fraud posture or proposing/updating rules and lists with a human-approval workflow — this is a generic developer API story, not an agent-access pattern. missing for 10: any mention of AI agent integration, agentic rule-proposal workflow, or human-approval gate mechanism tied to programmatic rule/list changes.

                                                      • [claimed-docs] Sift easily integrates into your existing systems using modern REST APIs, Javascript snippet, and SDKs for iOS and Android.
                                                      • [claimed-docs] What actions your business is taking in response to users (e.g., approve an order, block and event due to fraud, cancel order due to chargeb…
                                                      • [claimed-docs] Sift offers Workflows, a powerful rules automation platform, and Review Queues.
                                                      Riskifiednone0/10

                                                      Evidence covers order review/decision APIs, notifications, chargeback automation, and Beacon data collection, but there is no mention of programmatic management of fraud rules, velocity rules, or blocklists, nor any agent-facing approval workflow for such changes.

                                                      Agent triage

                                                      1. ai-native userAn agent can work the review queue — pull flagged cases with their context, summarize the evidence, and recommend a decision for a human to confirm

                                                        weight 2 · round drawn
                                                        Siftnone0/10

                                                        Sift has Review Queues and REST/Decisions APIs for humans to review flagged cases (sift-docs-12, sift-docs-3), and community evidence confirms a human-in-the-loop review model (sift-comm-4), but there is no evidence of an AI agent programmatically pulling flagged cases, summarizing evidence, or recommending decisions for human confirmation.

                                                        • [claimed-docs] Sift offers Workflows, a powerful rules automation platform, and Review Queues.
                                                        • [claimed-docs] What actions your business is taking in response to users (e.g., approve an order, block and event due to fraud, cancel order due to chargeb…
                                                        • [community] Sift Science founder on false positives: 'Most of our customers review each user we flag, and have a human make a final go/no-go decision ab…
                                                        Riskifiednone0/10

                                                        Riskified's evidence describes automated decisioning APIs (/decide, /submit, /advise), notifications, and merchant integrations, but nothing describes an agent-accessible review queue with case context retrieval, evidence summarization, or a human-confirm workflow. No API for pulling flagged cases with context or generating human-reviewable recommendations is documented.

                                                        Builtin ai

                                                        1. risk analystThe product ships its own AI assistant — natural-language queries over my fraud data, drafted rules, investigation summaries — built into the console

                                                          weight 2 · round drawn
                                                          Siftnone0/10

                                                          The evidence pack covers Sift's APIs, scoring, workflows/rules automation, and review queues, but there is no mention of any built-in AI assistant, natural-language query capability, drafted rules generation, or investigation summary generation in the console. Missing for 10: any documentation or mention of a natural-language/AI assistant feature, evidence of NL-to-query capability, evidence of AI-drafted rules or summaries.

                                                          • [claimed-docs] Workflows enable you to make risk-based decisions in real time during key events. Follow this guide to create your own custom Workflow.
                                                          • [claimed-docs] Sift offers Workflows, a powerful rules automation platform, and Review Queues.
                                                          Riskifiednone0/10

                                                          Evidence covers API endpoints, webhooks, chargeback automation, Beacon SDK, and integration processes, but nothing describes a built-in AI assistant, natural-language query interface, rule drafting, or investigation summaries in the console.

                                                          Fraud surfaces — stories about fraud surfaces in this arenaFraud surfaces

                                                          Stories about fraud surfaces in this arena

                                                          Abuse coverage

                                                          1. risk analystProtection extends beyond checkout — account takeover, fake account creation, promo and policy abuse are scored and managed in the same system

                                                            weight 2 · round to Sift

                                                            Docs explicitly cover multiple fraud surfaces beyond checkout — account takeover ('Block unauthorized access in real time'), fake account creation ('Stop fraudulent signups at the door'), and abuse-specific scoring ('fight multiple types of fraud at once... add an abuse-specific risk score'), all managed within the same Workflows/Decisions/Review Queue system. Missing for 10: dedicated documentation or case study specifically on promo/policy abuse handling, and independent hands-on verification of multi-surface scoring in one unified dashboard.

                                                            • [claimed-docs] Block unauthorized access in real time.
                                                            • [claimed-docs] Stop fraudulent signups at the door.
                                                            • [claimed-docs] Want to fight multiple types of fraud at once? Learn how to add an abuse-specific risk score so that you can easily do so.
                                                            • [claimed-docs] Workflows enable you to make risk-based decisions in real time during key events. Follow this guide to create your own custom Workflow.
                                                            • [claimed-docs] Sift offers Workflows, a powerful rules automation platform, and Review Queues.
                                                            • [claimed-docs] Learn to set up custom Decisions, like Ban Account or Cancel Order, that are connected to real business actions in your backend.
                                                            Riskifiedpartialclaimed5/10

                                                            Riskified's Login API explicitly scores account-takeover attempts (allow/notify/challenge) alongside its core checkout fraud decisioning (decide/submit/advise) and automated chargeback handling, showing the same system spans multiple fraud surfaces beyond checkout. However, there is no documentation of fake-account-creation detection or promo/coupon abuse scoring as distinct managed surfaces. Missing for 10: explicit fake-account-creation protection, promo/policy abuse scoring, and independent confirmation these are unified in one decisioning system.

