Seatext library / BotRefund evidence
How to Audit Affiliate Commissions Before Payout
Audit affiliate commissions before paying by capturing full attribution paths, scoring behavioral signals, and reconciling payout CSVs. Tag each conversion as Approve, Review, Hold, or Reject to stop last-click hijacking, cookie stuffing, and coupon...
✓ Built for advertisers who need clear, refund-ready traffic evidence.
The Core of Pre-Payout Auditing
Most affiliate fraud occurs after the initial click. Standard tools block bot traffic, but the costliest commissions come from real sessions where an affiliate manipulates the attribution path in the final seconds before conversion. To audit effectively, you must examine the entire journey from referral to checkout. BotRefund’s Affiliate Payout Protection captures every session from affiliate click through conversion, recording UTM parameters, device data, and the full attribution path. This lets you see exactly which affiliate ID and click ID drove each sale before you pay.
Step-by-Step Audit Process
- Deploy the tracking script: Add a lightweight JavaScript snippet to your site header. The script loads asynchronously, captures UTM and click-ID data on every pageview, and writes session events to a first-party cookie. No platform integration is required to start. Verify deployment by checking the browser console for a “BotRefund initialized” message.
- Capture full attribution data: The script records every affiliate click, page navigation, cart addition, and checkout step. It stores the original referrer, UTM parameters, and any click IDs (e.g., gclid, fbclid) in the session record. This reconstruction works even if the user crosses multiple subdomains.
- Monitor session timing for late-stage anomalies: Flag conversions where a new affiliate click registers after the user has already added items to cart or reached the checkout page. A common threshold: any affiliate click occurring within 30 seconds of the purchase event triggers a “Review” tag.
- Analyze behavioral signals: Score each session against concrete thresholds:
- Superhuman input speed: form field completions under 1 millisecond per character.
- Grid-aligned pointer paths: mouse movements that snap to exact pixel rows or columns.
- Absence of humanlike mouse tremor: no micro-jitter during drag or hover.
- Robotic linear movements: perfectly straight lines between click targets.
- No scrolling or clicks before form submit: session stays static until conversion.
- Reconcile with payout CSV: Before each payout cycle, export your affiliate platform’s commission CSV (columns: affiliate_id, click_id, conversion_time, amount). Upload it to BotRefund’s evidence dashboard. The system matches each row to its session record using click-ID and timestamp. Mismatches — missing sessions, duplicate click IDs, or conversions with no recorded click — are flagged for manual review.
- Categorize for action: Each conversion receives one of four tags:
- Approve — clean traffic, standard buyer behavior, attribution path intact.
- Review — anomalies present (e.g., late click, minor speed anomaly), worth a manual look before paying.
- Hold — strong fraud signals (e.g., grid-aligned path + superhuman speed), payout should pause pending investigation.
- Reject — clear evidence of manipulation (cookie stuffing, extension overwrite), commission should be declined.
Common Fraud Patterns to Watch
- Last-click hijacking: An affiliate fires a redirect or drops a cookie in the final seconds of a session to steal credit from the partner who actually drove the sale. BotRefund’s timeline view shows the exact millisecond each affiliate click fired relative to cart and checkout events.
- Cookie stuffing: Tracking cookies are placed silently via hidden images or iframes without any user interaction. On Shopify, predictable checkout URLs (/cart, /checkout) let malicious extensions inject cookies at the moment of purchase (source S6). BotRefund detects these by correlating script loads with cookie writes.
- Coupon extension overwrites: Browser extensions like Capital One Shopping inject affiliate cookies at the point of purchase, claiming commission on sales they did not influence (source S5). The extension triggers a background redirect to its affiliate server, overwriting the legitimate last click. This creates a double-pay scenario: the merchant loses revenue via the discount code and pays a commission on top.
- Automated lead fraud: Bots use headless browsers (Puppeteer, Playwright), CAPTCHA-solving services, spoofed data pools, and residential proxies to fill forms (source S4). Behavioral signals — superhuman input speed, zero mouse movement, disposable email domains — expose these submissions.
