first commit

This commit is contained in:
ray zhou
2026-05-21 18:16:26 +08:00
commit 033aa0ae69
324 changed files with 24705 additions and 0 deletions

View File

@@ -0,0 +1,327 @@
Online Gambling in the US | State Rules & Market Outlook
0
https://www.iannefieldsstewart.com/wp-content/themes/twentytwentyone
Close
Search Results
Menu
Online Slots
Online Casinos & Bonuses
Guides and News
Slot Providers
© 2026 Slots2Win
Ім'я користувача або Адреса електронної пошти
Пароль
Only fill in if you are not human
Keep me signed in
# The Complex Landscape of US Online Gambling: Stakes Path, State Rules, and the Future of Digital Betting
Release Date:
September 15, 2025
|
Author:
Casino
The US online gambling map is a mosaic: federal rules set the outer frame, while each state paints its own picture of what is allowed, how it is taxed, and who may operate. Since the 2018 repeal of PASPA, momentum has shifted toward broader sports betting adoption and measured expansion of iGaming (online casino), but progress is uneven. Stake, a crypto-forward operator known for rapid payouts and a global audience, embodies both the upside and friction of the US. The upside is a high-value, tech-literate player base across large states; the friction is licensing, payment scrutiny, and divergent state policies on iGaming and crypto. Success depends on meticulous compliance, state partnerships, responsible-gambling leadership, and adaptable product design that can function with or without native crypto rails.
## What is Stake and why does it matter now
Stake grew globally by pairing a fast, modern UX with cryptocurrency rails, a wide slate of casino titles and sportsbook markets, and aggressive brand marketing. In the US, the playbook must be adapted: Licensing must be state-by-state, often via market-access deals with existing land-based or tribal properties. Payments must satisfy rigorous KYC/AML, source-of-funds checks, and transaction monitoring. Product must incorporate responsible-gambling tools and observability that satisfy auditors and regulators. Crypto may require guarded, hybrid approaches (e.g., fiat front ends with compliant crypto settlement where allowed, or delayed on-chain features) depending on state policy and evolving federal guidance.
## The legal backbone: federal statutes that still shape online betting
While states grant the practical permission to operate, several federal laws continue to influence design and risk:
- Wire Act (1961): Restricts interstate transmission of bets/wagering information. Interstate routing must be controlled; geofencing and in-state data paths remain critical engineering concerns.
- UIGEA (2006): Targets payment processing for unlawful internet gambling. It doesnt define “unlawful”—states do—but compels banks, processors, and operators to build filters and monitoring.
- Bank Secrecy Act / AML frameworks: Require KYC, suspicious activity reporting (SARs), enhanced due diligence (EDD) for higher-risk customers, and robust recordkeeping.
- Consumer & data privacy laws: Operators must comply with frameworks that govern data retention, security, and user rights; in practice, this pushes for privacy-by-design architectures and vendor audits.
## The fifty-state puzzle: how state law fragments the market
Post-PASPA, states can legalize sports betting and, separately, iGaming (online casino). The result is four common categories: 1) Sports betting only (mobile and/or retail). 2) Sports betting + iGaming (full online casino). 3) Retail-only betting (physical sportsbooks). 4) No betting authorized.
Licenses, skins, tax rates, eligible partners, and marketing restrictions vary. Some states cap the number of mobile “skins” per land-based licensee; others enable broader competition. Age thresholds, self-exclusion systems, and RG (responsible gambling) messaging may be standardized in one state and highly bespoke in another.
## State snapshots
Below is an illustrative, non-exhaustive snapshot of pivotal US states that collectively define the near-term ceiling for market growth.
1. California (CA) Status: No statewide mobile sports betting or iGaming currently authorized. Multiple 2022 ballot propositions failed. Dynamics: Strong tribal sovereignty, complex negotiations over market access, revenue sharing, and regulatory oversight. Outlook: California remains the largest unserved online market; any legalization will be transformative but politically difficult.
2. New York (NY) Status: Mobile sports betting live; rapid scale since 2022. iGaming not yet legalized. Key friction: High tax on sports betting gross gaming revenue (GGR) has pressured margins; operators respond via promotional restraint and product optimization. Outlook: iGaming proposals resurface regularly. If enabled, NY could become a top-three online casino market overnight.
3. Texas (TX) Status: Sports betting not authorized statewide; recurring legislative interest but hurdles remain. Drivers: Population scale, pro-sports culture, and major ownership groups provide momentum; conservative policy currents slow progress. Outlook: A prize market; legalization timing uncertain.
4. Florida (FL) Status: Tribal compact litigation and negotiations have defined recent years; mobile betting availability has fluctuated. Outlook: Continued evolution possible via compact pathways; iGaming remains a separate, longer-term question.
5. New Jersey (NJ) Status: Mature online market for both sports betting and iGaming; robust set of licensed operators. Best practices: Strong compliance culture, vendor certification pathways, and a large, data-rich ecosystem enable sophisticated CRM and RG tooling. Outlook: Stable growth with periodic product innovation.
6. Michigan (MI) Status: Sports betting and iGaming live; modern framework and multi-operator environment. Outlook: Competitive but rational market; responsible-gambling technology is a differentiator.
7. Pennsylvania (PA) Status: Sports betting and iGaming live; comparatively high tax rates on certain verticals. Outlook: Healthy demand; operators must offset tax drag with retention, product depth, and cost discipline.
## Licensing, taxes, and fees: how the dollars and rules stack up
Typical cost components for a new state entry
- Market-access fee: Payment or rev-share to a land-based partner (casino, racetrack, or tribal entity).
- License application & renewal: State filing fees, investigative costs, and annual renewals.
- Compliance tooling: Geolocation, identity verification, AML transaction monitoring, fraud scoring, and RG platforms.
- Technical certifications: Gaming labs (e.g., RNG, sports models, wallets), ongoing change-management costs.
- Taxes: GGR taxes vary by product (sports vs. iGaming) and by state.
Illustrative state taxation table (indicative ranges; exact rates vary)
| Category | Sports Betting GGR Tax (Typical Range) | iGaming GGR Tax (Typical Range) |
| --- | --- | --- |
| Low to Moderate | 10% 20% | 12% 20% |
| Moderate to High | 20% 36% | 20% 40% |
| Very High | ≥ 36% | ≥ 40% |
Key takeaway: High tax regimes push operators to optimize promo spend, shift to higher-margin products, and intensify retention rather than acquisition.
## Payments, crypto, and compliance (KYC/AML)
Payments stack today: ACH, debit, credit (where allowed), online banking, instant bank transfer, prepaid cards, and e-wallets dominate. Crypto reality: Because US frameworks remain cautious, many operators default to fiat rails even if they support crypto abroad. Where crypto touches the stack, custody, travel-rule compliance, and on/off-ramp partners require rigorous due diligence.
KYC/AML pillars: Identity proofing: Document checks, facial liveness, sanctions/PEP screening, and continuous monitoring. Source-of-funds triggers: Automatically escalate for high deposit velocity, unusual behavior, or on-chain signals. Transaction monitoring: Rules + machine learning for pattern detection; SAR filings for suspicious activity. Recordkeeping: Immutable audit logs, role-based access, and defensible privacy controls.
## Responsible gambling, consumer protections, and marketing limits
Modern US regulators expect operators to go beyond minimums: RG tooling: Deposit, loss, session, and time limits; reality checks; cool-off and self-exclusion; friction-light but effective UX. Data signals: Real-time markers of harm (e.g., chasing losses, night-time binge patterns) trigger proactive, tiered interventions. Marketing: Clear T&Cs, no targeting self-excluded or under-21 users, offer-cap discipline, and transparency on bonus wagering requirements. Support: 24/7 channels, multilingual service, and direct links to helplines and counseling resources.
## Product & UX: what competitive US products look like today
Sportsbook: Deep markets, same-game parlays, early cash-out, in-play latency control, personalized odds carousels. iGaming: Diverse library (slots, live dealer, RNG table games), episodic jackpots, low-latency streaming, high availability (four-nines+). Wallet: Instant deposits/withdrawals where possible, fee transparency, intelligent payment routing. Observability: Real-time risk dashboards, laddered limits, automated geofence alerts, and end-to-end tracing for audits. Accessibility: WCAG-aligned design; mobile-first interactions and battery-friendly animations.
## California spotlight: the biggest prize and the toughest gridlock
Californias potential remains unmatched: nearly 40 million residents, multiple pro-sports franchises, and a tech-sophisticated audience. But legalization has been constrained by competing visions among tribes, commercial operators, and other stakeholders over who controls digital rights, how revenue is split, and which regulator has primary oversight. Any future path likely hinges on a negotiated ballot initiative or a compact-driven framework that respects tribal sovereignty while defining clear, consumer-safe rules for mobile wagering. For a crypto-savvy brand, the first order of business would still be market access, fiat-ready payments, and conservative RG—with crypto features on a roadmap paced by policy.
## Business scenarios for Stake in the US (2025-2030)
Scenario A Hybrid compliance leader (most probable): Stake pairs fiat-first US products with optional, regulator-approved crypto components as rules mature. It partners with land-based brands for access; invests in AML/RG tech leadership; enters a handful of iGaming states and several major mobile-betting states; and sets the standard for real-time observability and payouts.
Scenario B iGaming breakthrough: A wave of iGaming legalization (e.g., NY, CA, additional populous states) expands TAM dramatically. Stake leverages its casino UX depth and VIP-club playbooks to scale quickly via joint ventures and data-driven retention.
Scenario C Regulatory choke (downside): Tighter views on crypto rails, sustained high sports-betting taxes, and limited iGaming expansion compress margins. Stake focuses on a smaller footprint with premium retention, high-trust payouts, and esports-adjacent content while waiting for policy tailwinds.
## Market size projections and revenue drivers
Illustrative projections (industry-style model, 2025-2030)
| Year | States w/ Mobile SB* | States w/ iGaming | US Online GGR (Sports + iGaming) | Notes |
| --- | --- | --- | --- | --- |
| 2026 | ~3236 | ~810 | $23$30B | Incremental state adds; ARPU grows with product depth |
| 2027 | ~3438 | ~912 | $26$34B | iGaming expansion boosts margin mix |
| 2028 | ~3540 | ~1014 | $28$38B | Marketing efficiency and RG tech drive sustainable growth |
| 2029 | ~3641 | ~1216 | $30$42B | Scale effects; improved cost of payments and fraud containment |
| 2030 | ~3742 | ~1418 | $33$47B | Upper range assumes one mega-state iGaming launch |
Revenue drivers & bottlenecks
Drivers: iGaming legalization, lower payment friction, data-driven personalization, VIP lifecycle management, and trust in fast withdrawals. Bottlenecks: Elevated tax regimes, advertising caps, strict bonus accounting, prolonged vendor approvals, and crypto policy ambiguity.
## Risks & mitigations checklist for operators
- Regulatory risk: Mitigate via early engagement, independent audits, transparent RG reporting, and conservative interpretations of ambiguous guidance.
- Payments & AML risk: Mitigate via multi-processor routing, dynamic risk scoring, travel-rule-compliant crypto partners, and automated SAR workflows.
- Operational risk: Mitigate via chaos-engineering drills, multi-region failover, live-ops playbooks, and quarterly model validations.
- Reputational risk: Mitigate via public RG dashboards, rapid dispute resolution, plain-English bonus terms, and third-party certifications.
- Competition risk: Mitigate via unique product formats, cross-vertical engagement (sports + casino), and loyalty programs that reward sustainable play.
## Opportunities for innovation (Web3, on-chain proofs, fintech rails)
- On-chain provably fair proofs: for game rounds and promotions increase transparency without exposing PII.
- Programmable payouts: (instant, rule-based withdrawals once risk checks pass) shorten wait times and build trust.
- Composable identity: (privacy-preserving credentials, age proofs) reduces friction during KYC while satisfying regulators.
- Wallet abstraction: allows users to benefit from crypto security without key-management complexity.
- Fine-grained RG telemetry: marries behavioral science with real-time data to prevent harm and reduce chargebacks.
## Glossary of key terms
- GGR (Gross Gaming Revenue): Wagers minus wins paid to players.
- iGaming: Online casino (slots, table games, live dealer).
- KYC/AML: Know-Your-Customer and Anti-Money-Laundering obligations.
- Market access: The contractual rights to offer an online “skin” in a state, often through a land-based partner.
- RG (Responsible Gambling): Policies and tools that reduce gambling-related harm.
- Skin: A branded online operator platform tied to a licensee within a state.
Conclusion
The US is both a marathon and a maze. For Stake and its peers, the winning formula is part legal strategy, part engineering discipline, and part user empathy. The legal strategy is about patient state-by-state entries, thoughtful partnerships, and transparent dialogue with policymakers. The engineering discipline is about ring-fenced wallets, auditable payments, bulletproof geofencing, and automated AML/RG that is explainable to auditors. The user empathy is about fair odds, honest promotions, fast payouts, and proactive harm reduction. California will remain the headline until its policy puzzle is solved; New York represents the “now” of scale with a chance at iGaming in coming years; Texas and Florida are strategic maybes; New Jersey, Michigan, and Pennsylvania are the laboratories of best practice. If the next five years deliver even a modest expansion of iGaming, a drop in payment friction, and clearer rules for crypto rails, the upper bound of industry projections comes into view. In that future, the operators that lead on compliance, care, and craft will win—not just the market, but the long-term trust that sustains it.
Written by:
Valeria M.
Release Date:
September 15, 2025
Last Updated:
September 15, 2025 | Valeria M.
FAQ
Browse through common questions and answers to gain deeper insights into this topic.
Is online casino legal everywhere in the US?
No. While sports betting has broader adoption, iGaming (online casino) is legal only in a smaller set of states. Always check with your states regulator to confirm the legality.
Why do tax rates vary so much across states?
Tax rates vary because each state balances revenue goals with consumer protection and competitiveness. Higher taxes can lead to reduced promotional offers and tighter margins for operators.
Can I use cryptocurrency to bet in the US?
The availability of cryptocurrency betting depends on state regulations and operator policies. Many platforms in the US default to fiat payment systems while cryptocurrency regulations are still evolving.
How do operators verify my location to ensure Im in a legal state?
Operators use geolocation services like GPS, Wi-Fi triangulation, and network signals to ensure players are within state boundaries. Betting from outside a legal state is restricted by law.
What responsible gambling tools should I expect on legal platforms?
Responsible gambling tools typically include deposit limits, time limits, self-exclusion, reality checks, and access to customer support. Many platforms provide proactive interventions to minimize harm.
Why is California such an important state for the online gambling market?
California is the largest unregulated market for online gambling in the US, with nearly 40 million residents. Its legalization of online betting would significantly impact national market share and set the precedent for other states.
How does the regulatory environment affect new operators entering the US market?
New operators face strict licensing requirements, high compliance costs, and must navigate the varying legal frameworks from state to state. These factors can create barriers to entry but also ensure that players are protected from fraud and unsafe platforms.
What are the key differences between sports betting and iGaming regulations?
Sports betting is generally more widely legalized and regulated than iGaming (online casinos). While most states that have legalized sports betting also regulate mobile and retail sportsbooks, only a select few have expanded to include online casinos.
What is market access, and why is it necessary for operators like Stake?
Market access refers to the legal ability for an online operator to offer its services in a specific state, often achieved through partnerships with land-based casinos or other local entities. Without market access, operators cannot legally accept bets or wagers from players in that state.
How do taxes affect the profitability of online gambling operators?
Higher tax rates on gross gaming revenue (GGR) can reduce profit margins for operators. This forces them to adjust business models by limiting promotional offers, improving customer retention, and optimizing operational costs to stay profitable.