                                                            • [claimed-docs] API is triggered only for customer-initiated authentication requests, e.g., user tries to login to their account... `decision` field will be…
                                                            • [claimed-docs] `decision` field will be set as one of the following values: `allow`, `notify`, or `challenge`.
                                                            • [claimed-docs] Riskified offers fully automated chargeback gateway integrations for major gateways: Braintree, Stripe, Adyen, PayPal; this process automate…
                                                            • [claimed-docs] Notifies Riskified that a chargeback has been submitted for a specific order.
                                                            • [claimed-docs] The `/decide` endpoint is used to request that Riskified review an order for fraud after the customer has input their payment data and compl…
                                                            • [claimed-docs] For each order reviewed by advise we provide a synchronous decision if it is clear fraud... CVV/3DS recommendations can be provided... TRA/S…

                                                          Integrations

                                                          1. ops userThere are maintained integrations for my commerce stack — Shopify, Salesforce Commerce, BigCommerce, and the major PSPs — not just a raw API

                                                            weight 2 · round to Riskified
                                                            Siftnone0/10

                                                            Evidence shows only generic REST API, JS snippet, and mobile SDKs — no mention of maintained Shopify, Salesforce Commerce, BigCommerce, or PSP-specific integrations. Everything points to a raw API/SDK integration model, not prebuilt commerce-platform connectors.

                                                            • [claimed-docs] Sift easily integrates into your existing systems using modern REST APIs, Javascript snippet, and SDKs for iOS and Android.
                                                            • [claimed-docs] What actions your users are taking, usually key user lifecycle events (e.g., creating an account, placing an order, posting content to other…
                                                            • [claimed-docs] What actions your business is taking in response to users (e.g., approve an order, block and event due to fraud, cancel order due to chargeb…
                                                            Riskifiedpartialclaimed7/10

                                                            Riskified documents maintained platform integrations beyond raw API: a dedicated Shopify app with automated order actions (docs-11,12,21,22), a Salesforce Commerce Cloud/Agentforce Commerce fraud cartridge (docs-10), and automated Chargeback Gateway Integration with major PSPs (Braintree, Stripe, Adyen, PayPal) (docs-4,16,17). However, there is no mention of a BigCommerce integration, and the PSP integrations are scoped to chargeback data only rather than full checkout/decisioning flows. Missing for 10: explicit BigCommerce integration, evidence of maintained PSP integrations beyond chargebacks (e.g., payment/checkout-time connectors), independent confirmation of integration quality/maintenance cadence.

                                                            • [claimed-docs] Riskified offers fully automated chargeback gateway integrations for major gateways: Braintree, Stripe, Adyen, PayPal; this process automate…
                                                            • [claimed-docs] Agentforce Commerce (formerly Salesforce Commerce Cloud / SFCC) fraud protection cartridge provides a structured integration process tailore…
                                                            • [claimed-docs] Voids authorization on orders declined by Riskified. Enables automatic restocking of orders declined by Riskified. Captures funds for orders…
                                                            • [claimed-docs] If we have questions about shop flows or encounter data issues, we will reach out to you for clarification... Once data validation passes, y…
                                                            • [claimed-docs] The Chargeback Gateway Integration (CGI) framework enables seamless connectivity with leading payment gateways, including Adyen, Stripe, Bra…
                                                            • [claimed-docs] Once you have installed the Riskified app in your Shopify store, the integration process can begin. During this time, most of the “heavy lif…
                                                            • [claimed-docs] Voids authorization on orders declined by Riskified. Enables automatic restocking of orders declined by Riskified. Captures funds for orders…

                                                          Psp coverage

                                                          1. developerUse the product across whatever payment stack I run — multiple PSPs, gateways, and platforms — rather than being locked to one processor's rails

                                                            weight 3 · round to Riskified

                                                            Sift's architecture (generic REST Events/Decisions API, JS snippet, SDKs) is inherently processor-agnostic — it ingests events from any application regardless of which PSP or gateway processes the payment, rather than being tied to one processor's rails. However, there is no explicit documentation or case evidence naming specific PSPs/gateways/platforms it integrates with or confirming multi-processor deployments in practice. Missing for 10: explicit multi-PSP/gateway integration examples, named partner processors, or customer testimony confirming cross-stack usage.

                                                            • [claimed-docs] Sift easily integrates into your existing systems using modern REST APIs, Javascript snippet, and SDKs for iOS and Android.
                                                            • [claimed-docs] What actions your users are taking, usually key user lifecycle events (e.g., creating an account, placing an order, posting content to other…
                                                            • [claimed-docs] What actions your business is taking in response to users (e.g., approve an order, block and event due to fraud, cancel order due to chargeb…
                                                            • [claimed-docs] Custom events and fields describe user actions not captured by the supported events in our Events API.
                                                            Riskifiedpartialclaimed6/10

                                                            Riskified is gateway/platform-agnostic via its own API (/decide, /submit, /advise), with automated chargeback integrations naming specific gateways (Braintree, Stripe, Adyen, PayPal) and platform cartridges for Shopify and SFCC, indicating it can plug into multiple PSPs/platforms rather than lock a merchant into one processor. However, the evidence doesn't explicitly enumerate broad PSP/gateway compatibility beyond the four named chargeback gateways, nor discuss developer-facing flexibility across arbitrary payment stacks explicitly. missing for 10: a comprehensive list of supported PSPs/gateways beyond chargeback integrations, explicit statements about processor-agnostic architecture, and independent confirmation of multi-PSP interoperability.

