Fraud review
The optional fraud section applies explainable heuristic signals when a referral is created. It is disabled by default. These signals indicate review priority; they do not prove alternate accounts. No external VPN/proxy provider is contacted and no raw address is stored.
Signals and weights are SAME_IP (60), MUTUAL_REFERRAL (70), RECENT_FIRST_JOIN (20) and LOW_PLAYTIME (20), capped at 100. Bands are low 0-29, medium 30-59 and high 60-100. The configurable review threshold decides whether a referral is held. First-join age means age since this ReferralTrack installation first observed the player; Bukkit playtime is not AFK-adjusted. These limits are shown plainly so staff can interpret each result.
Use /referraltrack review list [page] and /referraltrack review show <player>. A held referral cannot validate or release rewards. A staff decision requires the explicit confirmation word and a printable reason:
/referraltrack review approve <player> confirm <reason>
/referraltrack review reject <player> confirm <reason>
After approval, review revoke ... confirm <reason> excludes the referral and cancels queued, unclaimed welcome rewards. review rollback ... confirm <reason> additionally removes the attribution record. Already delivered money or commands are reported for manual recovery because arbitrary commands have no safe universal inverse. Referral milestone side effects also require manual review.
Every system assessment, staff decision and later referral removal writes an append-only audit row with actor, action, reason and timestamp. Rejected validation remains rejected. A second decision is refused. Staff commands require referraltrack.admin.