Overview

Use Local Graph in your RiskOS™ account to uncover fraud patterns in real time as they form within your ecosystem and stop them before they scale.

Local Graph is a client-specific graph that links users and identity elements, such as devices, emails, phone numbers, and IP addresses, through the events they appear in together. Every user and identity element in Local Graph carries its complete activity, along with real-time risk signals derived from that activity. For example, a device carries a count of rejected applications from it in the last hour, and a user carries a flag when a new device is observed for them.


Explore features


How it works

Local Graph updates in real time as events run through your RiskOS™ workflows. An event, or evaluation, includes all the data collected during the workflow run: what you send in the request, plus what the workflow adds, such as enrichment results and computed fields. Local Graph processes each event in four steps:

  1. Identify entities

    When an event runs through a workflow, Local Graph identifies the entities in its data. An entity is a user or identity element, such as a device, email, phone number, IP address, or national ID. Each RiskOS™ use case comes with standard entities configured and can also include custom ones. Only events that run through a RiskOS™ workflow are added, and each client's graph is built only from its own events.

  2. Match or create nodes

    Each entity is a node in the graph. Local Graph checks whether each entity in the event already has a node. Entities seen before keep their existing node, and new entities get a new one.

  3. Set up connections

    Local Graph connects every entity that appeared in the event. The event itself is the connection: entities are linked because they appeared together. Over time, each entity becomes connected to every entity it has appeared with (its linked entities), such as a device to every email and phone number used on it.

  4. Update activity and compute signals

    Local Graph adds the event to the activity of every entity in it, then updates their signals. Because this happens with every event, each new event is evaluated against up-to-date activity and signals.


What each entity carries

For every entity, Local Graph keeps the following, updated in real time:

What it holdsExample
ActivityEvery event the entity has appeared in, with each event's key detailsEvery onboarding application and login from a device
Linked entitiesEvery entity it has appeared with in an eventThe emails and phone numbers used on a device
SignalsValues calculated from its activity over time windowsOnboarding applications from the device in the last hour

Activity and linked entities give investigators the full context on an entity. Signals let workflow rules use that context in real time.


Example: a new application from a device seen before

Device D-1042 has already been used for two onboarding applications in the last hour, with the emails [email protected] and [email protected]. A new application now comes in from the same device, with the email [email protected] and IP address 203.0.113.24.

  1. Identify entities: Local Graph identifies three entities in the new application: the email, the device, and the IP address.
  2. Match or create nodes: The device has been seen before, so it keeps its existing node. The email and IP address are new, so each gets a new node.
  3. Set up connections: Local Graph sets up a connection between each pair of the three entities, three in all. The device gets two new connections, to the email and the IP address. The third connects the email and the IP address.
  4. Update activity and compute signals: The application is added to each entity's activity, and their signals update. The device's applications in the last hour go from 2 to 3, and so do its unique emails. A workflow rule can flag this pattern.

Did this page help you?