                                                            • [claimed-docs] Riskified offers fully automated chargeback gateway integrations for major gateways: Braintree, Stripe, Adyen, PayPal; this process automate…
                                                            • [claimed-docs] The Chargeback Gateway Integration (CGI) framework enables seamless connectivity with leading payment gateways, including Adyen, Stripe, Bra…
                                                            • [claimed-docs] Agentforce Commerce (formerly Salesforce Commerce Cloud / SFCC) fraud protection cartridge provides a structured integration process tailore…
                                                            • [claimed-docs] Voids authorization on orders declined by Riskified. Enables automatic restocking of orders declined by Riskified. Captures funds for orders…
                                                            • [claimed-docs] Riskified supports different integration types:\n- **Pre-authorization Synchronous**: Review orders before payment authorization\n- **Post-a…

                                                          Model transparency — stories about model transparency in this arenaModel transparency

                                                          Stories about model transparency in this arena

                                                          Explainability

                                                          1. risk analystEvery score comes with its top risk factors — why this transaction looks risky — not just an opaque number

                                                            weight 3 · round drawn
                                                            Siftnone0/10

                                                            The evidence pack documents Sift's 0–100 risk score, Workflows, and Decisions APIs, but nowhere mentions score explanations, reason codes, or top contributing risk factors accompanying each score. Missing for 10: any documentation of explainability/reason-code output, feature-importance breakdowns, or examples of a score being paired with human-readable risk drivers.

                                                            • [claimed-docs] Sift represents this risk with a score between 0 and 100, where risky events have higher scores.
                                                            • [claimed-docs] Workflows enable you to make risk-based decisions in real time during key events. Follow this guide to create your own custom Workflow.
                                                            • [claimed-docs] Sift offers Workflows, a powerful rules automation platform, and Review Queues.
                                                            Riskifiednone0/10

                                                            Evidence describes decision outcomes (approve/decline/allow/notify/challenge) and notification mechanisms, but nothing indicates that decisions are accompanied by explanatory risk factors or reason codes for analysts. No mention of feature-level explanations, contributing signals, or reason breakdowns anywhere in the docs.

                                                            Model evaluation

                                                            1. finance leadMeasure the model itself — precision and recall on my traffic, shadow-mode trials of new models or rules before they take over decisions

                                                              weight 2 · round drawn
                                                              Siftnone0/10

                                                              Evidence covers scoring, workflows, decisions, and events APIs, but there is no mention of precision/recall metrics on the customer's own traffic, model performance measurement, or shadow-mode trialing of new models/rules before they go live. missing for 10: precision/recall measurement tooling, shadow-mode/challenger model testing, any model transparency reporting for finance/business stakeholders.

                                                                Riskifiednone0/10

                                                                The evidence pack only covers API endpoints, integrations, notifications, and chargeback automation — nothing about model performance metrics (precision/recall), model versioning, or shadow-mode testing of new models/rules before go-live is documented.

                                                                Openness — open source, data portability, and self-hosting storiesOpenness

                                                                Open source, data portability, and self-hosting stories

                                                                1. ai-native userDo everything through the API that I can do in the UI

                                                                  weight 2 · round to Sift

                                                                  Sift's docs show extensive REST APIs covering events, decisions, scoring, and even a Workflows API for automation, indicating broad programmatic access mirroring core UI functions (sift-docs-1,2,3,5,6,12). However, there's no explicit evidence that Review Queues or full workflow configuration UI actions are fully API-equivalent, and no independent confirmation of complete UI/API parity. missing for 10: explicit parity claim for Review Queues and workflow UI configuration, independent verification of full CRUD API coverage matching every console action.

                                                                  • [claimed-docs] Sift easily integrates into your existing systems using modern REST APIs, Javascript snippet, and SDKs for iOS and Android.
                                                                  • [claimed-docs] What actions your users are taking, usually key user lifecycle events (e.g., creating an account, placing an order, posting content to other…
                                                                  • [claimed-docs] What actions your business is taking in response to users (e.g., approve an order, block and event due to fraud, cancel order due to chargeb…
                                                                  • [claimed-docs] Sift represents this risk with a score between 0 and 100, where risky events have higher scores.
                                                                  • [claimed-docs] Workflows enable you to make risk-based decisions in real time during key events. Follow this guide to create your own custom Workflow.
                                                                  • [claimed-docs] Sift offers Workflows, a powerful rules automation platform, and Review Queues.
                                                                  Riskifiednone0/10

                                                                  The evidence pack documents Riskified's API endpoints (decide, submit, advise, chargeback, notifications) and SDKs, but never discusses the merchant dashboard/UI or compares what can be done there versus via API, so there's no evidence of feature parity between UI and API.

                                                                  Privacy posture — data-handling and privacy storiesPrivacy posture

                                                                  Data-handling and privacy stories

                                                                  1. ai-native userChoose where my data is stored (region/residency)

                                                                    weight 2 · round drawn
                                                                    Siftnone0/10

                                                                    No evidence in the pack mentions data residency, regional storage options, or geographic control over where Sift stores customer data; one community comment even notes hesitation about sending data to Sift without clarity on compliance handling. Missing for 10: any documentation of region selection, data residency options, or compliance certifications addressing storage location.

                                                                    • [community] Potential customer notes hesitation: reservations about sending personal user data to an aggregator that would then require legal review for…
                                                                    Riskifiednone0/10

                                                                    No evidence in the pack mentions data residency, region selection, or storage location options for merchant/customer data; documentation covers API endpoints, integrations, and notifications only.

                                                                    • ai-native userControl data retention and deletion

                                                                      weight 2 · round drawn
                                                                      Siftnone0/10

                                                                      Sift is a fraud-detection API/platform, and the evidence pack contains no documentation of data retention controls, deletion APIs, or configurable data lifecycle policies for users. One community comment (sift-comm-3) even flags unresolved privacy/legal review concerns about sending personal data to Sift, but this is not concrete evidence of a retention/deletion mechanism either way. missing for 10: any documentation of data retention settings, a deletion/right-to-be-forgotten API, or data lifecycle/export controls.