Similar Articles
When two powerful gods collide, you kind of expect something epic is about to happen.
[Unibet Owner: Net Worth and Profits](https://www.iannefieldsstewart.com/news/unibet-owner/)
Release Date:
December 10, 2025
|
Author:
[Who is the Stake Owner? Founders of Stake Casino Reveal](https://www.iannefieldsstewart.com/news/who-owns-stake-casino/)
Release Date:
November 18, 2025
|
Author:
[Gambling License Cost: A Guide to Fees and Requirements](https://www.iannefieldsstewart.com/news/gambling-license-cost/)
Release Date:
November 14, 2025
|
Author:
Release Date:
November 14, 2025
|
Author:
Release Date:
November 14, 2025
|
Author:
[Curacao Gambling License in The iGaming Industry](https://www.iannefieldsstewart.com/news/curacao-gaming-license/)
Release Date:
November 14, 2025
|
Author:
Popular
Author:
[Unibet Owner: Net Worth and Profits](https://www.iannefieldsstewart.com/news/unibet-owner/)
Author:
[Who is the Stake Owner? Founders of Stake Casino Reveal](https://www.iannefieldsstewart.com/news/who-owns-stake-casino/)
Author:
[Gambling License Cost: A Guide to Fees and Requirements](https://www.iannefieldsstewart.com/news/gambling-license-cost/)
Author:
Online Slots
Online Casinos & Bonuses
Guides and News
Slot Providers
Menu
LOGIN TO YOUR ACCOUNT
Only fill in if you are not human
Keep me signed in
SIGN UP
The username must be no shorter than 3 characters.
The password must be no shorter than 8 characters and consisting of letters, numbers and other symbols.
Receive email notifications about new slots, promotions and other activities.
By registering you are certifying that you are over the age of 18.
By registering you are certifying that you have reviewed and accepted our updated [Terms & Conditions](https://www.iannefieldsstewart.com/terms-and-conditions/), [Privacy](https://www.iannefieldsstewart.com/privacy/) and Cookie Policy.
Only fill in if you are not human

View File

@@ -0,0 +1,563 @@
US iGaming Compliance Checklist for Operators | Before Launch
[Online Casino Software Development Cost in 2026](https://sdlccorp.com/post/how-much-does-it-cost-to-develop-casino-software/) [Read More »](https://sdlccorp.com/post/how-much-does-it-cost-to-develop-casino-software/)
[Top Online Poker Software Providers in the USA (2026)](https://sdlccorp.com/post/top-online-poker-software-providers-usa/) [Read More »](https://sdlccorp.com/post/top-online-poker-software-providers-usa/)
# US iGaming Compliance Checklist: What Operator Need Before Launch
- [Michael Klein](https://sdlccorp.com/post/author/micheal/)
- Last Updated : March 31, 2026
### Table of Contents
US iGaming compliance is easier to manage when you treat it as a product problem, not a legal task left for the end. A launch is only ready when identity checks, location controls, wallet flows, responsible gambling tools, and reporting rules work the way your approved state scope says they should.
This guide is for operator teams, product owners, engineering leads, payments teams, and compliance managers preparing for launch. It focuses on what you need to map, build, test, document, and prove before real-money traffic goes live.
Quick answer: a US iGaming launch is ready when state scope is locked, KYC and geolocation are enforced before money or play, AML monitoring links identity to wallet and gameplay, responsible gambling controls work at platform level, and your logs can reconstruct any player session on demand.
## What launch-ready looks like
You are launch-ready when you can:
- Explain exactly which states, products, partners, and channels are in scope.
- Show that KYC, age checks, geolocation, AML, and responsible gambling work end to end.
- Export clear audit trails with stable IDs, timestamps, and change history.
- Show who owns each control, who approves changes, and how failures are escalated.
## Build your jurisdiction matrix first
Do not start with a “default” national flow. Start with a jurisdiction matrix. In the US, the rule set is different enough by state that late patching creates avoidable risk in onboarding, payments, marketing, and reporting.
As of March 2026, legal online casino play is live in New Jersey, Pennsylvania, Michigan, Connecticut, West Virginia, Delaware, and Rhode Island. Maine has authorized internet gaming, but rollout still depends on rulemaking and licensing. That means your market map should cover both live states and near-term expansion states from day one.
If you are still comparing launch order and approval workload, our guide to [securing a gambling license for online casino apps](https://sdlccorp.com/post/how-to-secure-a-gambling-license-for-online-casino-apps/) is the best follow-on read.
Each state line in the matrix should include:
- Product scope: casino, poker, sportsbook, or a limited mix.
- Operating model: commercial, tribal, lottery-led, or partner-based.
- Age and identity rules: onboarding depth, hard blocks, manual review, and re-verification triggers.
- Geolocation rules: when checks run, when they repeat, and how border cases are handled.
- Wallet and payment limits: deposits, withdrawals, payment methods, and exception handling.
- Responsible gambling rules: limits, cooling-off, self-exclusion, reality checks, and enforcement scope.
- Reporting and incident duties: who gets notified, when, and with what evidence.
- Vendor constraints: approved labs, KYC tools, geo vendors, PSPs, and hosting limits.
### US iGaming state overview
New Jersey
Market status
Live market
Primary regulator
New Jersey Division of Gaming Enforcement
Operating model
Mature commercial market linked to Atlantic City casino structure
What changes in your build
Expect high operator variety, strong change control, and clear approval paths for sites, games, and vendors.
Pennsylvania
Market status
Live market
Primary regulator
Pennsylvania Gaming Control Board
Operating model
Commercial market with major scale and strict oversight
What changes in your build
Plan for heavy event volume, strong audit discipline, and clean handoffs between operator, platform, wallet, and reporting teams.
Michigan
Market status
Live market
Primary regulator
Michigan Gaming Control Board
Operating model
Commercial and tribal participation
What changes in your build
Support multiple partner models and keep separation of duties clear across operator, vendor, and tribal workflows.
Connecticut
Market status
Live market
Primary regulator
Connecticut Department of Consumer Protection
Operating model
Limited operator framework
What changes in your build
Fewer operators means less room for loose governance. Vendor control, onboarding quality, and player-protection proof need to be clean.
West Virginia
Market status
Live market
Primary regulator
West Virginia Lottery
Operating model
Smaller regulated market
What changes in your build
Do not treat it as a light version of compliance. Geo, payments, and audit controls still need full launch readiness.
Delaware
Market status
Live market
Primary regulator
Delaware Lottery
Operating model
Centralized lottery-led model
What changes in your build
Reporting, platform behavior, and operational controls should align to a more centralized oversight style.
Rhode Island
Market status
Live market
Primary regulator
Rhode Island Lottery and related state oversight
Operating model
Single-operator structure with centralized oversight
What changes in your build
Geo, age checks, and responsible gambling tools need to work cleanly from day one because the operating model leaves little room for inconsistency.
Maine
Market status
Authorized, not live yet
Primary regulator
Rulemaking and licensing implementation pending
Operating model
Internet gaming authorized in January 2026 but not launched
What changes in your build
Use Maine as a feature-flag state for now: keep geo boundaries, reporting hooks, and onboarding logic ready, but do not assume launch timing until the rules are final.
## Assign control ownership early
Strong control design starts with ownership. A checklist is not enough if nobody owns the live workflow behind it.
Compliance should own rule interpretation and regulator response. Engineering should own control logic, event logging, and evidence exports. Payments teams should own cashier risk, settlement, chargebacks, and exception review. Support should own self-exclusion handling, player messaging, and escalation paths.
Keep approvals simple but strict: define who can change limits, risk rules, payout settings, and vendor configurations, then make those changes visible in audit history.
## Go-live controls that must work end to end
Licensing and scope
What should be live before launch
Lock states, products, channels, skins, and partners in configuration. Only approved scope should be enabled in production.
Evidence you should be able to export
Versioned state matrix, approval history, partner mapping, and environment snapshots.
Failure that usually delays launch
A default flow that quietly enables unsupported states, features, or channels.
Identity and age checks
What should be live before launch
Complete KYC paths for pass, fail, retry, and manual review. Enforce age checks before funding or play.
Evidence you should be able to export
Decision logs, document outcomes, reviewer actions, timestamps, and retention references.
Failure that usually delays launch
Treating KYC as a front-end form instead of a control with traceable decisions.
Geolocation
What should be live before launch
Check location at login, before money movement, before play, and again when confidence changes.
Evidence you should be able to export
Method used, confidence signal, state result, denial reason, re-check trigger, and player message.
Failure that usually delays launch
Letting a player stay active when location cannot be confirmed.
Wallet and payments
What should be live before launch
Use an authoritative ledger, idempotent payment handling, and clear reversal and exception logic.
Evidence you should be able to export
Transaction trail, reconciliation reports, webhook history, and adjustment approvals.
Failure that usually delays launch
Double credits, silent failures, and manual fixes that do not leave a clean record.
AML and fraud monitoring
What should be live before launch
Stream identity, wallet, device, and gameplay signals into one case workflow with reason codes.
Evidence you should be able to export
Alert history, rule versions, reviewer identity, case notes, and exportable reports.
Failure that usually delays launch
A risk process that looks at deposits only and misses the wider account pattern.
Responsible gambling
What should be live before launch
Enforce limits, cooling-off, and self-exclusion in shared platform services, not only in the UI.
Evidence you should be able to export
Limit history, exclusion lifecycle, blocked-action logs, and promotion suppression records.
Failure that usually delays launch
A restricted player finding another app, skin, or channel where the control is not active.
Audit trail and change control
What should be live before launch
Keep structured, append-only core events and require approvals for sensitive config changes.
Evidence you should be able to export
Player, session, transaction, and correlation IDs; release notes; rule versions; build history.
Failure that usually delays launch
Being unable to explain which build or rule version was live when a decision was made.
## Use GLI-19 as a proof framework
Many jurisdictions and labs use GLI standards as a starting point for interactive gaming controls. Use GLI-19 the same way your internal reviewers will use it: as a proof framework that asks whether you can explain, trace, and reconstruct what happened.
The fastest way to fail a review is to have a control that exists in a policy file but does not leave usable evidence in the product.
Use these questions before certification and before go-live:
- Can you reconstruct a player session from login to wager to payout?.
- Can you tie an admin or configuration change to a person, approval, and timestamp?.
- Can you replay wallet balances and transaction history without gaps?.
- Can you show which rule version or configuration was active at the moment a decision was made?.
### Logging coverage to support
Good logs answer reviewer questions quickly. They are structured, consistent, and easy to export. They do not rely on screenshots, free-text notes, or one team remembering what another team changed.
- Player lifecycle events: registration, verification changes, lockouts, and account status.
- Session events: login, logout, timeout, device change, and error state.
- Wallet events: deposits, withdrawals, reversals, balance changes, bonuses, and adjustments.
- Gameplay events: game launch, wager request, wager result, interruption, and resettlement.
- Risk and control events: AML alerts, geolocation outcomes, responsible gambling actions, and payment exceptions.
- Admin and release events: configuration edits, approvals, build versions, and release timestamps.
## Geolocation evidence
Geolocation is not just a pass-or-fail gate. It is proof that you enforced state boundaries at the right moments and handled uncertainty the right way.
### When to check location
Run geolocation checks when access, money movement, or wagering risk changes:
- At login or session start.
- Before deposits and withdrawals.
- Before the first wager or gameplay session.
- During play at sensible intervals, especially near borders or after network changes.
- Whenever device, browser, network, or GPS signals change in a way that affects confidence.
### What to keep for review
Store the decision result, method used, confidence or quality signal, state outcome, reason for denial, re-check trigger, and the exact message shown to the player. If location cannot be confirmed, block the regulated action and show a next step that helps the player fix the issue instead of guessing.
For a broader view of recurring launch issues, see our article on [regulatory compliance challenges in the iGaming industry](https://sdlccorp.com/post/regulatory-compliance-challenges-in-the-igaming-industry/).
## AML signals
AML monitoring works best when identity, wallet, and gameplay signals meet in one pipeline. Looking at deposits alone leaves too much context behind.
Build one event stream that normalizes signals from KYC, cashier, gameplay, device, and account behavior. Score activity with rules or models, create a clear case workflow, and preserve the reason codes and reviewer actions that explain each outcome.
- Identity events: registration, login changes, document reviews, manual review outcomes, and device changes.
- Wallet events: deposit attempts, failures, successes, withdrawals, reversals, chargebacks, and unusual funding patterns.
- Gameplay events: wager spikes, unusually short sessions, rapid balance swings, and bonus-related patterns.
- Case events: alert creation, reviewer assignment, escalation, disposition, and report export.
## Responsible gambling at the platform layer
Responsible gambling controls should live in the platform and wallet layer, not only in the interface. If a user can bypass a limit by switching surface, skin, or device, the control is not finished.
- Deposit, loss, and session limits with clear timing logic.
- Cooling-off tools and full self-exclusion workflows.
- Reality checks and clear status messages at the right moments.
- Suppression rules for bonuses, marketing, and reactivation attempts when a player is restricted.
Keep the full history: requests, approvals, effective dates, enforcement logs, and every blocked action tied to the rule that triggered it.
## Audit trails that stand up to review
Auditors usually ask one simple question: can you reconstruct what happened? Build your audit model to answer that fast.
Use stable player, session, transaction, and correlation IDs across services. Keep timestamps consistent, keep core events append-only, and store rule versions and build versions with the decisions they shaped.
Teams building a new stack from scratch can also review our [iGaming software development](https://sdlccorp.com/services/games/igaming-software-development/) overview to map account, wallet, and game services cleanly before launch.
## Final pre-launch drill
The final two weeks before launch should feel like a controlled pressure test, not a content review. Test real failure paths, not only happy paths.
- Confirm state scope and partner configuration in the live release candidate.
- Test KYC pass, fail, retry, manual review, and timeout paths.
- Test geolocation near borders, on weak signals, and after device or network changes.
- Test deposit, withdrawal, reversal, and exception flows in the cashier.
- Test responsible gambling limits, cooling-off, self-exclusion, and blocked-action messaging.
- Run an audit export drill: one player, one session, one payment trail, one admin change, one risk case.
- Verify who gets alerted when a control fails and how quickly the issue is contained.
After launch, review thresholds, admin access, payment exceptions, vendor health, and blocked-user events every week. Most compliance drift starts after launch, not before it.
## Conclusion
US iGaming launches go well when the control design is clear before traffic starts. Lock the state matrix first, connect KYC to geolocation and wallet flows, enforce responsible gambling at platform level, and make sure your logs can explain every decision without guesswork.
## FAQs
How many US states have legal online casino play right now?
As of March 2026, legal online casino play is live in New Jersey, Pennsylvania, Michigan, Connecticut, West Virginia, Delaware, and Rhode Island. Maine has authorized internet gaming, but it is not live yet because rulemaking and licensing still need to be completed.
What does state-by-state compliance mean in practice?
It means one national rule set is not enough. You need a versioned matrix that maps product scope, onboarding rules, geolocation logic, responsible gambling controls, reporting duties, and approved vendors for each state you serve.
What logs matter most before go-live?
Keep logs that let you reconstruct player identity decisions, session flow, geolocation outcomes, wallet movement, gameplay events, admin actions, rule versions, and release history. If a reviewer cannot follow the sequence quickly, the log is not good enough yet.
What geolocation evidence should operators store for audits?
Store the result, method, confidence signal, denial reason, re-check trigger, state outcome, and the exact player-facing message. The goal is to show not just that a control fired, but why it fired and what happened next.
