Cloudflare on Friday released a fraud investigation dashboard for its Account Abuse Protection service, built on the idea that a history of ordinary behavior is harder to fake than a single identity check.

The dashboard is available first to customers in Cloudflare’s Early Access program, the company announced in a blog post. Fraud analysts can look at the entire population of accounts behind a site’s login and signup flows — total event volume, the IP addresses and devices observed, breakdowns by country and network provider — then narrow from those patterns to a single account.

The premise is that identity checks no longer settle much. Passwords, biometric scans and liveness tests ask whether a person can pass a check at a moment in time. But inexpensive AI tools now let fraudsters combine leaked credentials with synthetic media built to beat those checks, so a passed check does not mean an account can be trusted. The company’s answer is what it calls a stateful trust model: each interaction is weighed against the behavioral, network and device history the account has already built up.

The mechanics start with the customer, who picks an identifier from an existing login or signup flow, such as an email address, username or phone number. Cloudflare cryptographically hashes the value into a per-domain Hashed User ID that stands in for the account without exposing the underlying data. Every login or signup event then attaches itself to that ID, along with the network and device signals Cloudflare sees at its edge.

In a worked example of a credential stuffing investigation, the company described an analyst who opens the dashboard after failed logins climbed. The leaked-credential summary shows about 2,400 events in which a username or password matched a leaked record, against 11,700 where credentials came back clean. Cloudflare calls that an investigative lead, not proof that each of those accounts was compromised.

From there, filters shrink the pool. An analyst might ask for accounts with at least three failed logins, three leaked credential matches and activity from five or more unique IP addresses, then open the individual view for the worst of them. That view shows the account’s login success rate, its most common networks, locations and devices, and an event log in which every entry carries a timestamp and a Ray ID, the identifier Cloudflare assigns each request, for cross-checking against Security Events.

If a review confirms a compromise, the account’s Hashed User ID can go into a web application firewall rule to challenge or block whatever comes from it next.

The launch continues a run of security work Cloudflare has detailed this week. On Tuesday it described turning AI models loose on its own firewall to hunt for gaps.

Friday’s launch also adds two access roles meant to limit who sees what. One grants entry to the dashboard; a second, Account Abuse Protection PII, is required to view account-level personal information such as email addresses and to create or update Logpush export jobs containing it. Cloudflare urged administrators to hand out the roles on a need-to-know basis.