                                                                      • [community] Potential customer notes hesitation: reservations about sending personal user data to an aggregator that would then require legal review for…
                                                                      Riskifiednone0/10

                                                                      No evidence pack items address data retention policies, deletion mechanisms, or user/customer data control tools; the docs focus entirely on fraud-decision APIs and integrations with no privacy-posture or data lifecycle controls mentioned.

                                                                      Residency compliance — stories about residency compliance in this arenaResidency compliance

                                                                      Stories about residency compliance in this arena

                                                                      Residency

                                                                      1. ops userControl where fraud data lives and how long it's kept — regional residency options and retention controls that survive a privacy review

                                                                        weight 2 · round drawn
                                                                        Siftnone0/10

                                                                        No evidence pack items discuss regional data residency, data hosting locations, retention periods, or compliance/privacy review controls; one comment even notes a prospective customer's hesitation about privacy/legal review with no resolution shown. Missing for 10: any documentation of regional hosting/data residency options, retention/configurable deletion policies, or compliance certifications addressing privacy review.

                                                                        • [community] Potential customer notes hesitation: reservations about sending personal user data to an aggregator that would then require legal review for…
                                                                        Riskifiednone0/10

                                                                        No evidence in the pack addresses data residency options, regional data storage, or retention/deletion controls; documentation covers API flows, integrations, and authentication only.

                                                                        Sca

                                                                        1. developerEuropean traffic is routed intelligently through SCA — 3DS triggered when required or risky, exemptions requested when safe — to protect both compliance and conversion

                                                                          weight 2 · round to Riskified
                                                                          Siftnone0/10

                                                                          The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                                                                            Riskifiedfullclaimed7/10

                                                                            Riskified's /advise endpoint explicitly returns CVV/3DS recommendations and adds TRA/SCA exemption recommendations for regulated markets, directly matching the story of intelligently triggering 3DS or requesting exemptions per order. This is first-party documentation with no independent corroboration of real-world accuracy or European-specific behavior. Missing for 10: independent/hands-on validation of SCA exemption success rates, and explicit detail on how 'European traffic' specifically is distinguished/routed versus other regions.

                                                                            • [claimed-docs] For each order reviewed by advise we provide a synchronous decision if it is clear fraud... CVV/3DS recommendations can be provided... TRA/S…
                                                                            • [claimed-docs] For each order reviewed by advise we provide a synchronous decision if it is clear fraud... In addition, CVV/3DS recommendations can be prov…

                                                                          Review queues — stories about review queues in this arenaReview queues

                                                                          Stories about review queues in this arena

                                                                          Case review

                                                                          1. risk analystFlagged transactions land in a review queue that shows the full context — customer history, signals, similar cases — so I can decide quickly and consistently

                                                                            weight 3 · round to Sift

                                                                            Sift documents Review Queues as a product feature alongside Workflows, and community evidence confirms human analysts do review flagged users to make final decisions, supporting the general workflow. However, there is no evidence detailing the review queue UI showing customer history, similar cases, or signal context in one view. missing for 10: documentation/screenshots of review queue UI showing customer history and similar cases, evidence of consolidated signal context, independent hands-on confirmation of queue usability.

                                                                            • [claimed-docs] Sift offers Workflows, a powerful rules automation platform, and Review Queues.
                                                                            • [community] Sift Science founder on false positives: 'Most of our customers review each user we flag, and have a human make a final go/no-go decision ab…
                                                                            Riskifiednone0/10

                                                                            Evidence covers Riskified's API endpoints (/decide, /submit, /advise), notifications, chargeback automation, and Beacon data collection, but nothing describes a human review-queue UI showing analyst context, customer history, or similar cases for manual decisioning — Riskified's documented flow is automated/API-driven decisioning, not analyst-facing case review tooling.

                                                                            Feedback loop

                                                                            1. risk analystMy review decisions and confirmed fraud outcomes feed back into the model and rules, so the system learns from every case we work

                                                                              weight 2 · round to Sift

                                                                              Sift's Decisions API explicitly captures business actions like 'block due to fraud' or 'cancel due to chargeback' and feeds them back to Sift, and docs state Sift 'gets smarter the more data it has,' supporting a feedback loop from confirmed outcomes into the model. Review Queues and Workflows are documented as connected to decisions, and a founder note confirms customers commonly have analysts make final go/no-go calls that presumably feed Decisions API. Missing for 10: explicit documentation that individual analyst review-queue verdicts (not just automated decisions) are looped back per-case to retrain the model, and any detail on how confirmed fraud outcomes update rules/workflows specifically.

                                                                              • [claimed-docs] What actions your business is taking in response to users (e.g., approve an order, block and event due to fraud, cancel order due to chargeb…
                                                                              • [claimed-docs] Because Sift gets smarter the more data it has about your business, you can jump start your integration by backfilling a few months worth of…
                                                                              • [claimed-docs] Sift offers Workflows, a powerful rules automation platform, and Review Queues.
                                                                              • [community] Sift Science founder on false positives: 'Most of our customers review each user we flag, and have a human make a final go/no-go decision ab…
                                                                              Riskifiednone0/10

                                                                              The evidence describes automated decisioning APIs (/decide, /submit, /advise), chargeback notification integrations, and onboarding model calibration by Riskified's own analytics team, but nothing describes an analyst-facing review queue where human review decisions or confirmed fraud outcomes are captured and fed back into the model/rules on an ongoing basis. Missing for 10: evidence of an analyst review UI, a mechanism for analysts to submit manual review/fraud confirmations, and documentation that such decisions retrain or update the fraud model/rules.

