Reconstruct the path a CTV impression claimed to take, test the app, channel and device behind it, then assemble the evidence a claim or block would need — the verification lead decides what's filed.
A bid request arrives claiming a device, an app or channel, and a TV screen.
02
Normalise device, app and channel fields, and mark what an SSAI proxy forwarded rather than sent.
Reason
03
Reconstruct the path the impression claims to have taken, bid request to named app or channel.
04
Test the app, channel and device identity behind it against declared authorisation and history.
05
Weigh SSAI-forwarded identifiers against the server ranges the client's own supply chain whitelists.
Decide
06
Flag misrepresentation and identity-spoofing signals a human should weigh, never a verdict.
07
Route every flagged bid to the named verification lead, never resolved without them.
Out
08
Retain the evidence, the reconstructed path, the flags and the lead's decision against the case.
09
Execute write actions only inside the approval boundaries agreed during implementation.
→Product statement
The agent triages, reconstructs and reports what each source measured; the verification lead declares fraud, files any claim and decides any block, and the advertiser stays the counterparty of record.
2Signal assembledDevice, app and channel fields, SSAI-forwarded headers, prior sessions and whitelist status, each sourced
3Path reconstructedReconstructed path, identity-test result, misrepresentation flags and confidence
4Controls appliedSSAI-header checks, whitelist-range checks, authorisation checks and confidence threshold
No human action required
Stages 1 to 4 run unaided, and no claim or block is made at any of them — the agent tests and reconstructs, and the verification lead's lane opens at the confidence gate.
5DecisionBranches at the confidence threshold
High confidence
Goes to the verification lead to review.
Low confidence
Adds a second analyst read first.
Verification review
The flag is held with its reconstructed path, its identity test and the confidence.
Confirm · Edit · Escalate to claims review
Confirmed — packaged for the lead's decision▼
6Case-management and evidence systems updatedOnly where write access and approval policy allow it
Why it's flaggedThe device did not send this request and a person still decides.
ActionConfirmEditEscalate to claims review
What the score decidesBelow the configured threshold the flag picks up a second analyst read before it reaches the lead.
Value
Where AI adds value
The same four claims, placed at the point in the workflow where each one applies.
Where the value landsValue 01 – 04
Every flagged bidFrom the bid-request log
03Triaging
Test every flagged bid
Reconstruct the claimed path and test it against SSAI headers, whitelist ranges and declared identity.
01Approved path
The device did not send it
Server-side ad insertion composes the request; the device identifier, IP and user agent are all forwarded values, and app and channel identity is self-declared.
02Human review
Send review to the paths
Misrepresentation and identity-spoofing signals concentrate behind whitelisted SSAI ranges, so the lead's read starts there.
04Build an evidence trail
The impression, the path it arrived on and the analyst who escalated it stay on the case.
Integrations
Typical integrations
Five system groups connect to the same agent. Which of them are in scope is decided in discovery.
Ad verification & CTVDoubleVerify · IAS HUMAN · Pixalate
A campaign-level IVT rate can look clean while the misrepresentation signal concentrates on one app or channel. Nestack reports the flagged-signal rate by slice, not only in total.
Slice performance — reported separately, not only in aggregateIllustrative example
Slice
Failure rate
Lift
Lift vs. threshold
Status
Impressions served through SSAI
7.7%
4.0×
Review
Long-tail apps and FAST channels
5.5%
2.9×
Review
Publisher-direct CTV inventory
3.3%
1.7×
Watch
Major streaming apps bought directly
1.9%
0.8×
Normal
Bar: misrepresentation-signal lift vs. the major-app baseline · scale 0–4.0× · tick at 2.0×2 of 4 slices over threshold
Evidence-linked improvement
Every flight ends by adding a test
A cycle ends when the missed scheme is a case the next release has to pass. That suite is what the next alert triaged is measured against.
Improvement cycle · five stagesSwitchback — the path turns at Improve and returns at Learn
01Detect
Flagged-signal rate rises in an app or channel slice.
02Diagnose
The impression no television ever rendered is checked against the SSAI header, the whitelist range and the app declaration until one cause explains it.
03Improve
Version-stamp the correction and attach the cases that exposed it.
04Verify
The affected cases run again, and a fail stops the release.