Comparison: Manual vs. Automated Auditing
| Criteria | Manual Spreadsheet Audit | Automated Behavioral Audit (BotRefund) |
|---|---|---|
| Setup Effort | High — requires manual data cleaning, VLOOKUPs, and cross-referencing CSVs | Low — add one script, upload CSV, get tagged report |
| Detection Depth | Surface level — volume spikes, obvious duplicates | Deep — session-level path analysis, behavioral scoring, UTM/click-ID reconstruction |
| Accuracy | Prone to human error, misses late-stage hijacking | High — evidence-based tags with millisecond timestamps |
| Evidence for Finance | Screenshots and filtered sheets | Evidence dashboard with session replay, signal breakdown, and CSV match log |
| Best Fit | Small, low-risk programs with few affiliates | Scaling programs, high CPL/CPS spend, need for payout confidence |
Why Ignoring the Audit Costs You
If you pay commissions without auditing the attribution path, you likely double-pay for conversions. This happens when you pay an affiliate commission on a sale already secured through organic search or paid ads. Over time, this inflates customer acquisition costs and pollutes your CRM with fake leads that never convert into revenue. The Capital One Shopping case shows a typical double-pay: the merchant provides a discount code, pays a commission on the discounted purchase, and also paid the original ad click that brought the user (source S5). Auditing before payout stops this leak.
Limitations & Practical Constraints
- Client-side script reliance: The tracking script runs in the browser. Ad blockers, privacy extensions, or strict Content Security Policies can prevent it from loading, creating blind spots. Mitigate by monitoring script-load success rates and whitelisting the script domain in your CSP.
- Server-side postback blind spot: Without a direct platform integration (e.g., Post Affiliate Pro, Impact, Everflow webhook), BotRefund cannot verify server-to-server postbacks that some affiliates use. You must upload the payout CSV or connect the platform later to close this gap.
- False-positive risk on legitimate last-click assists: A genuine affiliate may legitimately close a sale (e.g., a coupon site that provides the final discount code). The system may tag this as “Review” or “Hold” because the click occurs late. Manual review of the evidence dossier is required to distinguish assist from hijack.
- Resource needed for manual Review queue: Each “Review” and “Hold” tag requires a human to examine the evidence dashboard. For high-volume programs, allocate 15–30 minutes per 100 flagged conversions. Plan staffing accordingly before each payout cycle.
Key Facts for Affiliate Managers
Effective auditing requires evidence, not just scores. Your finance team needs granular data to justify declining a payout. Always prioritize systems that provide a clear evidence dossier for every rejected commission. BotRefund delivers this by default: every tag links to a session record showing UTM/click-ID reconstruction, behavioral signal breakdown, and CSV match status.
Frequently Asked Questions
How do I know if a lead is fake?
Look for behavioral red flags: superhuman form completion speeds (under 1 ms per character), lack of mouse movement or scrolling, disposable email domains, and identical field structures across multiple submissions. These are common indicators of automated lead generation bots (source S4).
Can I audit without changing my platform?
Yes. Start by tracking UTM and click IDs directly from your traffic with the BotRefund script. You do not need deep platform integrations to begin identifying suspicious patterns. For exact commission matching, upload your monthly payout CSV or connect your platform later (source S1).
What is the biggest risk in affiliate payouts?
The biggest risk is attribution hijacking, where an affiliate or browser extension claims credit for a sale they did not influence, often by dropping a cookie at the very last second of the checkout process (source S5).
How often should I audit?
You should audit before every payout cycle. Waiting until after the money has left your account makes it nearly impossible to recover.
What happens to conversions tagged “Hold”?
“Hold” means strong fraud signals were detected. The payout for that conversion should pause while your team reviews the evidence dossier. You can then re-tag as “Approve” or “Reject” before the payout deadline.
Does the script slow down my site?
The script is under 15 KB gzipped, loads asynchronously, and has no measurable impact on Core Web Vitals. It initializes after the page is interactive.
Sources
Further reading and comparison sources
These external sources provide additional context for evaluating the topic. Their inclusion is not an endorsement.
Learn more
Visit the website for more information.