How do KYC and AML work together in iGaming?
KYC defines what you know about the player and what activity you allow. AML monitors how that account behaves over time. The two work best when identity, payments, device data, and gameplay signals feed one case workflow.
Which responsible gambling controls must work at platform level?
Deposit limits, loss limits, cooling-off, self-exclusion, and blocked-user suppression should all be enforced in shared platform and wallet services. That prevents players from bypassing controls by switching app, channel, or skin.
### ABOUT THE AUTHOR
#### Michael Klein
#### iGaming Expert
Michael Klein is an iGaming expert with 18 years of experience in the gaming industry. He helps businesses innovate and scale by applying cutting-edge strategies and technologies that drive growth, enhance player experiences, and optimize operations in the ever-evolving iGaming landscape.
PLAN YOUR SOLUTION
Name
Email
Number
Budget
Under $25,000$25,000 $75,000$75,000+
Project Description
Solve this Equation
Discuss Your Project
## More Insights You Might Find Useful
Explore expert perspectives, practical strategies, and real-world solutions related to this topic.
- [Michael Klein](https://sdlccorp.com/post/author/micheal/)
- April 20, 2026
### Reliable Affiliate Management Software for iGaming Operators: What to Look For
Reliable affiliate management software for iGaming operators should give operators
- [Sudhanshu Tamboli](https://sdlccorp.com/post/author/sudhanshu/)
- April 14, 2026
### SDLC Corp Redefines Workforce Intelligence with Launch of Advanced HRMS Dashboard on Odoo
SDLC Corp has announced the launch of its Advanced HRMS
- [Akash Golde](https://sdlccorp.com/post/author/akash-golde/)
- April 14, 2026
### The Hidden Cost of Managing WooCommerce and Odoo Separately
WooCommerce Odoo Integration: Hidden Costs of Running Systems Separately Disconnected
- Contact Us
## Lets Talk About Your Product
Get expert guidance on scope, architecture, timelines, and delivery approach so you can move forward with confidence.
### What happens next?
- We review your requirements
- Strategy call with experts
- Clear roadmap & estimate
- NDA Protected
- Enterprise Grade Delivery
- Global Clients
Name
Email
Number
Budget
Under $25,000$25,000 $75,000$75,000+
Project Description
Solve this Equation
Discuss Your Project
## Awards & Recognition
We are honored to receive recognition for our excellence from leading publications worldwide.
##### Contact Us
For Sales Enquiry email us a
For Job email us at
United States:
Transform Digital LLC 44 Montgomery Street, Suite 300 San Francisco, CA 94104
United Kingdom:
30 Charter Avenue, Coventry CV4 8GE Post code: CV4 8GF United Kingdom
United Arab Emirates:
Unit No: 729, DMCC Business Centre Level No 1, Jewellery & Gemplex 3 Dubai, United Arab Emirates
India:
715, Astralis, Supernova, Sector 94 Noida, Delhi NCR India. 201301
Qatar:
B-ring road zone 25, Bin Dirham Plaza building 113, Street 220, 5th floor office 510 Doha, Qatar
Services
- [Sports Betting App Development](https://sdlccorp.com/services/games/sports-betting-app-development-company/)
- [Casino Game Development](https://sdlccorp.com/services/games/casino-game-development-company/)
- [Poker Game Development](https://sdlccorp.com/services/games/poker-game-development-company/)
- [Ludo Game Development](https://sdlccorp.com/services/games/ludo-game-development-company/)
Solutions
Resources
Company & Legal
- [About Us](https://sdlccorp.com/about-us/)
- [Contact Us](https://sdlccorp.com/contact-us/)
- [Privacy Policy](https://sdlccorp.com/privacy-policy/)
- [Terms & Conditions](https://sdlccorp.com/terms-and-conditions/)
© COPYRIGHT 2025 - SDLC Corp - Transform Digital DMCC
2026 EDITION
Global
iGaming Comprehensive
Guide
Master the future of digital gaming with exclusive data, regulatory updates, and emerging market trends.
Trusted by 5000+ Leaders

View File

@@ -0,0 +1,317 @@
Internet Gaming and Sports
Betting FAQs For
Businesses
Licensing
Q: I am a business owner and would like to be licensed by the MGCB to provide services
for internet sports betting and/or online betting. What do I need to do?
A: The MGCB has published application forms for online sports betting and internet gaming on
its website. You will find links to forms on the Internet Gaming and Fantasy Contests page.
If you are uncertain whether you require a license or registration, please complete and submit a
Supplier Inquiry Form. Upon receipt of this form, a licensing coordinator will contact you to
discuss licensing requirements.
Independent Test Labs
Q: Do independent test labs require approval by the Michigan Gaming Control Board?
A: Yes, an independent test lab (ITL) must be approved by the MGCB before software or
hardware manufacturers can submit their products for ITL review. The manufacturers are
required to send only approved ITLs certification letters to the MGCB Gaming Lab. The MGCB
Gaming Lab will conduct a review of the ITLs systems and capabilities prior to approving an
ITL.
Q: Are ITLs required to be licensed to provide ITL services to a software/hardware
manufacturer, and/or an internet gaming operator/platform provider, internet sports
betting operator/platform provider
A: Yes.
Equipment
Q: Can an internet gaming and/or internet sports betting supplier license applicant ship
equipment (ex., blank servers, switches, routers, etc.) to a Michigan facility (i.e., data
center or casino)?
A: An internet gaming and/or internet sports betting supplier license applicant is not prohibited
from shipping equipment to a Michigan facility prior to receiving a license for the purpose of
preparing for the launch of internet gaming and/or internet sports betting in Michigan, provided
both of the following conditions are met:
(1) No gaming software is installed in the live gaming or production environment unless
approved by the MGCB or used only to conduct limited testing in accordance with the conditions
established below.
(2) The equipment will not be used for internet gaming and/or internet sports betting until the
internet gaming and/or internet sports betting operator is licensed and authorized by the MGCB
to go live.
The shipment of equipment prior to licensure will have no bearing on the MGCBs decision to
grant or deny an applicants request for a license. In the event an applicant does not receive a
license for any reason, the MGCB assumes no liability.
Q: May operators and platform providers perform very limited testing in the production
environment, primarily to test setup and integrations to ensure the production
environment is fully functional, provided that the production environment has no
external exposure until the approved go-live date and time?
A: Yes, provided all of the following conditions are met:
(1) There are no alternative means to perform the testing in a test environment that mirrors the
production environment.
(2) Testing will be performed by operator or platform provider personnel and their identified
designees who have read and agreed to all test account protocols established by the operators
or platform providers internal controls in accordance with the administrative rules.
(3) Testing will be performed on a secure and separate VPN identified only for the purposes of
the limited testing.
(4) The purpose and scope of the limited testing must be documented, and sufficient records of
all testing must be maintained.
(5) The production environment is used only for the purposes of the limited testing.
(6) The test case must have a specific open and ending time which must be reasonable to the
amount of time needed to perform testing. As an alternative, the operator or platform provider
must closely apprise the board of testing open and ending times.
(7) The production environment used for limited testing must not have any external or public
exposure.
(8) The operator or platform provider must have strict procedures in place to ensure that the
production environment used for limited testing does not have any external or public exposure.
(9) On completion of testing, all test data must be properly identified and segregated or deleted
from the production environment.
This allowance shall have no bearing on the MGCBs decision to grant or deny an applicants
request for a license. In the event an applicant does not receive a license for any reason, the
MGCB assumes no liability.
Branding Requirements
Q: What are the branding requirements for internet gaming?
A: Sec. 4(7) of the Lawful Internet Gaming Act, MCL 432.304(7), states: “An internet gaming
operator may offer internet gaming under a maximum of 2 separate brands, 1 for each of
interactive poker and other casino style games. This subsection does not prohibit an internet
gaming operator from using fewer than 2 brands or from using a single brand to offer any
combination of interactive poker or other casino style games. Only an internet gaming operator
or its internet gaming platform providers may process, accept, or solicit internet wagers under
this act. All websites and corresponding applications used to offer internet gaming must clearly
display the brand of the internet gaming operator or its affiliate. The internet gaming operator
may also elect, in its sole discretion, to have the brand of each internet gaming platform that it
utilizes be the name and logos or no more than 1 internet gaming platform provider if the
internet gaming platform also clearly displays the internet gaming operator's own trademarks
and logos or those of an affiliate. The internet gaming operator is responsible for the conduct of
its internet gaming platform provider.”
Q: What are the branding requirements for internet sports betting?
A: Sec. 4(7) of the Lawful Sports Betting Act, MCL 432.404(7), states: “A sports betting operator
may use no more than 1 internet sports betting platform to offer, conduct, or operate internet
sports betting. Only a sports betting operator or its internet sports betting platform provider may
process, accept, offer, or solicit internet sports betting wagers. The sports betting operator must
clearly display its own brand or that of an affiliate on the internet sports betting platform that it
utilizes. The sports betting operator may also elect, in its sole discretion, to have the brand of
the internet sports betting platform that it utilizes be the name and logos of no more than 1
internet sports betting platform provider if the internet sports betting platform also clearly
displays the sports betting operator's own trademarks and logos or those of an affiliate. A sports
betting operator is responsible for the conduct of its internet sports betting platform provider.”
Q: The acts establish requirements for the branding of internet gaming and internet
sports betting platforms. What does the platform include?
A: The platform is the integrated system of hardware, software, applications, including mobile
applications, and servers through which an operator operates, conducts, or offers internet
gaming or internet sports betting. The platform generally includes all mobile applications and
websites used to offer internet gaming or internet sports betting to authorized participants.
Operator Branding
Q: What brand must be displayed on each platform?
A: The operators own brand or that of an affiliate must be clearly displayed on each platform.
This applies regardless of whether the operator elects to include the name and logos of its
platform provider on the platform.
Q: Who is an affiliate?
A: An affiliate is a person that, directly or indirectly, through one or more intermediaries, controls
or is controlled by an operator.
Q: What is considered the operators own brand or that of an affiliate?
A: This includes the operators or its affiliates own name and any trademarks or logos
registered to or owned by the operator or its affiliate. Names, trademarks, and logos owned by a
person other than the operator or its affiliate are not considered the operators or its affiliates
own brand, regardless of whether the operator or its affiliate has acquired the rights to use such
names, trademarks, and logos.
Q: How must the operators or its affiliates own brand be displayed on each platform?
A: The operators or its affiliates own brand must be clearly displayed on each platform,
including on all mobile applications and websites used to conduct internet gaming or internet
sports betting. The operators or its affiliates brand must be distinctive, prominently featured,
and obvious and visible to the authorized participant.
Platform Provider Branding
Q: Can the operator also display its platform providers brand on the platform?
A: Yes. At the operators discretion, the name and logos of no more than one platform provider
may be displayed on each platform. However, each platform must also clearly display the
operators or its affiliates own brand.
Q: What constitutes a platform providers name and logos?
A: Any name and logos the platform provider owns or otherwise has the right to display on the
platform.
Q: Can the names and logos of multiple platform providers be displayed on a single
platform?
A: No. Each platform may display the name and logos of no more than one platform provider.
Q: If a platform provider owns or possesses the rights to use multiple names, can more
than one platform provider name be displayed on a single platform?
A: No. One platform provider name may be displayed on each platform.
Separate Branding
Q: Can an operator use separately branded mobile applications or websites to connect to
the same platform?
A: No. Each platform, inclusive of any mobile applications and websites, is limited to a single
brand. That brand must clearly include the operators or its affiliates own brand and may also
include the name and logos of no more than one platform provider.
Q: Can different brands be used to offer internet gaming?
A: Yes. If an operator utilizes separate platforms for interactive poker and other casino-style
games, each platform may, at the operators discretion, display a different brand. The brand of
each platform, including any mobile applications and websites, must clearly include the
operators or its affiliates own brand and may include the name and logos of no more than one
platform provider.
Q: How many separately branded platforms can an operator use?
A: An operator can utilize a maximum of three separately branded platforms one internet
sports betting platform, one internet gaming platform used to conduct interactive poker, and one
internet gaming platform used to conduct other casino style games. Each platform may display
a different brand, subject to the branding requirements outlined above.
Authorized Participant Accounts
Q: May operators and platform providers launch applications in the various app stores
prior to go live where authorized participants may download the app and create accounts
but would not be allowed to place any wagers until board approval is granted to launch?
A: Yes, provided the accounts are created in accordance with Part 5 of the internet sports
betting and/or internet gaming administrative rules, as applicable, and operators and platform
providers follow know your customer requirements. The board provides no guarantees
regarding licensing or any other necessary approval to launch.
Q: Can an operator or platform provider allow authorized participants to deposit funds to
their accounts prior to go live provided that no wagers will be placed or accepted until
the operator or platform provider receives board approval to launch?
A: Yes, subject to all of the following conditions:
(1) An authorized participant must establish an account before making a deposit. The account
must be created in accordance with Part 5 of the internet sports betting and/or internet gaming
administrative rules, as applicable, and the operator or platform provider must follow know your
customer requirements.
(2) The operator or platform provider must comply with all applicable provisions of the internet
sports betting and/or internet gaming administrative rules.
(3) The operator or platform provider and its payment processors must comply with applicable
state and federal law.
(4) The operator or platform provider must maintain sufficient records of all deposits.
(5) Authorized participants must be prevented from placing wagers until the operator or platform
provider is approved by the board to launch. The board provides no guarantees regarding
licensing or any other necessary approval to launch.
Advertising
Q: Can an operator and/or platform provider advertise its internet gaming and/or internet
sports betting products in Michigan?
A: Yes. Advertising, both before and after launch, is allowed. An operator or platform provider
does not need a license from the board to conduct advertising. The board provides no
guarantees regarding licensing or any other necessary approval to launch.
Q: What requirements apply to internet gaming and internet sports betting
advertisements?
A: Under the administrative rules and related technical standards, internet gaming and internet
sports betting advertisements cannot target self-excluded individuals. Advertisements directed
to the general public at large are not considered advertisements that target any specific
individuals, including those that may be self-excluded.
Q: Are there branding requirements for advertisements?
A: No. The statutory branding requirements, which are outlined above, apply to platforms only.
There are no branding requirements for advertisements.
Q: Are there any restrictions on the methods that can be used for internet gaming and
internet sports betting advertisements?
A: There are no restrictions on the methods that can be used to advertise internet gaming and
internet sports betting, subject to both of the following: (1) advertisements must not target selfexcluded individuals; and (2) a marketing affiliate licensed or registered by the board must not
promote or market illegal online gaming sites to individuals located in Michigan. Advertising can
be conducted via both traditional methods and social media.
Q: Is board approval of advertisements required?
A: No. Board approval of internet gaming and internet sports betting advertisements is not
required.
Q: A social media platform or other publisher has requested confirmation from the board
that a specific operator and/or platform provider is allowed to advertise, and that board
approval is not required. Can the board provide this confirmation?
A: Yes. Please email the request to hicksd8@michigan.gov.
Q: Are advertisers required to be licensed or registered with the Board?
A: If the advertiser is an affiliate marketer and has an agreement based on the sharing of customer
revenue, it must be licensed as a supplier. Affiliate marketers that do not have an agreement
based on the sharing of customer revenue must register with the Board as a vendor. “Affiliate
marketer” means a person involved in promoting, marketing, and directing business to online
gaming sites who is compensated based on the volume of customer referrals to an online gaming
site or customer activity, including but not limited to, number of registrations, number of depositing
registrations, or wagering activity, or both.
