BI · reconciliation 2026

The first reconciled fraud view on a brand-new AWS region

An org-wide fraud-and-revenue dashboard for AWS's European Sovereign Cloud, whose credibility came from correcting two of its own headline numbers.

Business Analyst, AWS Payments & Fraud Prevention

Impact

Delivered the first unified, reconciled fraud view on a brand-new AWS region, corrected a flattering ~98% automation headline down to an honest ~12 to 13%, drove a revenue undercount to under 1%, and made flag-to-shutdown speed measurable at ~1 day on average.

Reported model-automation rate -87%
Claimed (lazy attribution)
~98%
Measured (enforcement path modelled)
~12 to 13%
Automated rules disambiguated from analyst bulk actions. Accuracy over a flattering headline.
What the unified view put on one fact table 5/5 signals
  • Registration outcomes
  • C-score trajectories
  • Enforcement attribution
  • Preventable compute
  • Sleeper signals
Five surfaces on every ESC account since launch, all reading from one canonical account-level fact table and ~40 parameterized, QuickSight-portable SQL files. Enforcement attribution is the tab that produced the automation correction.

Flag-to-shutdown speed became measurable here too: about a day on average, with only a tiny number of reversals. Before the unified view there was no figure at all, not a slower one.

Revenue reconciliation gap
under a percent
Mirror-versus-native undercount driven down to a fraction of a percent.
Context

The European Sovereign Cloud was a brand-new AWS region with no unified view of the fraud landing on it. Leadership was deciding from fragments. The data also lived across an ESC-native surface and a mirror that did not reconcile one-to-one, which made shipping numbers that looked right and quietly did not add up the easiest thing to do.

What I did
  • I designed, built and announced org-wide a multi-tab analytics dashboard covering every ESC account since launch: registration outcomes, c-score trajectories, enforcement attribution, preventable compute and sleeper signals.
  • I built it on a canonical account-level fact table and ~40 parameterized SQL files that stay portable to QuickSight.
  • I replaced a misleading ~98% 'model automation' figure with an honest ~12 to 13% auto-shutdown rate, after modelling the enforcement path properly and disambiguating automated rules from analyst bulk actions.
  • I drove a mirror-versus-native reconciliation that pushed a revenue undercount down to a fraction of a percent.
  • I said in the launch message which of the dashboard's own numbers to trust: trends and rates fully reconciled, a few absolute dollar totals still rough pending Data Engineering fixes.
Outcome

The account-level fact table underneath became what the team's QuickSight binds to, so new tabs and reports inherit the reconciliation instead of re-deriving it. Rough absolute totals ship labelled as pending Data Engineering fixes rather than presented as fact, which is why the view survived being checked.

Without this work

Leadership keeps deciding on fragments. The inflated 98% figure keeps misrepresenting how enforcement actually works, the undercount quietly understates the region, and rough dollar totals read as fact because nothing labels them.

The full story

The dashboard was the easy half. What made it trusted was two honest corrections.

The first number arrived already believed. Roughly 98% of shutdowns were reported as model-automated. That was an artifact of lazy attribution rather than a measurement, and nobody had re-derived it. Checking it meant modelling the enforcement path, then separating automated rules from analyst bulk actions, which is the distinction the original figure had collapsed. The real auto-shutdown rate came out at about 12 to 13%. I shipped the smaller, true number, because a view that flatters the enforcement stack is worth nothing the first time someone checks it.

The second correction ran the other way. Revenue on the region was being undercounted, and the gap sat between the two surfaces holding the data. I reconciled them and drove the undercount under a percent. That revision moves the region’s reported revenue up, not down.

Then I announced it org-wide, and the message said plainly that trends and rates were fully reconciled while a few absolute dollar totals were still rough pending Data Engineering fixes. A dashboard that tells you which of its own numbers to trust is worth more than one asking for blanket faith. That is the version that became the team’s source of truth.

  • Streamlit
  • QuickSight / SQL
  • Reconciliation
  • Enforcement attribution
  • Launch