Decisions · Program mechanics and currency
Should you allow point transfers
Allow transfers between your program and a small set of partners, where each movement is priced and settled. Do not allow free member-to-member transfers, because they are the main channel for monetising stolen accounts. If members need to combine balances, offer household pooling, which keeps points inside an account group you can see.
Allow transfers between your program and a settled set of partners, and refuse free member-to-member transfers. The two get discussed as one feature, and they have almost nothing in common: partner transfers are priced commercial agreements, while member transfers are an open channel between accounts that fraud will find before your roadmap does.
## Partner transfers are priced and settled
When a partner currency converts into yours, the partner buys those points from you at a wholesale rate, which is revenue. When your members convert out to a partner, you pay the partner to assume the obligation, a redemption at whatever settlement rate the contract fixes. Both directions are billable events with a counterparty and an invoice. Nothing about them requires trusting individual members, which is why they are the safe half of the decision.
## The ratio is where the value moves
Members compute transfer value through the ratio, and the ratio can quietly destroy it. Say your point is worth 1 cent and a partner's is worth 1.5 cents. At a 1:1 ratio a member turns 1 cent of value into 1.5, and your own catalogue will be drained through the partner. At 3:1 the same member turns 3 cents into 1.5, the transfer destroys half the value, and usage collapses to people who never did the arithmetic. The workable range between those failures is narrow, and it shifts whenever either side devalues, so the agreement needs a ratio revision clause from day one.
## Member-to-member transfer is how stolen points leave
An account takeover monetises through movement. Points that can only be redeemed for a flight in the owner's name are awkward to steal. Points that can be sent to another member move to a mule account within an hour and are gone in a way a merchandise order is not. If you offer person-to-person transfer anyway, lock transfers for 72 hours after any credential change, and cap what any account can send per month. A fee helps too, less for the revenue than because priced transfers leave an economic trail.
## Household pooling delivers the legitimate use case
Most genuine demand for moving points is a family assembling one reward. Pooling meets it: balances combine inside a declared household group and never leave the account graph you can see, so the fraud surface barely grows. Gifting flows, by contrast, inherit every takeover problem above while serving the same underlying need worse.
## Transfer rights are nearly impossible to withdraw
Once members hold balances they earned expecting transferability, removing the feature is a material change to the deal, and the people who care most are the ones with the largest balances. Grant the capability as if it were permanent, because in practice it is.
The recommendation flips at the extremes of balance size. A grocery program whose accounts hold a few dollars of value can allow gifting freely, since the prize for an attacker is too small to organise around. An airline whose top accounts hold thousands of dollars of currency should not, whatever the engagement team projects. What nobody can hand you is a reliable public figure for transfer fraud rates; operators do not disclose them, so the design has to assume the channel will be attacked rather than price the risk from data.