An advertiser, who is not an affiliate marketer, is not required to register if it provides less than
$100,000 worth of goods or services, or both, to any internet gaming/sports betting operator
(operator) or internet gaming/sports betting platform provider (platform provider) in connection
with its Michigan operation in a calendar year.
An advertiser, who is not an affiliate marketer, must register as a vendor if it provides more than
$100,000 worth of goods or services, or both, to any operator or platform provider in connection
with its Michigan operation in a calendar year. This applies to media buying agents and
advertisers who have contractual relationships with an operator or platform provider. This does
not apply to media outlets and other advertisers providing goods or services through a media
buying agent.
Bonuses and Promotions
Q: Can an operator or platform provider conduct internet gaming and/or internet sports
betting bonus and promotional wagering offers?
A: Yes. An operator or platform provider may conduct internet gaming and/or internet sports
betting bonus and promotional wagering offers. This includes any bonus or promotion that
involves internet wagers, internet sports betting wagers, internet wagering accounts, and/or
internet sports betting accounts. Examples may include, but are not limited to:
• Deposit bonuses.
• Risk free wagers.
• Loss refunds.
• Promotional odds or lines.
• Free wagers.
• Promotional drawings or raffles that involve internet wagers, internet sports betting
wagers, internet wagering accounts, and/or internet sports betting accounts (e.g., if an
authorized participant is required to have an internet wagering or internet sports betting
account to participate; if an authorized participant must conduct internet wagers or
internet sports betting wagers to earn entries; if an authorized participant can win
money, free play, or any other representation of value that will be deposited into their
internet wagering or internet sports betting account; etc.).
Q: What requirements apply to internet gaming and/or internet sports betting bonus and
promotional wagering offers?
A: Internet gaming and internet sports betting bonus and promotional wagering offers must
adhere to recordkeeping and operational requirements prescribed in the administrative rules
and related technical standards. See R 432.649(2)-(4) and R 432.749(2)-(5). These
requirements apply to all bonus and promotional wagering offers conducted after an operator or
platform provider launches internet gaming and/or internet sports betting in Michigan. In
addition, any bonus and promotional wagering offers initiated before launch that will be
completed after launch or will otherwise impact regulated internet gaming and/or internet sports
betting are expected to meet these requirements (e.g., if an authorized participant will receive
funds, free play, etc. once internet gaming and/or internet sports betting go live).
Please note that any bonus or promotional wagering offer that impacts or involves land-based
casino gaming at a Detroit casino may be subject to requirements of the Michigan Gaming
Control and Revenue Act and related rules.
Q: Can an operator or platform provider conduct a bonus or promotion that does not
involve internet wagering and/or internet sports betting wagering?
A: Bonuses and promotions that do not involve internet wagers, internet sports betting wagers,
internet wagering accounts, and/or internet sports betting accounts are outside the scope of the
Lawful Internet Gaming Act (LIGA), Lawful Sports Betting Act (LSBA), and related administrative
rules. Non-wagering bonuses and promotions are not regulated by the board under the LIGA,
LSBA, and related rules and generally are not subject to the requirements outlined above.
Operators and platform providers are responsible for ensuring that non-wagering bonuses and
promotions comply with all applicable laws and regulations (e.g., the Michigan Penal Code). In
addition, operators and platform providers must maintain records of all non-wagering bonuses
and promotions and provide such records to the board on request.
Please note that any bonus or promotion that impacts or involves land-based casino gaming at
a Detroit casino may be subject to requirements of the Michigan Gaming Control and Revenue
Act and related rules.
Q: Can an operator or platform provider conduct a promotional drawing or raffle?
A: Yes. An operator or platform provider can conduct a promotional drawing or raffle that
involves internet wagers, internet sports betting wagers, internet wagering accounts, and/or
internet sports betting accounts. Such drawings and raffles are regulated by the board under the
LIGA, LSBA, and related rules and are subject to the requirements outlined above.
Non-wagering promotions involving a drawing or raffle are not regulated by the board under the
LIGA, LSBA, and related rules, as stated above.
Q: Is board approval of bonuses and promotions required?
A: No. Board approval of internet gaming and internet sports betting bonuses and promotions is
not required.
Tournaments and Contests
Q: What requirements apply to internet gaming and internet sports betting tournaments
and contests? Is board approval required?
A: Tournaments and contest must adhere to recordkeeping and operational requirements
prescribed in the administrative rules and related technical standards. While board approval is
not required, an operator or platform provider must file written notice with the board prior to the
first time a tournament or contest type is conducted. An operator or platform provider may file a
master tournament list with the board to satisfy this requirement.
Geofencing
Q: Are licensed operators and their platform providers required to use geofencing
technology to block wagers initiated by individuals physically located in any geographic
areas within the state of Michigan (e.g., Indian land)?
A: The Lawful Internet Gaming Act and Lawful Sports Betting Act provide that wagers must be
initiated and received or otherwise made by an authorized participant located in the state of
Michigan or, for internet sports betting or internet poker only, another jurisdiction in the United
States authorized by a multijurisdictional agreement entered into by the board. The acts do not
restrict locations within the state of Michigan from which wagers may be accepted by a licensed
operator. Licensed operators and their platform providers may accept wagers from individuals
located anywhere within the geographic boundaries of the state of Michigan, including on Indian
land, unless otherwise provided in applicable federal law. See Geofencing Specifications
(Technical Bulletin 2020-01) for more information on geofencing specifications and
requirements.
Internet Gaming and Internet Sports Betting Conducted Exclusively
on Indian Lands
Q: Can an Indian tribe conduct internet gaming and/or internet sports betting exclusively
on Indian lands that is not subject to the Lawful Internet Gaming Act and/or Lawful
Sports Betting Act?
A: Yes, provided each wager meets applicable criteria for exemption, including: (1) the
individual who places the wager is physically present on Indian lands when the wager is
initiated; (2) the wager is received or otherwise made on equipment that is physically located on
Indian lands; and (3) the wager is initiated, received, or otherwise made in conformity with the
safe harbor requirements described in 31 USC 5362(10)(c). If the wager is initiated through an
internet wagering account or internet sports betting account and received on an MGCBapproved internet gaming platform or internet sports betting platform, the tribe will have to use
MGCB-approved methods (such as an audit trail from a licensed geolocation service provider)
to validate that the wager is exempt from the Lawful Internet Gaming Act or Lawful Sports
Betting Act. Exempt wagers can be deducted or otherwise excluded from the payments a tribe
makes under those acts.
Responsible Gaming Databases
Q: Has MGCB developed the responsible gaming databases yet?
A: Yes. For questions regarding the responsible gaming databases and distribution to operators
and platform providers, please contact Sandra Johnson at johnsons56@michigan.gov.
Updated May 12, 2022

View File

@@ -0,0 +1,884 @@
Table of Contents
PREFACE 04
| INTRODUCTION | 05 |
| --- | --- |
| BSA/AML GOVERNANCE | STATE REGULATORY REQUIREMENTS 06 07 |
| RISK ASSESSMENT | BOARD AND SENIOR LEADERSHIP RESPONSIBILITIES 08 CULTURE OF COMPLIANCE 08 AML OFFICER 09 NEW PRODUCT/SERVICE, M&A, AND PROPERTY REVIEWS 09 INTERNAL REPORTING POLICY 09 10 |
| PATRON IDENTIFICATION AND DILIGENCE | RISK ASSESSMENT PROCESS 11 PREVENTIVE STEPS FOR RISK MITIGATION 13 EXAMPLES OF HIGH-RISK SERVICES/PRODUCTS 15 18 |
| SUSPICIOUS ACTIVITY REPORTING | PATRON IDENTIFICATION AND VERIFICATION 19 SANCTIONS SCREENING 21 KNOW YOUR CUSTOMER/CUSTOMER DUE DILIGENCE 21 EXAMPLES OF HIGH-RISK PATRON TYPES 24 25 |
SUSPICIOUS ACTIVITY REPORTING REQUIREMENTS 26
TIMELINE FOR FILING A SAR 26
TYPE OF FILING: CONTINUING ACTIVITY REPORT 27
SUSPICIOUS ACTIVITY MONITORING AND REPORTING PROCEDURES 28
INTERNAL ESCALATIONS OF SUSPICIOUS ACTIVITY 28
TRANSACTION MONITORING AND DATA MINING 28
SAR INVESTIGATION PROCESS 31
DECISION TO FILE OR NOT FILE 31
COMPLETING/FILING A SAR 31
| | | TYPE OF FILING: CONTINUING ACTIVITY REPORT | 27 | |
| --- | --- | --- | --- | --- |
| | SUSPICIOUS ACTIVITY MONITORING AND REPORTING PROCEDURES | | 28 | |
| | | INTERNAL ESCALATIONS OF SUSPICIOUS ACTIVITY | 28 | |
AMERICAN GAMING ASSOCIATION BEST PRACTICES FOR ANTI-MONEY LAUNDERING COMPLIANCE
Table of Contents Cont.
SAR CONFIDENTIALITY 32
SAR SHARING 32
HIGH-RISK SUSPICIOUS ACTIVITY TYPOLOGIES 33
FINCEN SUSPICIOUS ACTIVITY REPORT (FORM 111) 36
| CURRENCY REPORTING REQUIREMENTS | 39 |
| --- | --- |
| INFORMATION SHARING | CURRENCY TRANSACTION REPORTS 40 CURRENCY OR MONETARY INSTRUMENT REPORTS 41 42 |
| INDEPENDENT REVIEWS | INFORMATION SHARING ACROSS AN ENTERPRISE 43 INFORMATION SHARING WITH PARTNERS/SERVICE PROVIDERS 43 314(B) INFORMATION SHARING 44 OTHER INFORMATION SHARING RESOURCES 44 45 |
| EMPLOYEE TRAINING | INDEPENDENT TESTING PROCEDURES FOR CTRs 47 INDEPENDENT TESTING PROCEDURES FOR SARs 47 48 |
| RECORDKEEPING AND RETENTION | 50 |
| ANTI-HUMAN TRAFFICKING | 52 |
| CONCLUSION | 55 |
| GLOSSARY | 57 |
| APPENDIX A: ANTI-MONEY LAUNDERING PROGRAM QUESTIONNAIRE | 60 |
RESTRICTING AND TERMINATING PATRON RELATIONSHIPS 37
AMERICAN GAMING ASSOCIATION BEST PRACTICES FOR ANTI-MONEY LAUNDERING COMPLIANCE
The U.S. gaming industry is one of the most heavily regulated and controlled business sectors across the globe. In addition to comprehensive and stringent state gaming regulations, most U.S. gaming operations are also subject to federal anti-money laundering (AML) and combating the financing of terrorism (CFT) requirements. 1
The modern casino and gaming operation is typically an entertainment service that offers its patrons highly regulated gaming at in-person casinos or other brick-and-mortar properties and/or through online gaming and sports betting platforms. Often, brick-and-mortar casinos are also combined with retail sportsbooks, racetracks, hotels, dining options, and live entertainment. To facilitate gaming activity, casinos, as well as online and mobile gaming operators, ordinarily provide some form of financial services to their patrons. They endeavor to ensure that these financial services are used for gaming-related purposes. Although most patrons visit casinos or mobile gaming applications for entertainment, leisure, and diversion, those engaged in illegal activity may attempt to use a casino or gaming platforms financial services to conceal or transfer illicit wealth.
This document is an attempt to distill the practices that a wide range of gaming businesses — including land based casinos, sportsbooks, and interactive and mobile gaming operations — have adopted to comply with federal AML requirements under the Bank Secrecy Act (BSA) and associated regulatory expectations. Throughout this guide, we generally use the term “casino” to refer to any physical, online, or mobile BSA-regulated gaming or sports betting business, unless explicitly described otherwise. This document is not intended to be a checklist of actions required or expected of every casino and should not be applied arbitrarily to any individual situation or on a blanket basis. The recommendations in this document are not exhaustive and may vary in applicability for distinct types of gaming businesses. AML/CFT Programs should be risk-based, and casinos have different risk profiles, so individual casinos will have good reasons for departing from or modifying a procedure in this document, or for developing supplemental or alternative procedures, including appropriate approvals and documentation of decision-making. It is important to note that best practices will continue to evolve in response to innovative technologies, enhanced compliance resources, regulatory guidance and enforcement decisions, and the Administrations enforcement priorities and approach toward regulations. Moreover, in some instances, industry practices may go beyond a legal requirement established by statute or regulation. Accordingly, this document should not be considered a guide to compliance with AML legal requirements. There are also open legal questions around the applicability of the BSA to certain types of gaming businesses, such as online operators, pending further guidance from the Financial Crimes Enforcement Network (FinCEN).
The American Gaming Association (AGA) is the premier national trade group representing the $261 billion U.S. casino industry, which supports 1.8 million jobs nationwide. AGA members include commercial and tribal casino operators, suppliers, and other entities affiliated with the gaming industry. It is the mission of the AGA to achieve sound policies and regulations consistent with casino gamings modern appeal and vast economic contributions.
Preface
1 As used in this paper, money laundering and AML compliance also encompasses the terms terror financing and CFT.
THE VALUE OF THE U.S. CASINO INDUSTRY REPRESENTED BY AGA, THE PREMIER NATIONAL TRADE GROUP
$261B
JOBS NATIONWIDE SUPPORTED BY THE INDUSTRY$1.8M
Casinos are required to implement and maintain an AML
and CFT Program (hereinafter, AML/CFT Program or BSA/
AML Program) that complies with the BSAs AML Program,
reporting, and recordkeeping requirements. 3 A casinos AML/
CFT Program must be risk-based and effective in practice,
not just on paper, and it should include, at a minimum:
○ An annual risk assessment
○ A formal know your customer (KYC) program
○ A system of internal controls, policies, and procedures to
ensure ongoing compliance with the BSAs requirements,
including suspicious activity and currency transaction
reporting and recordkeeping requirements
○ Internal and/or external independent assessments of the
AML/CFT Program
○ Appropriate, ongoing training of casino personnel
○ Designation of an individual or individuals charged with
ensuring day-to-day compliance with the casinos AML/
CFT Program and BSA requirements (the AML Officer)
○ Automated programs to aid in ensuring BSA compliance
○ A compliance testing/quality assurance program for AML
functions
○ Approval of the AML/CFT Program by the board of
directors or an equivalent oversight committee for
institutions without a board
To safeguard the integrity of the casino industry and the U.S. financial system, casinos and gaming operators have developed effective risk-based programs to ensure compliance with the legal requirements of the BSA and associated AML statutes and regulations. AML/CFT Programs help protect casinos and their employees from unwittingly being involved in money laundering and terrorist financing activity. In early 2021, the landscape of the U.S. federal AML laws and regulatory framework changed, following the enactment of the Anti-Money Laundering Act (AMLA). Designed to usher in a new era of AML effectiveness, the AMLA aims to modernize the AML/CFT laws of the U.S. pursuant to the purposes of the Act, which include, as relevant: ○ To improve coordination and information sharing among the agencies tasked with administering AML/ CFT requirements, the agencies that examine financial institutions for compliance with those requirements, federal law enforcement agencies, national security agencies, the intelligence community, and financial institutions ○ To modernize AML/CFT laws and regulations to adapt the government and private sector response to new and emerging threats ○ To encourage technological innovation and the adoption of new technology by financial institutions to more effectively counter money laundering and terrorist financing ○ To reinforce that financial institutions AML/CFT policies, procedures, and controls shall be risk-based The AMLA mandates a range of extensive congressional reports, regulatory reviews, and reforms, as well as updates to examination manuals and regulator and examiner training programs. It also mandates beneficial ownership reporting to FinCEN, although those regulatory requirements were updated in 2025 to exclude domestic entities “[c]reated
Since 1985, state-licensed casinos have been defined as “financial institutions” under the BSA. Accordingly, they are subject to BSA reporting, recordkeeping, and AML/CFT Program requirements. These regulatory requirements are contained in 31 C.F.R. Part 1021, and the U.S. Department of the Treasurys FinCEN periodically publishes regulatory guidance regarding those requirements on its website. Further, the industrys AML compliance programs are also influenced by guidance from the U.S. Treasury, including the National Strategy for Combating Terrorist and Other Illicit Financing (National Illicit Finance Strategy) and the National Money Laundering Risk Assessment (NMLRA). 2
Introduction
Primary BSA Requirements and Regulatory Expectations for Casinos
2 In May 2024, the U.S. Department of the Treasury announced its 2024 National Strategy for Combatting Terrorist and Other Illicit Financing. The 2024 strategy outlined priorities for the AML/CFT framework, law enforcement, and technological innovation. See U.S. Department of the Treasury, 2024 National Strategy for Combatting Terrorist and Other Illicit Financing (May 2024), available at: https://home.treasury. gov/system/files/136/2024-Illicit-Finance-Strategy.pdf; U.S. Department of the Treasury, The National Money Laundering Risk Assessment 2024 (Feb. 1, 2024), available at: https://home.treasury.gov/system/ files/136/2024-National-Money-Laundering-Risk-Assessment.pdf.
