Back to home
ProductAugust 2026·12 min read

Payment Agents: Your payment team, always on

Meet the team

marcusPerformance Agent

Turns more attempts into approved payments.

Marcus reads every signal in real time, finds the path that actually converts, and recovers the revenue that quietly leaks out of a checkout.

  • Daily performance briefing
  • Decline attribution & issuer analysis
  • Revenue recovery insights
SlackWhatsApp
zenoRisk Agent

Stops fraud without stopping growth.

Zeno scores risk in milliseconds, adapts to how each player actually behaves, and keeps friction off the people who fund your business.

  • AI fraud & anomaly detection
  • Identity & device intelligence
  • Chargeback evidence
SlackWhatsApp

AI agents built into Tonder to continuously optimize how your payments perform. But the job titles aren’t a metaphor — they do what those roles actually do at companies large enough to staff them: the daily performance review, the decline investigations, the fraud case files, the “should we change this rule?” analysis.

That last part is the whole point. A payments analyst and a risk analyst are two hires most operators in this vertical cannot justify — not because the work isn’t worth doing, but because it only pays for itself once you’re large enough to have already lost the money it would have saved. So the work doesn’t get done. Approval drifts for a month before anyone notices. A card tester runs for three weeks because nobody was looking at velocity on a Tuesday.

Most providers answer this with a dashboard. Dashboards are where questions go to die. You log in when something feels wrong, you stare at a chart, and you leave with a vague sense that approval “dipped a little.” Nobody opens a dashboard at 6 AM. Everybody reads Slack.

About the data in this article: Play Systems MX is our demo operator. The shape of the reports, the decline codes and the arithmetic are real; the merchant is not, and no real player identifiers appear anywhere below.

Marcus posts before you wake up

Payment problems don’t announce themselves. Approval doesn’t fall over; it drifts, two points at a time, until a month has gone. A card tester doesn’t trip an alarm; it runs for three weeks and then becomes chargebacks. An issuer doesn’t tell you it changed its overnight risk posture — it just starts saying no after 10 PM. By the time any of this is obvious enough to investigate, the money is already gone.

Which is why the important thing about Marcus isn’t that he can answer questions. It’s that he goes first. The briefing lands at six in the morning whether or not anyone thought to ask, whether or not anything looked wrong yesterday — and the numbers are in the message, not behind a link.

payments-daily
Slack
MarcusApp6:02 AM

76.2% approval730 of 958 · MX$360,013 — down 1.8pp from 78.0% yesterday.

Issuers · top 8 of 19

BBVA 79.9%(203/254)top volume · insufficient funds
Citibanamex 93.8%(137/146)clean
Santander 69.8%(74/106)rejected transaction
Banco Azteca 84.8%(56/66)insufficient funds
Banorte 71.7%(38/53)do not honor
HSBC 78.1%(25/32)do not honor
BanCoppel 34.0%(16/47)do not honor
Pomelo 5.9%(1/17)transaction not permitted

First-time deposits

50.8% conversion102 FTDs via cards.

Declines

227 issuer · 1 3DS authentication · 0 from your own risk rules (of 228)
Top 3 reasons of 11: rejected transaction (82), insufficient funds (63), do not honor (30)

3DS

105 people opened the challenge and never finished it. Those are not bank declines. Counting them, true card conversion was 68.7%

Fraud

r•••••312@email.com — 7 cards across 3 issuers, 0 approved, MX$455,000 attempted. Card testing. Handing it to Zeno.

approvals-by-bin-2026-07-14.xlsxSpreadsheet · 84 KB · every issuer, brand, funding type and decline code
5 replies· last reply 8:17 AM

Everything Marcus watches, in one list:

Daily performance briefing

Posted every morning, unprompted, with the numbers in the message rather than behind a link.

Decline attribution

Every decline assigned to one owner — the issuer, the 3DS flow, or your own rules. No “other” bucket.

Issuer and BIN analysis

Approval by bank, by BIN range, by funding type, against your own 30-day baseline.

3DS abandonment tracking

The deposits that vanish mid-challenge and never appear in a decline report anywhere.

Routing and retry guidance

Which BIN ranges want a different acquirer, a different descriptor, or no retry at all.

Ask-anything follow-ups

Reply in the thread the way you’d ask an analyst, and get the answer with the data behind it.

Where the numbers come from

A fair question about any agent that writes confident sentences: is it computing this, or narrating it? Marcus is not summarising a dashboard export. He reads the authorization record — the attempt level, not the settled level — and compares it against your own history, not an industry average.

1

Read the authorization record

Every attempt, not every settled payment: issuer response code, BIN, card brand and funding type, 3DS challenge outcome, retry chain, and the Guardian decision that preceded it.

