W WEBXPAYRisk intelligence
Confidential · Internal
Enterprise merchant risk API-backed portfolio · MySQL persistence

MERCHANT RISK
CONTROL CENTRE

One portfolio view for onboarding evidence, merchant
decisions and continuous enterprise-risk monitoring.

0 imported merchants 0 assessed merchants 0 high risk 0 activation blockers
!
Current portfolio posture

Merchant API portfolio is ready to synchronize

Pull the approval-view list, select multiple merchants, and run the merchant analysis. Every source record, normalized stakeholder, document link, finding, control and analysis version is stored in MySQL. No JSON data files are used.

!
Setup required

Connect MySQL and install the risk tables

Copy config.local.example.php to config.local.php, enter the database and API credentials, then run the installer.

Open database installer
Portfolio operating model

Turn this Merchant 360 into WEBXPAY's enterprise risk cockpit.

The API-backed application is the decision layer. It keeps one permanent merchant identity while onboarding evidence, documents, findings, controls and review history are added over time.

Recommended pattern

One portfolio. One merchant ID. Many evidence and monitoring feeds.

Do not create a separate risk website per merchant. Use the shared merchant register and reusable Merchant 360 workspace, driven by the WEBXPAY signup merchant ID and role-based review controls.

0Merchants in register
0High / critical risk
0Open activation controls
ConfiguredOnboarding API credential
Portfolio review bench

Every merchant. The same complete review workspace.

Use the table for a portfolio-wide decision view, then open the Merchant 360 workspace for evidence, documents, digital footprint and controls.

Loading Merchant 360…

Implemented data flow

List once. Analyze selected merchants. Persist every review.

The browser never calls the merchant API directly. PHP acts as a secure server-side proxy, retrieves the approval-view data and document URLs, normalizes the response, runs the analysis and stores all results in MySQL.

01
Approval-view list

Import merchant IDs, names, merchant number and credit-review status.

02
Multi-select review

Select up to the configured batch limit and fetch each approval-view detail response.

03
Document discovery

Recursively identify onboarding document links and de-duplicate them by SHA-256 fingerprint.

04
Risk analysis

Compare onboarding values, document availability and master-data linkage; optionally connect an AI analyzer webhook.

05
MySQL history

Store source snapshots, normalized merchant data, documents, findings, controls, decisions and every analysis version in MySQL.

Migration path

Add every existing merchant without losing history.

01

Import the merchant master

Load the WEBXPAY register through the approval-view list and keep signup_merchant_id as the permanent source key.

02

Match and de-duplicate

Resolve legal name, BR number, tax ID, merchant number, URLs, settlement account and stakeholders into one Merchant 360 record.

03

Migrate evidence

Attach onboarding documents with source section, document type, URL fingerprint and review status.

04

Baseline every merchant

Run rules and screening, calculate risk, then route every material exception to a named owner.

05

Connect live behaviour

Add transactions, settlements, refunds, disputes and website changes so risk updates after onboarding.

Minimum merchant record

Start with a clean master dataset.

Use a read-only reconciliation first. Confirm row counts, duplicates and missing critical fields before enabling updates to production systems.

Merchant IDLegal nameBR / tax IDDBA + outletsMCCProducts + channelsStatusOnboarded dateRisk ownerRisk ratingLast / next KYCSettlement accountExpected volumeActual GMVRefunds + disputesWebsite + social URLs
System of record

Model decisions, not just documents.

  • Merchant, legal entity and beneficial owners
  • Outlets, channels, products and MCCs
  • Settlement accounts and verification events
  • Documents, screening results and expiries
  • Assessments, scores, overrides and approvals
  • Transactions, settlements, refunds and disputes
  • Alerts, cases, actions, owners and audit events
Target architecture
01
Sources

XBOARD / CRM · Gateway · POS · Settlements · KYC · Public data

02
Risk core

Merchant identity · Rules · Scoring · Screening · Evidence vault

03
Workflows

Alerts · Cases · Approvals · Reviews · Remediation · Audit trail

04
Views

Portfolio cockpit · Merchant 360 · BRMC reports · Operations queue

Who sees what

Role-based workspaces.

Board / BRMC

Exposure, trends, concentration and overdue actions.

Risk & Compliance

Cases, screening, approvals, overrides and reviews.

Business / RMs

Merchant profile, actions and renewal readiness.

Operations / Finance

Settlement, refunds, disputes and reconciliation.

Fraud / Technology

Behaviour, rules, device and cyber signals.

Internal Audit

Read-only evidence, decisions and complete history.

Always-on triggers

Move from periodic review to continuous risk.

KYC expired or ownership changedSettlement name/account changedGMV outside expected rangeRefund or chargeback spikeDormancy then sudden activityMCC/product mismatchWebsite/legal page changedSanctions, PEP or adverse press hit
Practical rollout

A controlled 12-week path.

01

Weeks 1–2 · Foundation

Agree taxonomy, owners, access model and import the top 50 merchants.

02

Weeks 3–5 · Migration

Load the complete merchant register, evidence metadata and baseline scores.

03

Weeks 6–8 · Live signals

Connect gateway, settlement and screening feeds; tune alert thresholds.

04

Weeks 9–10 · Workflow

Launch cases, maker-checker approvals, SLAs, escalation and audit views.

05

Weeks 11–12 · Assurance

Pilot with Risk, Operations and RMs; reconcile outputs and launch reporting.