3 These terms are used interchangeably within this guide to refer to a casinos compliance measures to adhere to the BSA and mitigate money laundering and terrorist financing risks. 4 FinCEN, Anti-Money Laundering and Countering the Financing of Terrorism National Priorities (June 30, 2021), available at: https://www.fincen.gov/sites/default/files/shared/AML_CFT%20Priorities%20(June%20 30%2C%202021).pdf.
by the filing of a document with a secretary of state or any similar office under the law of a State or Indian tribe,” which would generally include regulated casinos and gaming entities in the U.S. It also requires that financial institutions consider National AML/CFT priorities when designing their AML/CFT Programs, as discussed further below. 4
State Regulatory Requirements While federal AML/CFT laws and regulations apply across all states, each state has the authority to adopt more restrictive or additional requirements. States that grant casino licenses typically impose exacting regulations on casino operations, though specific requirements vary from state to state. State regulatory specifications can include the games that can be offered (and their rules), the financial services that can be provided, and the procedures casinos must follow in providing them. State regulation also extends to the nature of the surveillance and security measures employed at casinos, and they can include audit and/or state reporting or information-sharing requirements. This guide is designed to focus on federal BSA requirements and expectations, but casinos must additionally be aware of and ensure that their AML/CFT Programs comply with any additional and/or more stringent AML requirements that are applicable to them under state laws.
EACH STATE HAS THE AUTHORITY TO ADOPT MORE RESTRICTIVE OR ADDITIONAL REQUIREMENTS
Introduction
BSA/AML
Governance
BOARD AND SENIOR LEADERSHIP RESPONSIBILITIES 08
CULTURE OF COMPLIANCE 08
AML OFFICER 09
NEW PRODUCT/SERVICE, M&A, AND PROPERTY REVIEWS 09
INTERNAL REPORTING POLICY 09
BSA/AML Governance
Risk-based AML compliance efforts and a strong culture of compliance are essential to the casino industry.
Board and Senior Leadership Responsibilities
Casino leadership, including its board of directors and compliance committee, holds ultimate responsibility for the casinos
compliance with the BSA.
Board and senior leadership responsibilities include:
Culture of Compliance Casino leadership should remain engaged in compliance efforts and set a tone from the top that compliance must be prioritized above revenue and other commercial interests. A culture of compliance can be established and maintained through:
Forging effective working partnerships with law enforcement agencies is another important way to nurture a culture of
compliance, ensuring that employees understand how BSA-required reports are used to achieve national policy goals that may
override business concerns. Such partnerships can be formal (such as hosting roundtables or forums to share information) or
informal (such as maintaining a close relationship with the local Federal Bureau of Investigation (FBI) field office and sharing
suspicious activity information).
Compliance with the casinos AML/CFT Program requirements and other compliance actions of individual employees should
be a factor in performance reviews. These factors should be considered in calculating compensation and bonuses, and in
determining any negative personnel action, from performance improvement plans through to termination of employment.
Casinos should consult with FIN 2014 A007,which discusses FinCEN expectations for for promoting a culture of
compliance. 5
○ Establishing a culture of compliance: Boards are expected to foster an organizational culture that prioritizes compliance above revenue interests. ○ Overseeing the AML/CFT Program: Boards are responsible for approving and overseeing casinos AML/CFT Program, ensuring it is effective, appropriately resourced, and independently tested. ○ Designating an AML officer: Boards should appoint a qualified individual to serve as the AML Officer, responsible for day-to-day compliance with BSA requirements.
○ Ensuring adequate AML/CFT compliance resources: Boards are responsible for ensuring that the AML/CFT compliance function and the AML Officer have sufficient authority, independence, and access to resources (human and technological) to ensure the AML/CFT Program is compliant, risk-based, and effective. ○ Being knowledgeable about BSA/AML requirements: Board members should receive periodic AML/CFT training, in accordance with their AML/CFT Programs training schedule. The training should cover applicable BSA/ AML obligations, the elements and effectiveness of their casinos AML/CFT Program, and how their BSA reports are used.
○ Regular communications emphasizing the importance of compliance and promoting transparency and accountability among all staff members ○ New hire and ongoing compliance training ○ Periodic compliance training tailored specifically to the casinos services
○ Adequate resourcing, independence, and authority granted to compliance functions ○ Compensation and promotion structures that incentivize compliance and disincentivize noncompliance, including compensation and bonus clawbacks or other impairment ○ Effective internal reporting and investigation mechanisms and policies
5 FinCEN, FIN-2014-A007, Advisory to U.S. Financial Institutions on Promoting a Culture of Compliance (Aug. 11, 2014), available at: https://www.fincen.gov/resources/advisories/fincen-advisory-fin-2014-a007.
AML Officer As required by the BSA, at least one employee at a casino must be designated as responsible for day-to-day compliance with BSA and AML requirements, policies, and training, and should be available to other employees to consult on related questions as they arise. This individual should be fully knowledgeable of the BSA and all related regulations and independent of casino operating departments. This individual may be known as the AML Officer or have another title/duties (for the purposes of this document, the employee with day-to day BSA/AML responsibility on the property shall be referred to as the AML Officer).
In addition, to ensure that the AML Officer has the necessary independence to execute their responsibilities, they should report to the Chief Legal Officer, Chief Risk Officer, Chief Compliance Officer, or an executive of comparable stature. If applicable, property-level leadership with oversight of AML/CFT Programs should have a direct reporting line to the centralized corporate compliance department for all AML/ CFT matters. All compliance-related reporting lines within the organization should be clearly delineated and identified to employees. The corporate board of directors, compliance committee, or other relevant committee should also receive routine briefings on the AML/CFT Program and any material changes. The AML Officer, along with the AML/CFT compliance function more broadly, should be vested with appropriate authority and resources to implement the program and assist the casino in managing risk. This means that the AML Officer should have sufficient stature in the organization to be a member of, or otherwise be able to regularly brief, senior leadership. The AML Officer should be senior enough to effectively promote the culture of compliance at all levels of the organization.
New Product/Service, M&A, and Property Reviews Casinos should have policies and systems in place to ensure that when new products, services, properties, or M&A deals are considered, the AML/CFT compliance function is involved early in the process and has a voice in decision-making based on AML/CFT risks associated with the proposal, as further discussed in the Risk Assessment section below.
Internal Reporting Policy Having a clear, effective, and accessible reporting mechanism for escalating compliance issues is an integral component of establishing a culture of compliance and identifying and addressing potential noncompliance. Casinos should have policies requiring personnel to report known and suspected noncompliance with casino policies and/or laws that are supported by robust anti-retaliation policies and controls. Casino personnel should feel empowered and safe to report compliance concerns, and they should be trained on the many ways in which they can make such reports. Personnel should also be encouraged to identify compliance program concerns and recommend enhancements through informal (e.g., ad hoc verbal remarks) and/or formal (e.g., employee surveys) channels. Casinos should provide multiple avenues for reporting, which may include emailing a designated email address, speaking with a manager and/or compliance point of contact, submitting a report via a dedicated webpage, and/or calling a third-party managed hotline. As permitted by applicable laws, there should also be an ability to submit reports anonymously. Additionally, there should be formal procedures and timelines in place for investigating reports, and, as appropriate, based on findings, implementing remedial and/or disciplinary measures. Reports, investigations, findings, and remedial/disciplinary measures should be fully documented and maintained for at least five years.
BSA/AML Governance Cont.
The AML Officer should be well-versed in the casinos products, services, patron base, entities, and geographic locations, as well as the potential money laundering and terrorist financing risks associated with those factors. It is important that the AML Officer understands how BSA-required reports are used by law enforcement agencies and functions as a liaison (partner) with those agencies. The AML Officer should be the designated point of contact for any BSA/AML-related examinations, audits, and law enforcement inquiries.
Risk Assessment
RISK ASSESSMENT PROCESS 11
PREVENTIVE STEPS FOR RISK MITIGATION 13
EXAMPLES OF HIGH-RISK SERVICES/PRODUCTS 15
The risk assessment process and internal controls should be clearly documented as a part of the casinos AML/CFT Program. The risk assessment process should begin by considering, at a minimum, the following questions to assess the casinos AML/CFT risks in different parts of its business: ○ What are the entry and exit points at the casino for patron funds that may come from illicit sources?
○ What casino departments or employees are best positioned to detect the entry and exit of such funds?
○ What are the characteristics of transactions that may involve illicit funds, or of patrons who are more likely to engage in suspicious activity?
○ Is the casinos geographic location high-risk for money laundering, terrorist financing, or other illicit finance activities?
○ What AML/CFT compliance measures (e.g., policies, procedures, controls, testing, third-party relationships, and systems, including automation) are in place to mitigate these risks?
○ How effective are those measures? Risk assessments should be reviewed and, as appropriate, updated at least annually, and more often, as circumstances warrant, due to new or materially changed AML/CFT risk factors, such as when a new product or service is launched. They should be reviewed and approved by senior leadership.
Risk assessments should be tailored to each casino venue by identifying, evaluating, and documenting its specific risks, considering factors such as the nature and characteristics of its geographical location, enterprise, products, financial services, patrons, and intermediaries. Casinos should also look at relevant enforcement actions and regulatory guidance to identify money laundering and terrorist financing typologies that may be used to exploit their properties, products, and/or services. The risk assessment should then identify the compliance measures that the casino has in place to mitigate each of those risks and assess the residual risks to the casino to determine whether the casinos AML/CFT measures are sufficient to adequately mitigate those risks. During these risk assessment processes, casino compliance professionals should bring to bear their judgment based on experience with casino transactions. Upon completion of a new or updated risk assessment, the compliance function should develop formal action items to be completed to reduce any insufficiently mitigated risks.
Risk Assessment Process
The BSA requires casinos to implement risk-based internal controls, policies, and procedures. Every
financial institution is potentially at risk of being used for illegal purposes or accepting proceeds from
illicit activity. Casinos should identify and assess their specific money laundering risks and adopt
effective measures designed to mitigate those risks.
Conducting a risk assessment should be the first step in building an AML/CFT Program.
Regulatory guidance that should be considered during the
risk assessment process include, among others, FinCENs
National AML/CFT Enforcement Priorities and the NMLRA. 6
The latest versions of these publications identified the
following typologies, among others, as key AML/CFT
threats in the U.S.:
○ Corruption
○ Cybercrime, including cybersecurity and virtual
currency risks
○ Terrorist and proliferation financing
○ Fraud
○ Drug trafficking activity
○ Human trafficking and human smuggling
○ Professional money laundering organizations
More specifically, the 2024 NMLRA highlighted specific money laundering risks impacting casinos and online gaming platforms, including: ○ Criminal money laundering organizations, casino junkets, and money-mule networks using casinos to launder illicit proceeds ○ Misuse of line-of-credit services to avoid currency transaction report (CTR) filings ○ Misuse of private gaming salons ○ Chip-walking in denominations lower than what casinos generally track (i.e., chips valued at less than $5,000) ○ Foreign illicit actors engaging in intra-property transfers, wherein they deposit funds at a foreign branch of a U.S.based casino property and then access an equivalent amount of funds at a U.S. branch of that same casino property, thereby potentially bypassing foreign currency controls and/or BSA reporting obligations ○ Deposits of illicit proceeds into betting accounts and subsequently withdrawing funds after minimal gaming activity to disguise the illicit funds as gaming earnings
On an annual basis and as part of its ongoing risk assessment, the casino should review its filed suspicious activity reports (SARs) for the previous year to analyze patterns of suspicious activity. The trends may then be reviewed by the casinos AML committee, if applicable, to determine whether adjustments to the AML/CFT Program or risk assessment are warranted. Information identified in independent assessments of a casinos AML/CFT Program should also be carefully analyzed and reviewed as part of the risk assessment process. Such assessments include evaluations of independent auditors and Internal Revenue Service examinations of the casinos AML/ CFT Program. Findings from these assessments may warrant updates to a casinos risk assessment. The casino should undertake corrective actions in response to issues that arise during these independent assessments and revise its AML/ CFT Program accordingly or decide that no such action is necessary. The results of these assessments should also be reported to the board. Furthermore, as referenced above, casinos should have policies and systems in place to ensure that when new products, services, properties, or M&A deals are considered, the AML/CFT compliance function is involved early in the process and has a voice in decisioning based on BSA/ AML risks associated with the proposal. Compliance should consider how the new product, service, property, or deal would impact the casinos BSA/AML risk assessment and what risk mitigation measures would be necessary to appropriately offset any intolerable increases in risk. Those considerations should factor into the casinos ultimate decisioning on whether and how to continue with the proposal.
6 FinCEN, AML and CFT National Priorities (June 30, 2021), available at: https://www.fincen.gov/sites/default/files/shared/AML_CFT%20Priorities%20(June%2030%2C%202021).pdf; U.S. Department of the Treasury, The National Money Laundering Risk Assessment 2024 (Feb. 1, 2024), available at: https://home.treasury.gov/system/files/136/2024-National-Money-Laundering-Risk-Assessment.pdf. Casinos may also consider guidance identifying U.S. jurisdictions considered high-risk for certain types of illicit activity, such as High Intensity Financial Crime Areas (HIFCA) and High Intensity Drug Trafficking Areas (HIDTA). FinCEN, HIFCA regional map, available at: https://www.fincen.gov/hifca-regional-map; Office of National Drug Control Policy, HIDTA map, available at https://www.hidtaprogram.org/.
