The marker families
| Family | Signals | Detection note |
|---|---|---|
| Escalation | Stakes, deposit frequency, session length trending up against the player's baseline | Trend detection — the baseline view catches what thresholds miss |
| Chasing | Deposits shortly after losses; cancelled withdrawals returning to play; declined payments retried persistently | Sequence patterns; the withdrawal-reversal marker also binds the payout flow |
| Loss of control | Night-time concentration, session outliers, multi-product intensity on one wallet | Cross-product aggregation is mandatory — per-product views miss the sum |
| Self-signals | Limit-setting, cool-off use, help-content visits, statements to support | The strongest family and the most under-wired; support routing is a marker source, not a courtesy |
| Financial context | Affordability triggers per regime; source-of-funds interactions | Shared surface with AML — routed to both, conflated with neither, per the flow design |
Parameters are configuration; the engine is not
Thresholds, windows and severities differ per market (regulatory expectations differ) and per product (cycle speeds differ) — rows in the configuration matrix with owners and effective dates. The detection engine itself is one mechanism: markers computed on the shared event stream, at the wallet level, with protection events first-class in the schema. Operators who bolt detection onto a single product's data rediscover the cross-product gap at review time.
Ranking without veto
Where a model layers on top (the AI monitoring rules apply in full): the model orders the queue and surfaces combinations, tuned toward sensitivity because the error costs are asymmetric — an unnecessary check-in costs minutes, a missed case costs a person. The structural rule worth repeating everywhere: a fired rule marker is never downgraded by a model score, and marker outputs flow into protection only — never into marketing eligibility, value scoring or LTV optimisation.
From marker to case, mechanically
- Severity maps to SLA. The mapping is written: which marker classes demand same-session response, same-day, or next-review.
- The case carries its evidence. The signals that fired, the player's baseline, prior interventions and outcomes — assembled for the handler, not hunted by them.
- No-action is a decision. Closing without intervention records a rationale and a review date. The trail's completeness — every marker resolved to an action or a reasoned no-action — is the number the audit checks first.
- Outcomes feed tuning. Marker classes that never lead to real cases get reviewed like dead alert rules; classes that keep appearing in escalations get their thresholds tightened. The queue disciplines from every other domain apply unchanged.
Continue reading: The interventions playbook — what the case handler does next. RG operations — the function around the queue.