Introducing Local Graph: A New Era of Identity Insight
June 15, 2026
The Local Graph Has Arrived: Turning Data Silos into Connected Intelligence
A login. A transaction. A password reset. Every touchpoint is a tiny glimpse into how an identity interacts with your brand. But identity trust — arguably the most valuable digital currency — isn’t built on a single moment. It’s built through understanding how each moment is connected to the ones that came before it.
Even the most sophisticated organizations struggle to see the full picture within their own walls. Without connected intelligence across user journeys and lines of business, teams spend valuable time piecing together insights that should be easy to find, and use to make identity risk decisions at scale.
That’s why we’re excited to introduce the Local Graph. Much like Socure’s Identity Graph, the Local Graph connects every part of an identity to its associated activities, signals, and outcomes from across your entire organization into a single, time-aware framework. Think of it as your custom intelligence hub — showing how an identity appears in your ecosystem today, how it has behaved in the past, and how all the individual elements connect over time.
And to turn that intelligence into action, we’re also launching two powerful new capabilities in RiskOS®: Persistent Profiles and Connected Rule Writing. These features bring the Local Graph to life, giving teams the ability to explore historical activity, uncover cross-journey connections, and build automated, data-driven rules that act on those insights in real time.
Connecting the Dots: Persistent Profiles
Imagine you’re an analyst investigating a potential fraud case. You pull up a user’s profile, and instead of a static snapshot, you see their entire journey unfold — every known interaction, associated identity element, and outcome, all in one dynamic, persistent view.
That’s a Persistent Profile. And it’s not centered around just a user — it could be any identity element such as a device, email, phone, address, IP, or even a custom entity. Each profile captures its full history: every activity, linkage, and signal your organization has historically seen.
The experience feels like tracing a story rather than sifting through data. Using the timeline view, you can watch that story unfold chronologically, seeing exactly when a user opened an account, logged in, made a transaction, or filed a dispute.
When you need to dig deeper, the table view table lets you filter and compare those moments side-by-side, uncovering subtle changes or emerging patterns across time, workflows, or lines of business.
You can even view “one-hop” relationships or connections — like a single device linked to multiple users — to uncover anomalous or risky relationships that might otherwise go unnoticed. These linkages are listed clearly at the top of each profile for quick, easy access.
Persistent Profiles from Socure on Vimeo
Persistent Profiles were built specifically to help eliminate blind spots, so your teams can understand the full context when making risk decisions.
However, we know that most risk decisions happen long before a human ever gets involved. That’s where Connected Rule Writing comes in.
Making Smarter Risk Decisions at Scale: Connected Rule Writing
Until now, automated decisions have been made based only on the data available at that moment. Connected Rule Writing brings past events and context into the equation.
This means your automated rules can now reference previous activity, velocity patterns, and relationships across identities and identity elements to make smarter decisions at scale.
For example, you can create rules that trigger if a device appears across multiple accounts in minutes, if a phone number is tied to repeat disputes, or if a user’s login velocity suddenly spikes. Rules can also draw from events in other journeys — referencing what happened at account opening, during a password reset, or in prior transactions.
Connected Rule Writing from Socure on Vimeo
By connecting current behavior with historical signals, Connected Rule Writing helps teams spot emerging risk earlier, adapt to new attack patterns faster, and automate smarter trust decisions at scale.
The best part? You can build and deploy these rules in seconds, with no engineering or technical resources required.
The Local Graph In-Action
Scenario 1: Account Takeover Prevention
A prepaid debit card provider has a simple rule in place to protect against Account Takeover (ATO): block any device after five failed login attempts.
So when a fraud analyst receives an ATO claim and pulls up the customer’s User ID in RiskOS, he’s surprised to see the last login was completely clean (correct password on the first try). Curious, the analyst clicks into the Device Profile associated with that login. That’s where the hidden pattern reveals itself.
This single device had successfully logged into four different customer accounts in the last two hours.
Unfortunately, the fraudster knew exactly how to beat the system. They weren’t guessing passwords; they were using stolen credentials to access multiple victim accounts, one by one. And because they never hit the failure limit on any single account, they got away with it.
With Connected Rule Writing, the team can now close this loophole across their entire organization. For example:
- IF a Device ID is associated with more than two (2) unique User IDs within 24 hours THEN flag for “Account Takeover.”
Now they can stop account takeovers earlier and prevent both major losses and unhappy customers.
Scenario 2: Marketplace Collusion
Let’s take a home-services marketplace where users can be both service requesters and providers. Over time, the fraud team starts noticing that certain providers have an unusually high number of five-star reviews.
The fraud analyst copy/pastes one particular service provider’s email ID in the search bar, and pulls up the profile. The analyst begins scanning the timeline of activities associated with the email — onboarding, service listings, and completed jobs.
Curious, the analyst clicks into the linked device profile. That’s where the pattern reveals itself. This single device ID is tied to 64 different emails — and all but one are listed as homeowners. It’s the tell-tale sign of a coordinated scheme: the provider is using a single device to create fake customer accounts, submit requests to their own business, and post glowing reviews to inflate their reputation.
To confirm the behavior, the analyst checks a few other flagged providers and finds similar overlap — one device associated with dozens of supposed homeowners. What looked like independent activity is actually a network of self-dealing accounts.
With Connected Rule Writing, the team can now automate detection of this behavior across the entire marketplace. For example:
- IF a device or IP appears in both service provider AND requester workflows within a 24 hours THEN flag for review.
- IF a single device is linked to more than three (3) accounts THEN tag as potential collusion.
Those conditions can be created directly in the RiskOS Workflow Builder, automatically tagging patterns like “Potential Collusion” or “Shared Device.”
Previously, this kind of collusion would have taken weeks to confirm and required heavy engineering support. Now, teams can see the full story instantly and build rules that stop the next instance before it happens — in minutes.
Where to Find These New Features
Persistent Profiles
There are three simple ways to access a profile:
- Use the search bar at the top to look up any internal UserID, email, device, phone, or IP, and open its full profile.
- Click the Profiles tab in the left sidebar to browse and filter by type.
- Within a Case, click any linked profile to view its full history and relationships.
Connected Rule Writing
Build smarter rules directly in the RiskOS Workflow Builder. When creating or editing a rule, look for the new Aggregation inputs — these let you reference historical events, cross-journey attributes, and velocity patterns directly in your logic, no engineering needed.
Local Graph Signals Tile
Within your Case Management view, you’ll see a new tile called Local Graph Signals, listing the specific aggregations and signals associated with the case so you can spot anomalous behavior fast.
Smarter Risk Decisions Start Here
Every decision, whether automated or human, gets stronger with context. RiskOS empowers your team with context, control, and the confidence to make the right decision across every moment that matters.
Ready to see the Local Graph in action?
Emma Griffin
Emma Griffin is a Product Marketing Lead at Socure, where she owns go-to-market strategy for fraud and risk intelligence solutions. With over a decade of marketing experience, she has built a career on turning complex ideas into clear narratives that resonate with buyers. Before tech, Emma performed as a professional Irish dancer on Broadway and toured internationally with Michael Flatley's Lord of the Dance.