Preventive Steps for Risk Mitigation Casinos should consider adopting policies and procedures that have the purpose of preventing patrons from attempting transactions that have a higher likelihood of money laundering, BSA violations, or other violations of law. Such policies and procedures should be tailored to the casinos specific risk factors, in accordance with the casinos risk assessment. Some examples of preventive policies and procedures may include: ○ Declining to accept a cash purchase of a casino check, monetary instrument, or initiate a wire transfer. This would not restrict the cage from issuing a check or funds transfer for documented casino winnings. Such approvals should be documented. ○ Requiring ticket-in, ticket-out (TITO) redemptions at self service kiosks to be capped at an amount below $3,000 (or an amount determined by the risk assessment) and monitoring to identify TITO redemptions of multiple tickets below that amount at the same self-service kiosk. ○ Increasing surveillance at TITO machines to detect stuffing multiple low-denomination tickets to avoid CTR reporting and placing TITO machines in areas that are easily observable by staff. ○ Barring cash-for-cash exchanges or only allowing them at a very low threshold, as this can be indicative of money laundering. Any cash exchanges should be consistent with the casinos risk assessment and, in rare circumstances, permit senior management to approve such exchanges above that threshold for an appropriate business purpose (e.g., foreign currency exchanges for established patrons at reasonable levels); such approvals should be documented. ○ Heightened scrutiny for checks or wire transfers originating from a labor union, charitable/nonprofit organization or foundation, law firm (including from an Interest on Lawyers Trust Account (IOLTA), accounting firm, business, third party, or any type of trust account. A casino may reject and/or reverse such checks and wire transfers and consider filing a SAR on the payment. ○ Issuing casino checks and wires to a patron only for the amount of their winnings (e.g., the remaining funds from a check or wire that already has been accepted).
○ A check for winnings should be payable only to the patron, and a wire transfer should be made only to the patrons account or, if applicable, to the account from which the originating wire was received. Similarly, if there is a return of front money paid by wire transfer, it should be wired back to the bank account from which the funds originated. ○ To the extent casino checks and/or wires are made payable to a patrons business, another casino account, or to someone other than the patron at the patrons request, casinos must develop appropriate procedures. Procedures should require that such transactions include cage or senior management approval. Such transactions should only be allowed when the casino has been able to obtain an appropriate business purpose for the action, which is documented, and an appropriate connection is documented between the patron and the business. ○ Suspending a patrons loyalty club account and/or barring the patron if the patrons activity has generated the filing of an incomplete CTR and the patron has declined to produce the required information, until the missing information is provided. Filing a SAR for the episode should also be considered. In such instances, the patron should be prohibited from further gaming and may be prohibited from the redemption of complimentaries (comps). ○ Directing international branch offices of the casino to adhere to the same recordkeeping and reporting requirements under the BSA that are consistent with the laws of the jurisdiction in which the international branch office is located, as well as local law. To the extent these offices are allowed to receive cash, casinos may want to consider voluntary CTRs. The office should also be required to identify and report internally any suspicious transactions in order that SARs can be completed where required. ○ Prior to travel outside the U.S., marketing executives should be trained on the laws that relate to gaming and marketing for the specific jurisdiction(s) they are visiting. If a traveling marketing executive is authorized to conduct a financial transaction in an international location, the casino may also need to report the transaction under the BSA. ○ Eliminating cash play at poker tables and documenting poker chip purchases at a certain dollar threshold.
Additional Preventive Measures
Specific to Online Gaming
○ Requiring that accounts from which patrons deposit and
withdraw funds match the name of the account holder
○ Where possible, returning funds to the original payment
source
○ Analyzing patron activity for evidence of account sharing
or attempts at evading/manipulating geolocation controls
○ Monitoring patron activity for evidence of deposits and
withdrawals without legitimate wagering activity
○ Searching player databases for:
Multiple players using similar usernames and email
addresses, based on geolocation data and device
intelligence
A large number of players geolocating from a similar
residential location
Multiple players using a shared device
○ Leveraging geolocation data to detect “impossible travel”
(i.e., multiple attempted transactions from jurisdictions of
significant distance, which would be physically impossible
and may be indicative of attempted proxy wagering or
account sharing)
○ Deploying device blocks in instances of repeated actions deemed to be suspicious and lacking any legitimate business purpose, aligned with an operators risk-based approach ○ Leveraging geolocation data at the time of patron funding and withdrawal to ensure funds are not being transmitted from restricted, high-risk, or sanctioned regions ○ Analyzing player accounts with multiple payment methods and consecutive deposits ○ Limiting the number of payment instruments that players are allowed to add (i.e., number of credit/debit cards, wallets, bank accounts, etc.) ○ Limiting the total dollar amount a player can deposit or disburse from their wallets in set periods of time
Examples of High-Risk Services/ Products GAMING VOLUME AND CHARACTER Different gaming venues may have differing risks based on their unique product mix and patron pool. Risks may evolve over time as a venues business model and/or patron transaction volume changes. Because money launderers often deal with substantial amounts of money, they may be drawn to larger casinos with higher gaming activity, where large-value transactions are more frequent and less likely to draw attention. For the same reasons, money laundering may be more likely to involve patrons bringing large amounts of money to a casino and playing games with higher dollar values. Accordingly, larger gaming venues will likely need more AML/ BSA compliance procedures than smaller casinos with lower dollar volumes. Nevertheless, smaller volume casinos must be alert to a patrons departure from ordinary patterns of play and suspicious use of the financial services offered by the casino. Similarly, the structuring of transactions to avoid reporting requirements can occur at any casino, regardless of business volume.
RANGE OF FINANCIAL SERVICES The broader the array of financial services available at the casino (e.g., front-money deposit accounts, markers/credit extensions, wire transfer services, check cashing, credit/debit card cash advances, and safety deposit boxes), the greater the opportunity for a money launderer to exploit several different services for illicit purposes. Casinos should strive to ensure that transactions have a legitimate gaming purpose and that other financial transactions conducted as a courtesy are prohibited or restricted to small amounts. In addition to being highly limited, such transactions should require approval by at least two individuals with an appropriate level of authority, such as the AML Officer, Cage Director, or other senior-level executive. The approval process for exceptions to the policy should be clearly documented in the casinos compliance program.
CHARACTERISTICS OF CERTAIN GAMES The rules of certain games may increase the likelihood of money laundering. For example, if a game allows patrons to bet either side (e.g., baccarat, craps, or roulette), confederated patrons might bet both sides to launder funds through the game. Similar risks may arise in the case of sports betting when a patron places a bet with a legally operating sportsbook on behalf of an unidentified third party, concealing the origin and owner of the funds or betting on both sides of the line. 7 In addition, race and sportsbooks may be potential targets for money launderers because confederates can bet on both sides of a game or an event, thereby offsetting their exposure. Because poker is not a house-banked game, transactions at poker tables may occur between patrons, rather than with the casino. Accordingly, the casino may be less likely to detect potential suspicious activity because poker — unlike table games, race and sportsbook wagers, or electronic games — does not allow the casino to determine verified win/loss. If a casino does not permit cash wagering in poker rooms, the risk of money laundering may be correspondingly reduced. Nevertheless, there could be information about a poker players source of funds or criminal associations that could raise red flags and should be escalated to Compliance.
CRYPTOCURRENCY Cryptocurrencies use blockchain technology as a means of decentralized recordkeeping for transactions. The regulatory climate for cryptocurrency is still developing and the value of cryptocurrencies is volatile. There have been a number of cases where cryptocurrency has been involved in money laundering or other illegal activity, and its illegal use is a major government concern.
7 See FinCEN, Correspondence with the American Gaming Association Regarding Sports Betting Conducted on Behalf of Third Parties (Dec. 24, 2014), available at: https://www.fincen.gov/resources/statutes regulations/guidance/fincen-correspondence-american-gaming-association-regarding.
The suggested best practice is to require any virtual currency to be converted to U.S. dollars prior to use for gaming at a slot machine, table game, sportsbook, or other gaming area. By requiring virtual currency to be converted to U.S. dollars prior to usage for gaming, it will be subject to the same CTR and SAR reviews as all other cash transactions conducted within the casino.
THIRD-PARTY PAYMENTS AND SHELL COMPANIES There has been a longstanding concern with the use of anonymous legal entities to promote money laundering and other illegal activities. These entities may be shell companies or act as unlicensed money transmitters. Contrary to popular belief, these entities are not only incorporated in offshore jurisdictions with reputations for secrecy but can also be organized under state law in the U.S. FinCEN has taken measures to address this risk. In 2018, FinCENs Customer Due Diligence (CDD) Rule became effective, requiring banks and certain other financial institutions (excluding casinos) to obtain beneficial ownership information on legal entity customers. Acceptance of payments for gaming or casino debt from legal entities or other third parties on behalf of patrons poses a money laundering risk for casinos. If a casino permits payments from third parties (either legal entities or persons), there should be written policies describing the types of third-party payments that are permitted and under what circumstances based on the casinos risk tolerance. For instance, casinos may restrict third-party payments to those from a business that is documented to be related to, or owned by, the patron or from relatives of the patron. To the extent a casino allows third-party payments, the casino should understand and document the nature of the relationship between the patron and third party.
ONLINE PAYMENTS AND DIGITAL WALLETS Online payments and digital wallets, including player account balances on online gaming platforms and cashless wagering accounts that allow cashless gaming on the casino gaming floor, can involve heightened BSA/AML risks. Digital wallets enable patrons to load cash into an account and use those funds for gaming on a casino floor or online platform, as determined by the casino operator and the functionality of the digital wallet. 8 Funding sources may include online transfers from bank accounts, credit/debit cards, deposits with a cashier within the casino, and others. Players place
wagers with a mobile device or computer with access to their wagering account. The patrons identity is confirmed, and each transaction creates a digital record. Digital wallets may be associated to a patrons player loyalty account with the casino. The best practice is to only allow accounts to be associated with one user. The casino should take reasonable precautions to ensure accounts are not shared by multiple patrons. The customer service agreement should require patrons to agree that the account is for personal use only.
Since online payments are non-cash transactions, CTR requirements do not apply to them. As such, an operator should implement adequate procedures to review transactions using this payment method for suspicious activity. However, Digital wallet deposits and withdrawals in cash are still subject to CTR requirements when they occur on casino premises. Converting deposits from one transaction type to another within the digital wallet platform should be strictly limited. Wherever possible, casinos should require the withdrawal method to match the deposit method, unless the funds have been sufficiently placed at risk. Funds deposited to a digital wallet should be confirmed to be used for a gaming purpose. A reasonable, risk-based review process should be implemented to detect patrons who frequently make deposits and withdrawals without associated gaming activity. Such instances should be considered for a SAR filing. In addition, to mitigate BSA/AML risks that can be associated with digital wallets, the best practice is to deploy the same
Digital wallets and online transactions, in general, can present a greater opportunity for money laundering. Bad actors can exploit these transactional methods to convert illicit funds into virtual assets (if supported) or to engage in fraudulent transactions The relative anonymity, speed, and convenience of these transactions can make suspicious activity through them more challenging for casino personnel to identify and prevent. These transactional methods may require separate or more sophisticated transaction monitoring systems and associated employee training to adequately monitor for suspicious activity. Casinos should ensure that any payment processor or digital wallet service provider also has robust BSA/AML policies and procedures, including transaction monitoring.
8 An important distinction is that Digital Wallets as noted here, are denominated in US dollars and the best practices in this section are not in reference to cryptocurrency which is covered in a separate section.
Risk Assessment geolocation and KYC measures that are applicable to the online and mobile wagering environment to the cashless wagering and digital wallet environment. These measures will ensure the true identity of the patron wagering with the digital wallet and cashless payments, and ensure that the wagering funds are being deposited from an authorized jurisdiction, mitigating the risk that the wallet is being used in a fraudulent manner or as a conduit to engage in money laundering or other illicit activity.
ONLINE GAMING Online gaming has many of the same risks associated with in-person casino gaming. Although there remains uncertainty regarding BSA coverage for certain online operators, those subject to the BSA must comply with AML Program and suspicious activity reporting requirements. Accordingly, appropriate reviews should be put into place to detect similar types of suspicious activity. The types of suspicious activity for online gaming include, but are not limited to, minimal gaming with large transactions, structuring, and identification issues. Additionally, prior to signing up for an online gaming account, new patrons should be subject to identity verification as well as compared against the Office of Foreign Asset Control (OFAC) and Specially Designated Nationals (SDN) sanction lists. If a patron appears on one of the sanction lists, the online gaming provider should block the creation of the account. Identity and credit card theft fraud rings may target the online gaming environment to establish fraudulent accounts with stolen identity information and fund those accounts with fraudulent payment instruments. Such fraud rings attempt to establish multiple online accounts and, if successful, typically make large deposits with minimal game play and then quickly try to withdraw those funds. Online casino and sports betting operators should establish tools to mitigate such fraud, which may include the methods described under the Preventative Steps section of this document.
HIGH-STAKES/LIMIT POKER ROOMS High-stakes/limit poker rooms can be particularly vulnerable to illicit financial activity, which may warrant heightened BSA/AML risk mitigation measures. These rooms tend to implicate a heightened risk of collusion between players and circumvention of a casinos BSA/AML compliance controls. Another risk factor is third parties introducing illicit funds into these rooms by funding or backing patrons gaming activity. Risk mitigation strategies may include additional surveillance and source of funds confirmation at certain monetary thresholds.
Patron
Identification and Diligence
PATRON IDENTIFICATION AND VERIFICATION 19
SANCTIONS SCREENING 21
KNOW YOUR CUSTOMER/CUSTOMER DUE DILIGENCE 21
EXAMPLES OF HIGH-RISK CUSTOMER TYPES 24
Patron Identification and Verification Before conducting any BSA-reportable transaction or opening a front money or market limit/credit account, digital wallet, other online patron balance account, or issuing a safety deposit box for a patron, casinos must collect and verify the patrons full name, permanent address, and Social Security Number (SSN), if applicable. However, this requirement does not apply to the establishment or use of player loyalty accounts. If a patron asserts that their only permanent address is a post office box, the casino should confirm this assertion by examining available databases and acquiring the patrons attestation to this fact. In addition, as part of these identification verification processes, patrons should be required to provide a valid, current, government-issued photo identification, which may include a: ○ Drivers license 9
○ Passport
○ Alien registration card
○ State-issued identification card (including Real IDs) 10
○ Global Entry card 11
○ Tribal identification card These identification collection and verification procedures should apply to any transaction that would trigger a CTR requirement and requests to open a front money or market limit/credit account, digital wallet, other online patron, balance account, and safety deposit box. A casinos AML/CFT policies and procedures may specify additional information that must be collected and verified in certain situations. For instance, casinos should request a patrons occupation, phone number, and email address prior to the patron exceeding the CTR threshold. Casinos should also consider the implementation of risk-based measures to verify such additional information. While the inability of a casino to obtain such additional information need not prevent a CTR transaction from occurring, if the nature of the patrons refusal or inability to provide the information is suspicious, it should be escalated for SAR consideration.
DOCUMENTARY REVIEW Other than a drivers authorization card, for in-person transactions, a casino generally may rely on viewing a valid, government-issued photo identification as verification of a patrons identity; however, if a document shows obvious indications of fraud, the casino must consider that factor in determining whether it can form a reasonable belief that it knows the patrons true identity. In some instances, information in the casinos records will suggest that certain information on the official identification document — most often the patrons permanent address — is no longer accurate. In those situations, if the casino can verify by reasonable inquiry the more recent information, it may wish to report the more recent information on any CTRs and SARs filed for that patron. Documentation supporting the verification and use of an address other than the one on the patrons government-issued ID should be maintained in the casinos records and is commonly requested by IRS examiners during a BSA examination. If the patron is a U.S. citizen or resident, an SSN is required for certain transactions, including CTRs and taxable events. Patrons may verbally provide an SSN. In such cases, it is recommended that the patron complete a W-9 Form to attest to the validity of the SSN. If the casino knows or has reason to believe that a previous SSN provided by the patron was incorrect, then the patron may also be required to complete and sign a W-9 Form before any pending transaction can be completed. Casinos should consider filing a SAR if inconsistencies in identifying information are suspicious. If a patron declines to provide an SSN when one is required, the casino must not complete any reportable transactions or
9 This does not include driver authorization cards or international drivers licenses/permits, which are not an acceptable form of identification.