                                                                              • [claimed-docs] If we have questions about shop flows or encounter data issues, we will reach out to you for clarification... Once data validation passes, y…
                                                                              • [claimed-docs] Notifies Riskified that a chargeback has been submitted for a specific order.
                                                                              • [claimed-docs] Riskified offers fully automated chargeback gateway integrations for major gateways: Braintree, Stripe, Adyen, PayPal; this process automate…

                                                                            Team workflows

                                                                            1. ops userReview work is a team workflow — assignment, escalation, SLAs, and a decision audit trail that shows who approved what and why

                                                                              weight 2 · round to Sift

                                                                              Sift documents Review Queues and Workflows for human review, plus a Decisions API that logs business actions like approve/ban/cancel tied to real events, which supports a basic audit trail; a founder comment also confirms a human-in-the-loop review pattern ('have a human make a final go/no-go decision'). However, there's no evidence of explicit team-workflow features like assignment routing, escalation paths, or SLA tracking. missing for 10: assignment/routing mechanics, escalation workflows, SLA timers/tracking, explicit 'who approved what and why' UI/reporting beyond raw decision logs.

                                                                              • [claimed-docs] Sift offers Workflows, a powerful rules automation platform, and Review Queues.
                                                                              • [claimed-docs] What actions your business is taking in response to users (e.g., approve an order, block and event due to fraud, cancel order due to chargeb…
                                                                              • [claimed-docs] Learn to set up custom Decisions, like Ban Account or Cancel Order, that are connected to real business actions in your backend.
                                                                              • [community] Sift Science founder on false positives: 'Most of our customers review each user we flag, and have a human make a final go/no-go decision ab…
                                                                              Riskifiednone0/10

                                                                              Evidence covers API decisioning, notifications, chargeback automation, and integrations, but nothing describes a human ops review workflow with case assignment, escalation, SLAs, or an audit trail of who approved what and why.

                                                                              Risk scoring — stories about risk scoring in this arenaRisk scoring

                                                                              Stories about risk scoring in this arena

                                                                              Custom signals

                                                                              1. developerFeed the model my own signals — device fingerprints, behavioral data, custom metadata — so scoring reflects my business, not just network defaults

                                                                                weight 2 · round to Sift

                                                                                Sift's docs clearly support ingesting custom events, custom fields, session/device signals, and business action data via Events/Decisions APIs, and scoring incorporates this custom data plus historical backfill to tailor risk to the business rather than generic network defaults. Missing for 10: independent hands-on verification of custom-field scoring impact and explicit device-fingerprint API documentation beyond general SDK mentions.

                                                                                • [claimed-docs] What actions your users are taking, usually key user lifecycle events (e.g., creating an account, placing an order, posting content to other…
                                                                                • [claimed-docs] What actions your business is taking in response to users (e.g., approve an order, block and event due to fraud, cancel order due to chargeb…
                                                                                • [claimed-docs] Because Sift gets smarter the more data it has about your business, you can jump start your integration by backfilling a few months worth of…
                                                                                • [claimed-docs] Custom events and fields describe user actions not captured by the supported events in our Events API.
                                                                                • [claimed-docs] When users are anonymous for parts or all of their experience on your site, we provide a special `session_id` field in the JS Snippet and Ev…
                                                                                • [claimed-docs] Sift represents this risk with a score between 0 and 100, where risky events have higher scores.
                                                                                Riskifiednone0/10

                                                                                Riskified's API endpoints (/decide, /submit, /advise) and Beacon.js collect a fixed, vendor-defined set of order/behavioral data required for fraud analysis, and model calibration is explicitly handled by Riskified's own analytics team (docs-12), not the developer. There is no evidence of an API or schema allowing developers to inject custom device fingerprints, arbitrary behavioral signals, or custom metadata fields into the scoring model to tailor it to their own business logic.

                                                                                • [claimed-docs] Riskfied's Beacon is a JavaScript snippet that merchants embed on their website. It collects fundamental data required to decide on the legi…
                                                                                • [claimed-docs] If we have questions about shop flows or encounter data issues, we will reach out to you for clarification... Once data validation passes, y…
                                                                                • [claimed-docs] The `/submit` endpoint sends transaction data to Riskified after the gateway authorizes the transaction for fraud analysis... the fraud deci…
                                                                                • [claimed-docs] For each order reviewed by advise we provide a synchronous decision if it is clear fraud... CVV/3DS recommendations can be provided... TRA/S…

                                                                              Network effects

                                                                              1. founderScoring benefits from a cross-merchant network — a card or identity seen across thousands of other businesses informs the risk decision on mine

                                                                                weight 2 · round drawn
                                                                                Siftnone0/10

                                                                                The evidence pack describes Sift's own ML scoring, event/decision APIs, and workflows, but nowhere claims that risk signals (e.g., a card or identity) are shared or aggregated across Sift's merchant customer base to inform another business's score. sift-docs-4 only references a business's own historical data improving its own model, not cross-merchant network effects.

                                                                                  Riskifiednone0/10

                                                                                  The evidence pack only documents Riskified's API endpoints, SDKs, and integration flows (decide, submit, advise, chargeback, notifications, Beacon, login) — none of it describes a cross-merchant data network, shared fraud signals across Riskified's merchant base, or how identity/card history from other businesses informs a given merchant's score. Without any documentation of the network-effect mechanism, this axis has no supporting evidence.

