A working record of how a B2B2C reseller channel with 8 million members went from a pricing feature with a fraud hole in it, to a system where commission is only real once a guest actually walks through the door — and from four scattered flows into one the reseller could actually run.
Where the commission comes from
RedDoorz Affiliate — internally called Redseller — is one leg of RedDoorz's B2B2C distribution: instead of selling rooms only through OTAs or its own app, RedDoorz opens a channel where individual resellers generate their own promo code, share it on social media, and earn a commission on every confirmed booking that comes through it.
Because affiliate discount codes were becoming a viral discovery pattern — resellers posting codes on Instagram, TikTok, WhatsApp groups — every reseller code was standardized with an RDAFF prefix. That single naming rule let pricing and ops instantly tell an affiliate-originated code apart from a market-wide promo, so affiliate discounts could be capped, governed, and reported on without leaking into the general promotions the marketing team runs.
One reseller, up to five live codes
Resellers can run several codes in parallel — a cap of five active at a time — each with its own window and its own status. Every card carries the same ticket-stub shape as a physical coupon: a small, deliberate echo of what a promo code actually is.
What the old logic paid for
The original rule paid 10% commission the moment a booking reached PAH — Pay at Hotel — status. That's an intent signal, not a fact: the guest hadn't checked in, hadn't paid, hadn't necessarily existed as a real stay at all.
At the scale of 8 million registered resellers, that gap didn't stay theoretical. A subset of resellers learned they could generate PAH bookings that would never convert into an actual check-in, collect the commission trigger anyway, and repeat it. No single case looked dramatic — but multiplied across the base, the leak became a recurring, structural loss.
Moving the trigger from intent to fact
The redesign moves commission eligibility from a booking event to a verified stay event: commission is only released once the guest has actually checked in at the property. It's a one-line change in principle — pay for a stay, not for a booking — but it closes the exploit without touching legitimate resellers' earnings.
Paired with the logic change, reseller onboarding now runs eKYC through Xendit, verifying each reseller's KTP (Indonesian national ID) at signup. Gating commission on a real check-in closes the exploit; gating accounts on a verified identity makes it far harder to route the same pattern through duplicate or fake reseller profiles.
ID Verified · Xendit eKYCThe payout side was rebuilt to make each state legible instead of a single opaque number:
Giving resellers something to actually read
A trust fix that no one can see doesn't build trust. Alongside the backend change, the dashboard was rebuilt so resellers can watch their own performance instead of waiting on a lump sum.
The product operations layer underneath all of it
None of the above ships as a single engineering ticket — it's a product operations problem: the same reseller base, the same booking data, and the same commission ledger were running through four disconnected flows, each with its own edge cases, its own manual checks, and its own way of quietly hiding fraud. The work was as much about removing steps as adding them.
Every one of these was a standing operational cost before it was a fraud problem: ops manually reconciling PAH bookings against actual stays, support fielding "where's my commission" tickets because the payout logic wasn't visible anywhere, and no single naming convention to separate an affiliate discount from a market promo. Simplifying the reseller-facing product and closing the fraud gap turned out to be the same exercise — fewer manual touchpoints meant fewer places for the exploit to hide, and a clearer surface for the reseller to trust.
Ops‑to‑ProductFive workstreams — a stacking rule, a fraud fix, a verified-identity requirement, a dashboard rebuild, and the operational simplification underneath all of it — that only work as a system when read together: the incentive (commission), the trigger (a real check-in), and the identity behind it (a KYC'd reseller) all point the same direction, running through one simplified flow instead of four.