2

Split the attribution

Each decline is assigned to exactly one owner — the issuer, the 3DS flow, or your own risk rules. Nothing lands in an “other” bucket, because that bucket is where accountability goes to hide.

3

Compare against your own baseline

A 30-day rolling baseline per issuer and per segment — not an industry benchmark. A 71% approval rate is fine for one BIN range and an incident for another.

4

Write it up and post it

Only what moved past its threshold gets called out. The full BIN-level breakdown rides along as a spreadsheet for whoever wants to dig.

Why the baseline is yours, not the market’s: a 71% approval rate is unremarkable on one BIN range and a live incident on another. Benchmarks tell you how you compare. Baselines tell you what changed — and only one of those is actionable before breakfast.

The report is the beginning of the conversation

Here is the part that changes how teams actually work: you can talk back. Marcus isn’t a broadcast bot. Reply in the thread the way you’d ask an analyst sitting next to you — plain language, no syntax, no query builder — and the answer comes back with the data behind it, in seconds rather than in next week’s meeting.

Why did Santander drop? Is it us or them?

Compare FTD conversion this week vs last. Cards only, new players only.

Which BIN ranges should we stop retrying?

What did 3DS abandonment cost us last week?

payments-daily
Slack

Marcus · 76.2% approval · 730 of 958 · MX$360,013 — down 1.8pp…

5 replies

DR
Daniela RojasPayments Ops8:14 AM

Marcus, why did Santander drop? Is it us or them?

MarcusApp8:14 AM

Them. All 32 declines were issuer-side, 28 of them “rejected transaction,” and they cluster between 10 PM and 1 AM. The same BIN ranges approve fine during the day, so this is Santander’s overnight risk posture, not anything on your side.

If it holds two more days it’s worth routing those BINs through the secondary acquirer after 9 PM. A similar case last month recovered 11 points of approval on the affected segment.

DR
Daniela RojasPayments Ops8:16 AM

Compare FTD conversion this week vs last. Cards only, new players only.

MarcusApp8:16 AM

This week

50.8%

Last week

57.3%

The whole gap is 3DS abandonment on two issuers whose challenge pages are timing out. Deposits that finished the challenge converted at the same rate both weeks — so nothing about your checkout got worse.

MarcusApp8:17 AM

Also handing this morning’s card-testing case to @Zeno — 7 cards, 3 issuers, one email. He’ll come back with the case file.

Look at what the second question actually was. That’s not reporting — that’s segment analysis that used to mean filing a ticket with a BI team and waiting a week. It happened inline, in the thread, while the question was still hot. And because both agents read the same data, Marcus can hand a question to Zeno mid-conversation: an approval anomaly becomes a fraud investigation becomes a rule change, without anyone exporting a CSV.

Three things that turned up this way

All three come from the same demo operator used throughout this article — not customer results, and each one is checkable against the reports above.

An issuer that only fails at night

Play Systems MX · demo

32 declines from Bank A in a single day, every one of them issuer-side, clustered between 10 PM and 1 AM. The same BIN ranges approved normally during the day — so this was the bank's overnight risk posture, not the checkout.

Action: route the affected BINs to the secondary acquirer after 9 PM.

A channel declining everything, quietly

Play Systems MX · demo

119 attempts at Bank B in July. 119 declines. Nothing in the pattern read as fraud — the channel was simply not working, and it had been not working long enough to look normal.

Worth: 119 deposits that were never going to arrive, recoverable with a routing test.

The losses that never show up as declines

Play Systems MX · demo

105 people opened a 3DS challenge and never came back. No bank declined them, so they appear in no decline report, no decline rate and no issuer breakdown.

Worth: 7.5 points of real card conversion — 76.2% headline against 68.7% actual.

Zeno: the memory your team never had

A blocklist that ends at your own front door is a blocklist a fraudster only has to beat once. They burn you on Monday, walk next door on Tuesday, and arrive as a new customer with a clean history — because as far as that operator can see, they are one. Every risk team in this market has been fighting the same people independently, and paying to learn the same lesson separately.

Marcus tells you what happened. Zeno tells you who you’re dealing with — and his memory doesn’t stop at your front door.

Think of it as a credit bureau for players. Every deposit, decline, chargeback and device signal builds a profile, and because Tonder processes for multiple operators in the same vertical, that profile survives the move from one brand to the next.

Player profiling

Every deposit, decline, chargeback and device signal builds a profile that persists.

Cross-operator signal

A device blocked at one operator doesn't arrive at the next one as a stranger.

Fraud case files

Cards, BINs, velocity, timeline and a recommendation — a story, not a log export.