                                                                                  Score actions

                                                                                  1. ops userMap score ranges to actions — allow, review, block, step-up 3DS — and tune thresholds to my own risk appetite instead of a fixed cutoff

                                                                                    weight 2 · round to Sift

                                                                                    Sift's docs describe Workflows as a rules automation platform for real-time risk-based decisions, with custom Decisions (e.g., Ban Account, Cancel Order) tied to score ranges (0-100), and Review Queues for human review — directly supporting configurable score-to-action mapping and threshold tuning. However, no evidence explicitly mentions 3DS step-up as an action type, and an older founder comment (sift-comm-8) claims 'no rules' which is in tension with the current Workflows rules-engine framing, though this appears to reflect product evolution rather than a live contradiction. missing for 10: explicit 3DS/step-up action documentation, independent hands-on confirmation of threshold customization in practice.

                                                                                    • [claimed-docs] Sift represents this risk with a score between 0 and 100, where risky events have higher scores.
                                                                                    • [claimed-docs] Workflows enable you to make risk-based decisions in real time during key events. Follow this guide to create your own custom Workflow.
                                                                                    • [claimed-docs] Learn to set up custom Decisions, like Ban Account or Cancel Order, that are connected to real business actions in your backend.
                                                                                    • [claimed-docs] Sift offers Workflows, a powerful rules automation platform, and Review Queues.
                                                                                    • [community] Sift Science founder on false positives: 'Most of our customers review each user we flag, and have a human make a final go/no-go decision ab…
                                                                                    • [community] CEO explains no-rules ML approach: 'we do not have any rules in our product... rules are rather easy for fraudsters to circumvent, and they …
                                                                                    Riskifiednone0/10

                                                                                    Riskified's docs describe its endpoints (/decide, /submit, /advise, login) returning pre-computed decisions like allow/notify/challenge or approve/decline, but there is no evidence that ops users can view underlying risk scores or configure/tune score-to-action thresholds themselves — decisioning appears to be Riskified's managed model rather than a merchant-tunable scorecard.

                                                                                    • [claimed-docs] The `/decide` endpoint is used to request that Riskified review an order for fraud after the customer has input their payment data and compl…
                                                                                    • [claimed-docs] For each order reviewed by advise we provide a synchronous decision if it is clear fraud... CVV/3DS recommendations can be provided... TRA/S…
                                                                                    • [claimed-docs] API is triggered only for customer-initiated authentication requests, e.g., user tries to login to their account... `decision` field will be…
                                                                                    • [claimed-docs] `decision` field will be set as one of the following values: `allow`, `notify`, or `challenge`.

                                                                                  Scoring api

                                                                                  1. developerGet a machine-learning risk score for a transaction in real time — synchronously, before authorization completes — through a documented API

                                                                                    weight 3 · round to Riskified

                                                                                    Sift's documented Score API returns a 0-100 ML risk score via REST, and Workflows enable real-time risk-based decisions during key events, supporting synchronous scoring before a decision. However, the evidence doesn't explicitly confirm the Score API is called synchronously pre-authorization (vs. async/webhook-based scoring), and community feedback notes many customers use human review queues rather than pure real-time automated decisions. Missing for 10: explicit documentation of synchronous call/response latency guarantees for pre-authorization use, and independent confirmation of real-time performance under transaction-blocking scenarios.

                                                                                    • [claimed-docs] Sift represents this risk with a score between 0 and 100, where risky events have higher scores.
                                                                                    • [claimed-docs] Workflows enable you to make risk-based decisions in real time during key events. Follow this guide to create your own custom Workflow.
                                                                                    • [claimed-docs] Block unauthorized access in real time.
                                                                                    • [community] Sift Science founder on false positives: 'Most of our customers review each user we flag, and have a human make a final go/no-go decision ab…
                                                                                    Riskifiedfullprobed7/10

                                                                                    Riskified's documented `/decide` endpoint explicitly returns a synchronous fraud decision before payment authorization completes, matching the real-time pre-auth workflow described in the story, and Riskified's own docs classify this as 'Pre-authorization Synchronous' integration. However, the docs describe a categorical decision (approve/decline) rather than an explicit numeric ML risk score, and no OpenAPI/swagger spec exists (probe returned 404s) to confirm formal API schema. missing for 10: explicit numeric risk-score field documentation, machine-readable OpenAPI spec, independent/hands-on corroboration of latency/real-time behavior.

                                                                                    • [claimed-docs] The `/decide` endpoint is used to request that Riskified review an order for fraud after the customer has input their payment data and compl…
                                                                                    • [claimed-docs] The `/decide` endpoint is used to request that Riskified review an order for fraud after the customer has input their payment data and compl…
                                                                                    • [claimed-docs] Riskified supports different integration types:\n- **Pre-authorization Synchronous**: Review orders before payment authorization\n- **Post-a…
                                                                                    • [probe] PROBE openapi: all candidate paths 404 (https://developers.riskified.com/openapi.json, https://developers.riskified.com/swagger.json, https:…

                                                                                  Rules engine — stories about rules engine in this arenaRules engine

                                                                                  Stories about rules engine in this arena

                                                                                  Backtesting

                                                                                  1. risk analystBacktest a rule against my historical traffic before deploying it, seeing exactly what it would have blocked, flagged, and cost

                                                                                    weight 2 · round drawn
                                                                                    Siftnone0/10

                                                                                    The evidence describes Workflows as a rules automation platform and mentions real-time decisioning, but nothing in the pack describes a backtest/simulation capability against historical traffic showing what a rule would have blocked/flagged/cost.