10 All state-issued IDs that are compliant with the Real ID Act are sufficient for BSA reporting purposes, even those that contain the disclaimer, “Not for Federal Identification.”
11 Global Entry cards are compliant with the Real ID Act.
open an account for that patron. If the patron has exceeded the reporting threshold for a CTR without providing an SSN, a casino should attempt to acquire that information from publicly available sources. Declining to provide an SSN may warrant completion of a SAR. More generally, if a patron is missing or refuses to provide the required information, the patron should be barred from further gaming activity until the required information is provided. Documentation of the incident should be added to the patrons account in the management system, detailing the missing information. A SAR should also be considered, as appropriate. NON-DOCUMENTARY REVIEW 12 In many states, casinos also offer online gambling options, including online sports betting and online casinos. Before any patron can make an online wager, they must first establish an online wagering account with the casino or sports betting operator. For some operators, such accounts may be established in person, in which case, identification information is collected and verified as described above. However, in most cases, such accounts are established remotely through the internet, making it impossible to verify identity through in-person review of physical documentation. In such cases, operators must rely on non-documentary methods of ID verification. Non-documentary methods require the patron to input or download personal information about themselves, which typically includes some combination of name, address, date of birth, government-issued ID number, phone number, email, and all or part of the patrons SSN. Some operators may also require the submission of a photo or scan of a government-issued photo ID, and in some circumstances, they may require uploading a selfie of the prospective patron. This information is then independently verified by comparing it against information obtained from a consumer reporting agency, public database, or other third-party electronic ID verification service. If the patrons identity cannot be reliably verified, the operator should deny the creation of an online wagering account until sufficient additional documentation is provided that can be reliably verified.
12 FinCEN, FIN-2021-R001, Exceptive Relief for Casinos from Certain Customer Identification Verification Requirements (Oct. 19,2021), available at: https://www.fincen.gov/sites/default/files/2021-10/Casino%20 Exceptive%20Relief%20101921_0.pdf. This relief was granted by FinCEN in response to the casino industrys request to allow verification by non-documentary means, which is not currently provided for in the BSA regulations.
BEFORE ANY PATRON CAN MAKE AN ONLINE WAGER, THEY MUST FIRST ESTABLISH AN ONLINE WAGERING ACCOUNT WITH THE CASINO OR SPORTS BETTING OPERATOR
Sanctions Screening Although separate from BSA/AML requirements, casinos should ensure they are not conducting transactions with individuals and entities on the list of Specially Designated Nationals and Blocked Persons (SDN List) maintained by the U.S. Department of the Treasurys Office of Foreign Assets Control (OFAC) or those ordinarily residing or organizing in jurisdictions comprehensively sanctioned by OFAC. 13 Casinos should not open accounts for, or conduct transactions with, patrons who are on the SDN List or who provide addresses or are otherwise known to be ordinarily resident in comprehensively sanctioned jurisdictions. 14 In order to mitigate the risk of engaging in such activities, casinos should conduct sanctions screening of patron information it obtains in the normal course of business against the SDN List, and have controls in place to block account creation for patrons with addresses or other geolocation information indicating they reside in a comprehensively sanctioned jurisdiction. Sanctions screening of patron information should be conducted at onboarding (or when otherwise first collected) and at regular intervals thereafter during the course of the patron relationship, in accordance with the casinos AML/ CFT Program requirements. A risk-based approach to the use of “fuzzy” matching logic should be used to limit the occurrence of false positives. For online gaming platforms, these measures should include geoblocking controls for authenticated patron IP and other electronic data associated with comprehensively sanctioned jurisdictions. Geoblocking controls will further decrease the risk of proxy betting as well as heighten AML and CFT compliance. U.S. persons are required to block property in which a blocked person has a present, future, or contingent property interest. Blocked persons include individuals on OFACs SDN List and, at the time of publication, those ordinarily resident in Cuba. This means that if a casino has funds on account for a blocked person, it must segregate those blocked funds into a separate, interest-bearing account and file a blocking report with OFAC. Although at the time of publication, there is not a blocking obligation with respect to persons ordinarily resident in Iran, North Korea, or the Crimea, Donetsk, or Luhansk regions of Ukraine, casinos must reject any attempted transactions involving these persons and file a reject report with OFAC. In practice, this will typically mean that casinos should return any funds they receive or have on account for such patrons and file a reject report with OFAC. Casinos should also consider their SAR obligations and how they
intersect with these OFAC requirements.
In addition, casinos should ensure that sanction issues are
woven into the fabric of compliance, including:
○ Management commitment
○ Risk assessment
○ Internal controls
○ Testing and audit
○ Training (Appropriate employees will be trained on OFAC
compliance responsibilities.) 15
Know Your Customer/ Customer Due Diligence 16 In addition to the identification collection and verification and sanctions screening measures discussed above, casinos are expected to implement and maintain a risk-based know your customer (KYC) program that includes patron identification and due diligence procedures for patrons that present increased AML/CFT risks. These KYC reviews may be triggered based on information obtained at initial onboarding of a patron or based on information or patron activity that arises during the course of the patron relationship. Information that may trigger enhanced customer due diligence can arise from a number of sources, including publicly available data, law enforcement agencies, casino personnel, third-party service providers, and other financial institutions. It may include negative media, court filings, subpoenas, informal law enforcement inquiries, and Section 314(b) requests, among other types of data. The casinos KYC program should identify the scenarios that would trigger a KYC review and the types of customer due diligence that should be conducted as part of those reviews, on a risk basis. These procedures should be calibrated to increase scrutiny of patron play, transactional activity, and background in situations that pose greater risk of money laundering and the use of funds that may derive from criminal activity. For patrons who do not trigger these higher risk reviews, their KYC file should be subject to a refresh at certain cadences (e.g., two years or as otherwise supported based on a casinos risk assessment). For instance, risk-based KYC reviews should be required for the below patrons, among others. A more detailed discussion regarding certain patron risk factors is provided at the end of this chapter. 13 U.S. persons and entities (including casinos) are prohibited from doing business with persons or entities designated by OFAC, and any assets of the designees generally must be frozen immediately. 14 The list of comprehensively sanctioned jurisdictions is updated from time to time by OFAC. At the time of publication, these jurisdictions included Iran, Cuba, North Korea, and the Crimea, Luhansk, and Donetsk regions of Ukraine. Up-to-date information regarding OFACs sanctions programs, including comprehensively sanctioned jurisdictions, can be found at: https://ofac.treasury.gov/sanctions-programs-and-country information. 15 For more information on OFAC compliance, see OFAC, A Framework for OFAC Compliance Commitments (May 2, 2019), available at: https://ofac.treasury.gov/media/16331/download?inline. 16 The terms “customer” and “patron” are used interchangeably throughout this guide.
Patron Identification and Diligence ○ High-volume patrons (those whose activity in terms of bills-in, marker play, or total play exceeds an actual and/or theoretical level determined by the casinos risk assessment). Based on recent enforcement actions, casinos should determine their top aggregated cash patrons and their top aggregated gaming volume patrons from the prior calendar year to complete enhanced due diligence case files. ○ High-loss patrons ○ Patrons with an unexplained sudden and sustained increase in play ○ Foreign nationals of jurisdictions regarded as high risk for narcotics trafficking, human trafficking, money laundering, terrorism, or other forms of illicit finance ○ Politically exposed persons (PEPs) ○ Repeated SAR subjects ○ Patrons conducting high-risk transactions, such as third-party payments, foreign financial transactions, and domestic wires above a certain amount, as determined by the casinos risk assessment ○ Patrons with high-risk occupations, such as marijuana related or virtual currency businesses ○ Patrons who have been the subject of recent law enforcement or regulatory subpoenas or other government inquiries ○ Patrons with high decline or chargeback ratios ○ Patrons engaged in high-risk gaming activities ○ Patrons using payment instruments with multiple state associations ○ Patrons who have been the subject of a 314(b) request ○ Patrons who are the subject of substantial tax liens or who have gone through recent personal bankruptcy proceedings ○ Patrons with financial fiduciary obligations (e.g., trustee, accountant, attorney, or nonprofit/charity executive) that may create a risk of misappropriation or other illicit financial activity ○ Patrons who recently received government stimulus or support payments
○ Patrons associated with individuals or entities known to be connected with the illicit generation of funds, including unlawful gaming ○ Patrons who may otherwise present an unacceptable risk of money laundering or violating the casinos AML/CFT policies
A critical component of KYC reviews is assessing a patrons source of funds and source of wealth to assess whether funds being used by the patron for gaming may derive from illegal activity or from legitimate sources. Source of funds refers to the origin of funds that a patron uses for a particular transaction or series of transactions at the casino. Assessing a patrons source of funds entails tracing that particular transaction or series of transactions back to a legitimate source, such as a bank account in the patrons name to which the patrons paychecks are deposited or a patron account at the casino that was funded by winnings from previous gaming activity at the casino. These assessments will generally entail asking the patron for information and documentation regarding their source of funds, which may include bank account records, paychecks, tax records, or credit records. Casinos should then assess whether the provided information supports the level and nature of play associated with the transactions. Source of wealth, on the other hand, refers to the origin of a patrons overall wealth and assets. These assessments involve looking at how the patron accumulated their assets over time and whether that information supports their overall level of play at the casino. To determine a patrons source of wealth, casinos may obtain information regarding the patrons employment and salary over time, inheritance, investments, and broader gaming activity at various casinos to assess
Patron Identification and Diligence whether that information supports the level of play at the casino during the course of the patron relationship. Casinos may also consult public records and third-party databases to verify a patrons source of funds and/or source of wealth. Such databases may provide casinos with negative news information concerning the patrons potential criminal activity or doubtful business practices, as well as any prior criminal history. Databases that may be relevant to consult in such situations include records of court activity, such as PACER, the antifraud website maintained by the Federal Trade Commission (FTC), and commercial screening products offered by third-party vendors, though such resources are considerably more limited for persons and activity located in non-U.S. jurisdictions. Casinos may also wish to consult social media (such as LinkedIn or Facebook) or other public source information. In addition to querying available databases, leveraging Section 314(b) information sharing with other financial institutions is a critical tool to obtain more information and reach judgments on whether the patron: ○ Has sources of legal wealth or income commensurate with their gaming activity ○ Has provided the casino with identification information and business-related information that can be readily confirmed
When conducting KYC reviews, a casino should obtain and
consider all available information relating to the patron and
transaction(s) at issue, including, as applicable:
○ Patron gaming, identification, and diligence records (retail
and interactive)
○ Credit history and associated records
○ Prior CTR/SAR filings
○ Incident report history (surveillance/security)
○ Publicly available information, including internet searches, court filings, and news articles, and information from commercial database services, such as LexisNexis and WorldCheck, that identify negative news, criminal history, sanctions hits, and/or PEPs ○ Employee statements/interactions ○ Hotel records ○ Cyber and other technical data (e.g., geolocation, IP information, device data, etc.) ○ Section 314(b) inquiries, subpoenas, and any other law enforcement, regulator, or third-party request relating to the patron ○ Information from marketing personnel, including at international branches, that have interacted with the patron or may otherwise have additional information about the patron ○ Information from casino operations, cage personnel, surveillance, or any other department that has interacted with the patron or otherwise observed the patron at the casino ○ Surveillance data ○ Information and records obtained from the patron and any third parties on the patrons behalf As made clear in recent BSA enforcement actions, ensuring that information is shared between departments and functions, and that all available information about a patron and transaction(s) is obtained and reviewed as part of KYC reviews is integral to maintaining an adequate KYC program and suspicious activity monitoring and reporting function. All KYC reviews must be fully documented, including identification of all records reviewed as part of the diligence. Patron files and risk ratings should be updated, as appropriate, based on new information identified and findings from KYC reviews. Casinos should additionally have procedures requiring KYC refreshes at various intervals, depending on the patrons risk.
In accordance with risk-based principles for KYC reviews, if, during the course of conducting customer due diligence on a patron, the casino learns of additional AML/CFT risk factors or red flags, further due diligence may be warranted. If a casino cannot determine a patrons source of funds or source of wealth during a KYC review, a SAR should be considered.
Examples of High-Risk Patron Types COUNTRY RISK Some patrons may be deemed to present a higher risk if the casino learns that they are non-resident aliens or foreign nationals or residents of countries that have been identified by the U.S. as jurisdictions of concern for narcotics trafficking, human trafficking, money laundering, terrorism, or other forms of illicit finance. Casinos should also monitor if the foreign national has been has been identified by the Financial Action Task Force (FATF) as high risk requiring a call to action or as subject to increased monitoring because of deficiencies in its AML regime, or if the foreign nation has been identified by Transparency International or a similar reputable organization as having a high level of public corruption. 17
Online operators should ensure they have implemented sufficient controls to prevent individuals located in comprehensively sanctioned locations from accessing their platform and should perform sanctions screening as part of onboarding, as further discussed above. MONEY BROKERS Certain countries, such as China, have capital flight restrictions (currency controls) that impose limits on the amount of funds in local currency that an individual may take out of the country during a specified time period. This restriction presents a money laundering risk to casinos. For example, Chinese law prohibits citizens from converting more than the equivalent of $50,000 in Chinese yuan into foreign currency per year. This may incentivize individuals operating within the U.S. to offer illicit cash brokerage services to Chinese nationals traveling abroad. The broker offers cash in the U.S. in exchange for a domestic transfer in the patrons home country. Money remitters outside the U.S. may offer foreign exchange services to avoid currency restrictions and could make payments to casinos by wire on behalf of casino patrons. Casinos should be aware of this risk in relation to patrons subject to these restrictions and direct casino staff to report any activity indicative of this behavior.
PEPs Also known as senior foreign political figures, PEPs are individuals who have been entrusted with a current or past prominent public function, and individuals who are close relatives or known close associates of such persons. PEPs and their transactions may warrant further inquiry and consideration by the casino, such as investigating their source of wealth or funds. The concern is that their source of funds for gaming could be from corrupt activities. As appropriate, casinos should identify and assess the risks of both foreign and domestic PEPs, as well as consider part time versus full-time PEPs. A part-time PEP is someone holding a part-time position within a government role, state-owned enterprise, or a political party. Even in a part time capacity, these individuals may still have the potential to access financial resources, making them susceptible to bribery and corruption. A part-time PEP generally has another job/business that may need to be identified and considered. A casino may need to conduct open-source research to identify PEPs, and a casino operator may opt to use a commercial service or third-party provider to do so. Online operators should perform PEP screening as part of onboarding and periodically thereafter.
INDEPENDENT AGENTS/JUNKET OPERATORS Casinos should also be attentive to the influence and impact of third-party marketing programs and relationships (e.g., independent agents/junket operators). To the extent such entities may bring a meaningful number of patrons to a casino property, casinos should undertake a review of the marketing entities practices and procedures and conduct appropriate due diligence on third-party marketers or firms.
MARIJUANA (CANNABIS) Despite being legal at the state level in multiple jurisdictions, the sale and distribution of marijuana remains illegal at the federal level. It may come to a casinos attention, for instance, in a KYC due diligence review, that a patron has ties to a state-licensed and regulated marijuana (cannabis) business (e.g., is an owner or employee of the business). Since the sale and distribution of marijuana is still prohibited federally, casino compliance programs should include a policy regarding how to address patrons with ties to such marijuana related businesses and whose source of funds for gaming may be from these businesses.
17 State Department, Annual International Narcotics Control Strategy Report (Mar. 2025), available at: https://www.state.gov/wp-content/uploads/2025/03/2025-International-Narcotics-Control-Strategy-Volume-2-Accessible.pdf; FinCEN, Financial Action Task Force Identifies Jurisdictions with Anti-Money Laundering, Countering the Financing of Terrorism, and Counter-Proliferation Finance Deficiencies (Feb. 23, 2025), available at: https://www.fincen.gov/news/news-releases/financial-action-task-force-identifies-jurisdictions-anti-money-laundering-3.