Blocklist with evidence

Every entry carries its reason and its history, so nobody quietly unblocks a chargeback machine.

Whitelist for proven players

Forty clean deposits shouldn't meet the same friction as an account created twenty minutes ago.

Monthly fraud report

Per property, ranked by recoverable pesos, sent to whoever owns risk.

Fraud cases, not event logs

When something like the card-testing case fires, Zeno writes the case file: every card attempted, the BINs and issuers behind them, device and velocity signals, the timeline, and whether that fingerprint has been seen at other operators on the network. Your team gets a story with a recommendation at the end, not a spreadsheet of raw events to interpret.

A blocklist that remembers why

Confirmed bad actors stay blocked across email, card fingerprint and device. The difference from a homemade list in a spreadsheet is that every entry carries its reason and its history — so six months later nobody is asking “why is this one blocked?” and quietly unblocking a chargeback machine.

And a whitelist, because false positives cost more

Risk teams love to talk about the fraud they stopped and never about the VIP they annoyed. A player with 40 clean deposits and zero chargebacks shouldn’t meet the same friction as an account created twenty minutes ago. The whitelist means your proven players get the frictionless path — fewer challenges, fewer manual reviews, fewer abandoned deposits from exactly the people who fund the business.

Underneath all three sits a score that resolves into green, yellow or red, and that score drives routing automatically — friction goes where the risk is and nowhere else. The scoring engine is a subject of its own; we wrote it up in Guardian AI for iGaming.

risk-ops
Slack
ZenoApp9:00 AM

July fraud reports are out — 4 properties, sent to risk and finance.

Chargeback rate fell to 0.82% from 2.44%— that’s under Visa VAMP, but still over Mastercard EFM at 0.5%. That’s the one to act on this month.
The card-testing case @Marcus flagged on 14 July is confirmed. Blocklisted on email, device and card fingerprint. Same device was blocked at another operator 12 days earlier.
fraud-report-july-2026.pdfPDF · 4 pages · issuer detail, disputes, hourly volume

What a Zeno report looks like

Monthly, per property, to whoever owns risk. The first page is the one most people read:

Monthly Fraud Report

Play Systems MX

July 2026 · prepared by Zeno

Risk: HighVisa VAMP: CompliantMastercard EFM: Breach
MetricThis monthLast monthChange
Total transactions4,0134,019▼ 0.15%
Cards acceptance65.4%60.9%▲ 4.5pp
Total volume$3,927,984$3,288,526▲ 19.5%
Avg transaction$979
Chargebacks134358▼ 62.6%
Chargeback rate0.820%2.440%▼ 1.62pp

Top issuer

BBVA

669 attempts · 92.5% approved

Peak fraud hour

23:00 UTC−6

264 transactions

Weakest segment

Amex credit

0 of 34 approved

Key insight

Citibanamex declined 100% of 119 attempts this month — 119 deposits lost, none of them for a reason that shows up as fraud. Fixing that one channel is the highest-return change available in July, and it costs nothing but a routing test.

Top issuers by attempts

IssuerAttemptsSuccessVolume
BBVA66992.5%$727.6K
Santander46067.6%$761.2K
Banorte38464.8%$170.6K
BanCoppel21340.9%$97.6K

Important findings

1

Chargeback rate of 0.82% sits under Visa VAMP’s 0.9% threshold but breaches Mastercard EFM at 0.5%. Left alone that means enrollment in a monitoring program with tiered fines. Prioritise in-flight dispute review this month.

2

BanCoppel approves 40.9% of 213 attempts. That doesn’t read as fraud — it reads as an issuer relationship problem. Worth testing a fallback route before writing the volume off.

3

Card testing confirmed on r•••••312@email.com — 7 cards across 3 issuers, MX$455,000 attempted, nothing approved. Blocklisted on email, device fingerprint and card fingerprint on 14 July. The same device was blocked at another operator on the network 12 days earlier.

Page 1 of 4 · generated by Zeno · sent 1 Aug 2026 · the full report adds issuer detail, dispute analysis, retry behaviour and hourly volume

Two things to notice. The findings are ranked by recoverable pesos, not by severity theatre — the compliance breach comes first because it has a deadline attached, and the 40.9% issuer comes second because it is the largest pile of money on the floor. And the numbers that improved are stated as plainly as the ones that didn’t; a fraud report that only ever brings bad news stops being read by March.

Then the same thing happens as with Marcus: you reply to it. “Which disputes are still in flight?” “What would EFM compliance cost us in blocked volume?” The report is a starting position, not a verdict.

Meet your new hires.

Both agents ship with every Tonder account, in the channel your team already uses.