                                                                                    • [claimed-docs] Sift offers Workflows, a powerful rules automation platform, and Review Queues.
                                                                                    • [claimed-docs] Workflows enable you to make risk-based decisions in real time during key events. Follow this guide to create your own custom Workflow.
                                                                                    Riskifiednone0/10

                                                                                    Evidence covers Riskified's fraud-decision APIs, notifications, chargeback integrations, and merchant integration flows, but nothing describes a rule backtesting capability against historical traffic showing what would have been blocked/flagged/cost before deployment.

                                                                                    Lists

                                                                                    1. ops userMaintain allow and block lists — emails, cards, devices, IPs — and velocity limits, managed through the dashboard and programmatically

                                                                                      weight 2 · round to Sift

                                                                                      Docs describe a general 'Workflows' rules automation platform and Review Queues, but there's no explicit mention of dedicated allow/block lists for emails, cards, devices, or IPs, nor velocity limit configuration in the dashboard or API. Compounding this, a Sift co-founder is quoted stating 'we do not have any rules in our product' as a core design philosophy, directly conflicting with the rules-engine framing implied by the Workflows docs. missing for 10: explicit allow/block list management (emails, cards, devices, IPs), velocity limit configuration, dashboard UI evidence, and resolution of the rules-vs-no-rules contradiction.

                                                                                      • [claimed-docs] Sift offers Workflows, a powerful rules automation platform, and Review Queues.
                                                                                      • [claimed-docs] Workflows enable you to make risk-based decisions in real time during key events. Follow this guide to create your own custom Workflow.
                                                                                      • [community] CEO explains no-rules ML approach: 'we do not have any rules in our product... rules are rather easy for fraudsters to circumvent, and they …
                                                                                      • [community] Critical take: 'The biggest problem with ML is that it takes time for it to react to new fraud patterns/schemes. While rules engines have li…
                                                                                      Riskifiednone0/10

                                                                                      Evidence covers order decisioning APIs, notifications, chargebacks, and integrations, but nothing describes allow/block lists for emails, cards, devices, or IPs, nor velocity limit configuration via dashboard or API.

                                                                                      Rule authoring

                                                                                      1. risk analystAuthor custom rules that combine model scores, velocity counters, list matches, and transaction attributes into allow, block, or review decisions

                                                                                        weight 3 · round to Sift

                                                                                        Docs describe Workflows as a 'powerful rules automation platform' for real-time decisioning (allow/block/review) using scores and custom logic (sift-docs-6, sift-docs-7, sift-docs-12), suggesting the requested rule authoring capability. However, a Sift co-founder is on record stating 'we do not have any rules in our product' and that rules are easy to circumvent, directly contradicting the existence of a rules engine (sift-comm-8), and no evidence details velocity counters or list-match integration into rule logic. missing for 10: explicit documentation of velocity counters, list matching, and multi-attribute rule composition within Workflows; independent verification reconciling the rules-vs-no-rules discrepancy.

                                                                                        • [claimed-docs] Workflows enable you to make risk-based decisions in real time during key events. Follow this guide to create your own custom Workflow.
                                                                                        • [claimed-docs] Learn to set up custom Decisions, like Ban Account or Cancel Order, that are connected to real business actions in your backend.
                                                                                        • [claimed-docs] Sift offers Workflows, a powerful rules automation platform, and Review Queues.
                                                                                        • [community] CEO explains no-rules ML approach: 'we do not have any rules in our product... rules are rather easy for fraudsters to circumvent, and they …
                                                                                        Riskifiednone0/10

                                                                                        Riskified's docs describe API endpoints (decide/submit/advise), notifications, and integrations, but there is no evidence of a user-facing custom rules authoring interface where a risk analyst can combine model scores, velocity counters, list matches, and transaction attributes into allow/block/review logic. The decisions described (allow/notify/challenge, approve/decline) are produced by Riskified's own models, not by analyst-authored rules. Missing for 10: any rule-builder UI, rule syntax/DSL, ability to combine velocity counters/list matches/model scores into custom logic, or analyst-facing rule management docs.

                                                                                        • [claimed-docs] The `/decide` endpoint is used to request that Riskified review an order for fraud after the customer has input their payment data and compl…
                                                                                        • [claimed-docs] For each order reviewed by advise we provide a synchronous decision if it is clear fraud... CVV/3DS recommendations can be provided... TRA/S…
                                                                                        • [claimed-docs] API is triggered only for customer-initiated authentication requests, e.g., user tries to login to their account... `decision` field will be…
                                                                                        • [claimed-docs] `decision` field will be set as one of the following values: `allow`, `notify`, or `challenge`.

                                                                                      Not comparable on these axes

                                                                                      1. ai-native userPlug MCP servers into this product so it can use their tools

                                                                                        weight 3 · not comparable
                                                                                        Siftn/a

                                                                                        Sift is a fraud-detection/risk-scoring platform, not an AI agent or assistant; the story asks whether the product can plug in MCP servers to consume external tools, which is a client-agent capability not applicable to this kind of product.

                                                                                          Riskifiedn/a

                                                                                          Riskified is a fraud-detection/e-commerce risk platform, not an AI agent or agent-enabling framework; plugging MCP servers into it so it can use external tools is a category mismatch for this product type, and no evidence suggests otherwise.