05Learn
It becomes a permanent test, and the detection rules move with it.
Learn → DetectThe return edge. The next flight is triaged against a suite one case longer.
Typical build scope
Twelve workstreams across six weeks
The build scope read against the delivery timeline. Week structure follows the six-week plan — discovery, sources, triage workflow, evaluation, integration, then production validation and handover.
WorkstreamWeek 1Week 2Week 3Week 4Week 5Week 6
01CTV verification workflow discovery and boundary definition.
02Ad-verification and SSP source assessment.
03Detection-rule and threshold mapping and rule mapping.
04Bid-log ingestion and field normalisation.
05Path-reconstruction and identity logic.
06Confidence scoring and escalation routing.
07Verification-lead approval workflow.
08Verification-vendor and SSP integration.
09Spoofing and identity cases.
10Guardrails and escalation controls.
11Impression-trail instrumentation.
12Deployment, documentation and Agent Care handover.
12 workstreams · 6 weeks · bar shows the weeks a workstream is active — several run in parallelFinal scope and sequence confirmed in discovery
Engagement tiers
What each tier includes
Rows are the capabilities named in each tier's scope. Higher tiers include everything below them.
Capability✓ in scope · — not at this tierPilotOne supply path, one vendorProductionProduction verification accessAdvancedMultiple markets / advertisers
Introduced at Pilot
Triage against your detection rules✓✓✓
Verification-lead approval✓✓✓
Detection-accuracy baseline✓✓✓
Introduced at Production
Reporting by app and channel—✓✓
Escalation workflow in your tools—✓✓
Approved evidence write-back—✓✓
Verification-vendor integration—✓✓
Introduced at Advanced
Multi-vendor detection rules——✓
Multi-stage lead approvals——✓
High bid-request volume——✓
Multi-market CTV controls——✓
Build priceFrom $5,000From $8,000Custom quote
Final build priceConfirmed after discovery based on integrations, workflow complexity, transaction volume, approval controls and deployment requirements.
Separate from buildBuild pricing is separate from recurring Agent Care, which covers managed monitoring, evaluations, incidents and verified improvements after launch.
What we need from you
What you bring, and what we build with it
Each input maps to a piece of build scope and a week in the delivery timeline.
You bringWe build with it
01Your CTV supply paths and current SSAI setup→Bid-log ingestion and identity-field mappingWeek 1
02Representative flagged and cleared bid samples→Triage baseline, path reconstruction and identity testsWeek 2
03Your detection rules and escalation thresholds→Detection-rule and escalation-threshold mappingWeek 1
04Access to relevant APIs, feeds or exports→Verification-vendor and SSP assessment, then integration setupWeek 2
05Paths you would not want blocked→Spoofing cases and the evaluation suiteWeek 4
06What no impression may be counted on→Confidence scoring, escalation routing, guardrails and approval controlsWeek 3
07Named verification leads to review flags→Verification-lead approval workflow, then pilot and production validationWeeks 5–6
Nothing else is requiredDeployment, documentation and Agent Care handover are ours.
Delivery timeline
Four phases across six weeks
The bands follow the work as it actually falls, so week 5 holds evaluation and pilot at once.
PhaseW1W2W3W4W5W6
DiscoveryW1
BuildW2 – W3
EvaluateW4 – W5
Pilot & LaunchW5 – W6
Week focusW1CTV verification discovery, detection-rule mapping and the automation boundaryW2Verification-vendor and SSP integration, and the triage baselineW3Triage workflow, confidence logic and escalation controlsW4Evaluation suite, guardrails and failure-mode testingW5Verification-vendor integration, pilot flights and targeted correctionsW6One flight run under the verification lead, then Agent Care handover
Reading the bandA bar spans only the weeks its work occupies; the week 5 overlap is real, not padding.
At the end of W6Once the cycle validates, monitoring moves to Agent Care.
DurationSix-week plan shown · typical delivery 4–6 weeks depending on scope confirmed in discovery.
Next step · Advertising AI agent
Build a CTV fraud and measurement agent around your verification workflow.
Show us your bid-request logs, your SSAI setup and who signs off on a claim. Next, we'll reconstruct one flagged path end to end so your verification lead can see exactly what the agent would hand them.