ByteDance · Product & Business Case
Analyze promo anomaly and design risk guardrails
TrueInterview
October 7, 2026 · 1 min read
In a two-hour 11.11 flash sale window from 11:00 to 13:00, account A123 submits 80 orders within 10 minutes using 12 different payment cards spread across 5 device IDs; 9 of those orders have a shipping address that also appears on orders from 4 other accounts; comparable users normally place about 2 orders per day. The live approval pipeline is designed to keep chargebacks at 0.3% and manual reviews at 2%. Part A — Diagnose: (1) What non-fraud explanations might account for this behavior? (2) Which specific data fields and joins would you retrieve within the next 15 minutes to tell coordinated abuse apart from genuine viral demand? (3) Suggest a real-time approve/hold/reject policy with explicit rules or model cutoffs, and estimate its business effect using a cost framework where a false positive costs $30 in lost GMV, a false negative costs $120 in fraud loss, and each manual review costs $1. (4) Calculate the GMV and loss impact of holding 50% of traffic similar to A123 for 30 minutes compared to rejecting it outright, and list your assumptions. Part B — Design safer promos: (5) Rework the promotion to curb abuse through coupon design, per-user limits, velocity caps, payment risk tiers, address trust scoring, and bot defenses, and specify guardrail metrics with alert thresholds. (6) Lay out an experiment and monitoring approach (holdout or geo-split), success and stopping criteria, and clear rollback triggers.
Overview: This question tests a candidate's skill in diagnosing promotion anomalies, separating coordinated abuse from organic viral growth, building real-time approve/hold/reject decisions with cost trade-offs, and outlining experiment and monitoring plans, covering fraud analytics, operational risk modeling, and experimentation.