                                                                                          • ai-native userIssue scoped/least-privilege API credentials for an agent

                                                                                            weight 2 · not comparable
                                                                                            Siftn/a

                                                                                            Sift is a fraud-detection/risk-scoring platform, not an agent-facing product issuing scoped API credentials for AI agents; no evidence pack items address credential scoping or agent-specific access control, and this is a category mismatch rather than a gap in an applicable capability.

                                                                                              Riskifiedn/a

                                                                                              Riskified is a fraud-decision API/service for merchants, not an agent-facing platform; there is no concept of issuing scoped credentials for an AI agent to act on a user's behalf. Authentication uses a single HMAC token per merchant integration, not agent-scoped credentialing — this is a category mismatch, not a missing feature.

                                                                                              • ai-native userSchedule recurring jobs or workflows

                                                                                                weight 2 · not comparable
                                                                                                Siftn/a

                                                                                                Sift is a fraud-detection/risk-scoring platform, not a workflow/job scheduling or automation orchestration tool; scheduling recurring jobs is outside its product category and not addressed by any evidence (Workflows here refer to real-time rules-based decisioning, not recurring job scheduling).

                                                                                                  Riskifiedn/a

                                                                                                  Riskified is a fraud-decisioning API/service, not an automation platform or agent framework; scheduling recurring jobs/workflows is not a relevant capability for this product category — it operates via real-time synchronous/asynchronous fraud decisions triggered by order events, not user-defined recurring schedules.

                                                                                                  • ai-native userVersion, review, and roll back my automations

                                                                                                    weight 1 · not comparable
                                                                                                    Siftn/a

                                                                                                    Sift is a fraud-detection/risk-scoring platform, not an automation/workflow builder with version control for user-created automations; the evidence pack shows Workflows and Decisions APIs but no versioning, review, or rollback of automations. This is a category mismatch rather than a missing feature.

                                                                                                      Riskifiedn/a

                                                                                                      Riskified is a fraud-decisioning API/service, not an automation-authoring tool with versionable workflows; there is no concept of user-built 'automations' to version, review, or roll back in this product category.

                                                                                                      • ai-native userExport all of my data in open formats and leave

                                                                                                        weight 3 · not comparable
                                                                                                        Siftnone0/10

                                                                                                        Sift is a fraud-detection API platform; evidence covers sending events/data into Sift via REST API, scoring, workflows, but there is no mention of exporting or bulk-downloading customer data out of Sift in open formats, nor any data-portability/export feature. missing for 10: any documented data export/download capability, open-format export (CSV/JSON dumps), or account data portability tooling.

                                                                                                          Riskifiedn/a

                                                                                                          Riskified is a fraud-decision API/service, not a data-storage or content-authoring product where a user's own data/documents need export in open formats; there's no concept of user-owned data corpus to 'export and leave' — this axis is a category error for this product type.

                                                                                                          • ai-native userRead the product's source under an open license

                                                                                                            weight 2 · not comparable
                                                                                                            Siftn/a

                                                                                                            Sift is a proprietary commercial fraud-detection SaaS product; there is no indication of an open-source license or public source code. This is a category error for the axis — closed commercial SaaS products aren't expected to publish source under open license, so it's inapplicable rather than a failure.

                                                                                                              Riskifiedn/a

                                                                                                              Riskified is a closed, proprietary fraud-detection SaaS product; there is no source code to read and no open-license claim anywhere in the evidence. Reading source under an open license is a category error for this type of hosted commercial service.

                                                                                                              • ai-native userSelf-host the core product

                                                                                                                weight 3 · not comparable
                                                                                                                Siftn/a

                                                                                                                Sift is a cloud-based fraud detection SaaS delivered via REST APIs and hosted risk scoring; self-hosting the core product is not a fair axis for this kind of managed service, and no evidence suggests otherwise.

                                                                                                                  Riskifiedn/a

                                                                                                                  Riskified is a SaaS fraud-decisioning platform delivered via API/notifications with backend model calibration performed by Riskified's own analytics team; self-hosting the core product is not a coherent axis for this category of service.

                                                                                                                  • ai-native userPrevent my data from being used to train AI models

                                                                                                                    weight 3 · not comparable
                                                                                                                    Siftnone0/10

                                                                                                                    Sift is a fraud-detection platform whose business model relies on ingesting user behavioral data to train its ML risk models; no evidence pack item mentions any opt-out, data-training-exclusion policy, or AI-training-specific privacy controls for end users. Missing for 10: any documentation of an opt-out mechanism, training-data exclusion policy, or user-facing privacy control preventing model training use.

                                                                                                                      Riskifiedn/a

                                                                                                                      Riskified is a fraud-prevention/e-commerce risk API, not an AI model or AI assistant product; the story about preventing personal data being used for AI model training is not a relevant axis for this kind of product.

                                                                                                                      • ai-native userOpt out of telemetry and usage tracking

                                                                                                                        weight 2 · not comparable
                                                                                                                        Siftn/a

                                                                                                                        Sift is a backend fraud-detection/risk-scoring API whose core function is ingesting customer/user behavioral data for fraud analysis, not a developer tool or AI agent with its own usage-telemetry settings that an 'AI-native user' would opt out of. The evidence pack contains no mention of telemetry collection about API/dashboard usage, making this axis a category mismatch rather than an unmet capability.

                                                                                                                          Riskifiedn/a

                                                                                                                          Riskified is a fraud-prevention/risk API platform, not an AI developer tool or agent with telemetry collected from AI-native usage; opt-out of telemetry/usage tracking is not a relevant axis for this product category.