Document risk frontend requirements

This commit is contained in:
Codex
2026-07-05 16:37:23 +03:00
parent a5600c75ae
commit e2834a7a52

View File

@@ -0,0 +1,127 @@
# Frontend Requirements: Risk, Audit, Funnel
## Scope
Frontend code is not changed in this backend release. The admin frontend should add read-only screens for individual-client risk scoring, security audit events, and the product funnel.
Legal-entity B2B flows are still manual and must not display automatic risk scoring decisions.
## User Payment Gate
Individual users cannot create payment orders until KYC is completed.
Expected client behavior:
- If the payment API returns `403` with `KYC verification is required before creating payment orders`, show a blocking state.
- Primary action: open or continue KYC.
- Do not show the QR/payment step.
- Do not retry order creation automatically.
Suggested copy:
- Title: `Для оплаты нужно пройти KYC`
- Body: `После подтверждения личности платежи станут доступны.`
- Button: `Пройти KYC`
## Admin Navigation
Add two admin sections:
- `Risk`
- `Audit`
Add one analytics section:
- `Funnel`
## Risk Screen
Backend endpoints:
- `GET /v1/risk/summary`
- `GET /v1/risk/assessments?limit=50&offset=0&decision=&user_id=&order_id=`
Summary cards:
- Total assessments
- Allowed
- Manual review
- Rejected
- Average score
- High risk
Assessment table columns:
- Created at
- User ID
- Order ID
- Score
- Decision
- Reasons
Filters:
- Decision: `allow`, `manual_review`, `reject`
- User ID
- Order ID
Decision badges:
- `allow`: green
- `manual_review`: yellow
- `reject`: red
## Audit Screen
Backend endpoint:
- `GET /v1/audit/events?limit=50&offset=0&severity=&action=&entity_type=`
Table columns:
- Created at
- Severity
- Action
- Actor type
- Actor ID
- Entity type
- Entity ID
- Metadata
Filters:
- Severity
- Action
- Entity type
Use collapsible JSON rendering for `metadata`.
## Funnel Screen
Backend endpoint:
- `GET /v1/analytics/funnel`
Display the funnel as ordered steps:
1. Registrations
2. KYC started
3. KYC completed
4. First payment
5. Successful operations
For each step after the first, show conversion from the previous step and conversion from registrations.
## Grafana Links
Expose optional links from the admin UI:
- `https://corp.grafana.elcsa.ru/d/elcsa-audit-security/infrastructure-audit-and-security`
- `https://corp.grafana.elcsa.ru/d/elcsa-product-funnel/product-funnel`
## Notes
- Do not show raw internal risk rule weights to end users.
- User-facing apps should show human states such as `Нужна проверка`, not numeric scores.
- Admin screens may show score, decision, and reasons.
- Legal entities should not use automatic risk scoring until KYB automation is added.