fraudulent requisites (repeated attempts that hurt conversion and provider limits);
test runs / brute-force attempts;
users/requisites flagged during investigations (support case / risk case);
prevention of repeated chargeback patterns.
Merchant / Pipeline — where exactly the blocking rule is applied.
Type — the requisite type (card/email/IP/phone/identifier).
Requisites — the exact value to be blocked.
Description — reason/context (for example: fraud, chargeback, test user, case #1234).
“more than N failed attempts within 24 hours”,
“more than N attempts from one IP per hour”,
“suspicious behavior — send to a separate scenario”,
you can define a threshold and time window,
the restriction can be lifted automatically when the window ends,
you can choose a soft response (not always a hard block): lower priority, another scenario, another PSP, etc.