Suspicious
Activity Reporting
| SUSPICIOUS ACTIVITY REPORTING REQUIREMENTS | 26 | |
| --- | --- | --- |
| TIMELINE FOR FILING A SAR ○ | 26 | |
| TYPE OF FILING: CONTINUING ACTIVITY REPORT ○ | 27 | |
SUSPICIOUS ACTIVITY REPORTING REQUIREMENTS 26
○ TIMELINE FOR FILING A SAR 26
○ TYPE OF FILING: CONTINUING ACTIVITY REPORT 27
SUSPICIOUS ACTIVITY MONITORING
AND REPORTING PROCEDURES 28
INTERNAL ESCALATIONS OF SUSPICIOUS ACTIVITY 28
TRANSACTION MONITORING AND DATA MINING 28
SAR INVESTIGATION PROCESS 31
DECISION TO FILE OR NOT FILE 31
COMPLETING/FILING A SAR 31
SAR CONFIDENTIALITY 32
SAR SHARING 32
HIGH-RISK SUSPICIOUS ACTIVITY TYPOLOGIES 33
Suspicious Activity Reporting Requirements
The BSA requires casinos to file a SAR if the casino knows, suspects, or has reason to suspect that a transaction or attempted
transaction aggregating at least $5,000:
Given that the SAR rule encompasses attempted transactions, casinos must ensure that they monitor both attempted and completed transactions for potential SAR filings.
○ Involves funds derived from illegal activity
○ Is intended to disguise funds or assets derived from illegal
activity
○ Is designed to avoid BSA reporting or recordkeeping
requirements
○ Involves the use of the casino to facilitate criminal activity
○ Has no economic, business, or apparent lawful purpose ○ Is not the sort in which the patron would normally be expected to engage, and the casino knows of no reasonable explanation for the transaction after examining the available facts
Timeline for Filing a SAR The regulations require that a SAR be electronically filed through the BSA e-filing system no later than 30 days from the date of the initial detection of facts that constitute a basis for filing a SAR. If no suspect is identified on the date of such initial detection, a casino may delay filing a SAR for an additional 30 calendar days to identify a suspect, but in no case shall reporting be delayed more than 60 calendar days after the date of such initial detection. The phrase “initial detection” should not be interpreted as meaning the moment a transaction is highlighted for review. There are a variety of legitimate transactions that could raise a red flag simply because they are inconsistent with a patrons account activity. The casinos automated account monitoring system or initial discovery of activity, such as system-generated reports, may flag the transaction for review; however, this should not be considered the initial detection of potential suspicious activity. Casinos should establish what they consider to be the trigger for starting the clock and apply this consistently.
Type of Filing: Continuing Activity Report The Continuing Activity Report filing type should be utilized in a SAR if a patron is subsequently recognized as having additional or repeated suspicious activity related to, or similar to, activity that has already been reported on a SAR filing with a filing type of Initial Report. The Continuing Activity Report filing type allows the casino to monitor a patron for up to 90 days before filing an additional SAR, which can then be inclusive of all subsequent SAR activity since the date of the initial SAR. A Continuous Activity SAR has a filing deadline of 120 calendar days from the date of the last SAR filing. SARs for continuous activity may be filed earlier than the 120-day deadline if the casino believes the activity warrants earlier review by law enforcement or there is not an expectation of additional activity (e.g., patron has been trespassed). The type of filing determination of Initial Report versus Continuing Activity Report lies in the activity of the individual(s). If the same suspicious activity has been discovered within 90 days from the initial activity, the type of filing selected would be Continuing Activity Report. If the same individual(s) are involved but in a different type of suspicious activity, the type of filing would be Initial Report (with reference to other SARs in the narrative by inclusion of associated BSA ID number).
For filings where a subject has been identified, the timeline is as follows: Day 0: identification of suspicious activity and subject Day 30: deadline for initial SAR filing Day 120: end of 90-day review Day 150: deadline for continuing activity SAR with subject information (this is 120 days from the date of the initial filing on day 30) If the activity repeats a third time, another 90-day period is allowed before requiring the third SAR filing with the filing type of Continuing Activity Report, which would result in three SARS filed over a 12-month period. If the activity does not recur within 90 days of the previously filed SAR but occurs again after the 90-day timeframe, the next SAR would be filed with a filing type of Initial SAR but would include reference to the prior SARs in the narrative along with associated BSA ID numbers. In appropriate cases, such as ongoing suspected illegal activity that requires immediate attention, the casino should reach out to the appropriate law enforcement agency in addition to filing a SAR.
A Continuous Activity SAR has a filing deadline of 120 calendar days from the date of the last SAR filing.
Suspicious Activity Monitoring and Reporting Procedures Suspicious activity monitoring and reporting policies and procedures should include a variety of potential suspicious activity examples for team member awareness and should be covered in department-specific ongoing training. Compliance should be monitoring industry and BSA/AML regulatory and enforcement news for awareness and to implement risk mitigation measures as needed to minimize exposure. Casinos should consult with FinCENs guidance in FIN-2008-G007, which discusses red flags for suspicious activity at casinos. 18 Casinos also should develop their own lists of red flags based on information from law enforcement, the casinos own experience, recent enforcement actions, and criminal cases involving money laundering, as well as BSA violations and other criminal activity involving casinos and their patrons. The list should be updated as needed and included in training. Additionally, casinos should routinely engage with law enforcement to obtain a clear understanding of evolving criminal trends and typologies/relevant risks. Casinos must ensure they have a holistic view of patron behavior across business lines and all gaming verticals. Casinos must also have information sharing systems in place to ensure that potentially suspicious activity typically identified and investigated by other departments, such as fraud and security, flows to Compliance for SAR filing consideration. Casinos, particularly online platforms, may want to consider having discrete SAR monitoring and reporting procedures specifically for fraud and cyber-events. Casinos should also consider the extent to which it may be appropriate to leverage information across the entire enterprise in investigating and reporting suspicious activity, including attempted suspicious transactions. In examining SAR procedures, the casinos review should consider the following components for a complete SAR compliance effort:
INTERNAL ESCALATIONS OF SUSPICIOUS ACTIVITY Casinos should incorporate a clear, easy to understand, and prompt internal escalation process for potentially suspicious activity that is reinforced in BSA/AML training and compliance communications. The process should include the reporting individual providing all available information about the transaction(s) or action(s) (e.g., patron name, SSN, players card number, and observed suspicious activity with any supporting documentation) without alerting the patron that their activity has been reported as potentially suspicious. Communication with other departments, such as surveillance, fraud, and marketing personnel, is crucial in ensuring all information is captured surrounding the activity. Each department involved should be providing their account of the potentially suspicious activity to allow the individual responsible for investigating the activity for a potential SAR filing to have a complete picture.
TRANSACTION MONITORING AND DATA MINING Transaction monitoring provides comprehensive and consistent risk-based observation of patron transactions, activity, and behavior, enabling the casino to better detect and report suspicious activity. Transaction monitoring scenarios should be developed based on a casinos risk profile, with specific thresholds related to gaming activity that will generate suspicious activity alerts when those thresholds are triggered. A dedicated compliance team should complete a review of those transactions alerted at or above thresholds, reviewing all patron information available as discussed further below. As highlighted in recent BSA enforcement actions, transaction monitoring scenarios should be regularly reviewed, tested, and updated as appropriate to ensure they remain risk-based, effective, and comprehensive, covering all of the casinos products and services, and appropriately tailored to the casinos specific risk factors and general high-risk typologies. Transaction monitoring should also be supported by automated technology that is appropriately validated, tested, and updated to ensure its continued effectiveness and efficiency. Casinos are increasingly incorporating artificial intelligence technology to enhance their suspicious activity monitoring programs by, for instance, enabling predictive analytics to identify aberrant or otherwise potentially suspicious patron and transaction activity in real time and improving efficiencies through automation. Behaviors or practices considered to be red flags for
18 FinCEN, Recognizing Suspicious Activity Red Flags for Casinos and Card Clubs (July 31, 2008), available at: https://www.fincen.gov/resources/advisories/fincen-guidance-fin-2008-g007.
Casinos should refrain from naming these internal escalations as SARs to avoid unintentional disclosure by employees. A SAR is the final document filed with FinCEN and only those making the final determination will know of the actual filing; whereas these internal notifications are simply the first step in the investigation process.
Suspicious Activity Reporting potential suspicious activity may be entirely legitimate, but casinos should be attentive to the risk that they are not. Given that licit and illicit activity may look the same to the casinos compliance team, application of data analytics and technology should be considered, as these resources may help identify certain specific types of illicit activity, such as bill stuffing in slot machines, minimal gaming, chip walking, front money deposits in cash, large cash buy-ins and/or redemptions to avoid reporting, and revolving markers.
BRICK-AND-MORTAR TRANSACTION MONITORING Unusual patterns of patron behavior on the gambling floor that may suggest a risk of money laundering or other illicit activity may include: ○ Patrons with large cash-in transactions with no cash-out transactions and/or little or no gaming, which cannot be reasonably explained through transaction review ○ Patrons with large cash-out transactions with limited cash in transactions, which cannot be reasonably explained through transaction review ○ Patrons that deposit money into their account and immediately request a withdrawal (of the same or similar amount) ○ Patrons with large cash-out transactions (in the aggregate) with little or no CTR out filings ○ Patrons with large chip-outs with limited redemptions or table buy-ins with chips ○ Patrons with large check cashing transactions and/or credit card advances with limited play ○ Patrons who unexpectedly use multiple sources or multiple destinations for funds or abruptly change the methods used for bringing money into or out of the casino ○ Patrons with significant increases in betting or financial transaction activity without explanation ○ Patrons with cash transactions, such as deposits or withdrawals, including aggregated transactions, that are just below the CTR reporting threshold ○ Patrons using wagering kiosks for multiple small wagers on the same event ○ Un-carded or unrated patrons with large redemptions and jackpot winnings
○ Un-carded or unrated patrons with large, aggregated slot buy-ins with redemptions equaling the buy-ins ○ Several redeemed gaming vouchers (i.e., TITO), in a short period of time, at the same (or adjacent) redemption kiosk not associated with a players card account ○ Checks or wire transfers received for the benefit of a patron (or multiple patrons) from third parties whose connection to the patron is suspect or unclear (or if the maker of the check or initiator of the wire transfer is high risk, such as the holder of an IOLTA account or a PEP) ○ Multiple apparently structured transactions over a period of time with the apparent purpose of avoiding BSA reporting requirements, such as transactions under reporting thresholds, with or without using an agent, or around the business day ○ A single payment received by the casino (e.g., negotiable instrument or wire transfer) for the benefit of multiple patrons if the casino cannot determine a relationship or business association between the source of the payment and the beneficiaries ○ Patron accounts with large account balances that remain dormant or inactive for an extended period of time ○ Patrons who pass winning tickets to others to cash out ○ Patrons who request multiple monetary instruments for a jackpot or wager win ○ Patrons who wager on both sides of a transaction in ways that are not explainable as hedging ○ Patrons who demonstrate no concern for the tax consequences of uncarded play, which may generate large documented income that is not offset by losses ○ Patrons who appear to be coordinating their gaming with another patron or patrons (e.g., passing chips or cash back and forth) to evade notice To maximize incentives (comps, promotional chips, airfare, discounts, and allowances), a player, or group of players working in concert, may often display a number of suspicious behaviors (e.g., passing chips, offsetting wagers, masking their activity, distorting their average wager, or walking with chips). For commercial reasons, casinos may work aggressively to curtail these behaviors with the help of surveillance, operations, and casino marketing. Casinos should exercise caution in assuming these behaviors are simple advantage play strategies that may not be illegal
Suspicious Activity Reporting and remain attentive to the risk that these same behaviors may be employed for money laundering purposes. In some cases, this behavior should be escalated to Compliance as potentially suspicious activity. Compliance personnel can take additional measures to review the potentially suspicious activity, such as reviewing relevant daily audit summaries, logs, and reports, including marker summaries, front-money/safekeeping summaries, multiple transaction logs (MTLs), negotiable instrument logs (NILs), check logs, and wire reports. Third-party transaction summaries should be requested and reviewed when working in partnership with a financial service offered by third parties, such as credit card cash access companies or check guaranty services. When reviewing transactions that cannot be explained through summaries and reports, a secondary review using surveillance should also be considered, if available.
When red flags are identified during the course of a patron relationship, casinos may wish to review any previous transactions with the patron that may appear suspicious in light of the new information and consider whether a SAR is warranted.
ONLINE TRANSACTION MONITORING As the gaming industry expands from traditional brick-and mortar casinos into the online space with interactive slots, table games, peer-to-peer games, and sports wagering, potential money laundering risk factors are also expanding. To keep pace with these activities, compliance personnel should have adequate research capabilities to focus on where transactions originate, how transactions are sent, and the true identity of the people involved.
Unusual activity in the online gaming space that may suggest a risk of money laundering or other illicit activity may include: ○ Online cash or digital wallet deposits with minimal or no play followed by a withdrawal request(s) ○ Cash deposits and withdrawals from a patrons online account or digital wallet at a casino cage that appear to be intended to circumvent CTR recordkeeping requirements ○ Excessive deposits (based on risk) made from different bank accounts, payment processors, or prepaid access cards ○ Deposits originating from one payment method but withdrawing to a different payment method that is not registered to the igaming account (does not apply to credit card deposits) ○ Numerous deposits and/or declined deposits from multiple payment processors or prepaid access cards in a short amount of time ○ Withdrawal requests to multiple bank accounts or payment processors ○ A player account that is accessed using a universally unique identifier (UUID) from multiple devices and/or IP addresses ○ Multiple user accounts using a UUID on the same device and/or IP address ○ Geolocation reports identifying individuals who have violated multiple anti-fraud checks, such as running fake GPS apps along with having mock location settings enabled or using other spoofing methods ○ Repeated deposit and withdrawal requests attempted from outside the authorized state (as detected through geolocation in states where this is prohibited) ○ Player account access and wagering attempts from outside the authorized state (as detected through geolocation) ○ Attempts to make cash deposits and withdrawals from a player account at a casino cage with conflicting or counterfeit identification
As discussed above, apart from a patrons activity at the casino, a casino may learn about red flags for potential suspicious activity from third-party sources during the course of a patron relationship. Those third-party sources might include negative media, court filings, law enforcement, and/or other financial institutions. Casinos should also consistently evaluate relevant subpoenas that are received, especially those associated with financial crimes. While receipt of a criminal subpoena generally will be a trigger for a KYC or SAR review, receipt of a subpoena alone does not require filing of a SAR, unless one of the SAR triggers is satisfied.
SAR INVESTIGATION PROCESS It is important to maintain a consistent approach to the decision-making around SAR investigations and filings, and to ensure such decisions are aligned with the casinos risk profile. Accordingly, casinos should have a documented procedure for how potentially suspicious activity is investigated and decisioned. In addition, it is vital to memorialize those investigations and decisions (including cases in which the casino decides not to file a SAR). An SAR investigation consists of examining all available information to determine whether a SAR should be filed for an escalated or alerted incident(s). The reviews may be prompted by direct observations by employees, system alerts, after-the-fact data analysis performed through back-of-house procedures, or other means (e.g., incoming law enforcement inquiry, 314(b) requests, or public negative news). The AML Officer and/or staff should begin their investigation promptly upon receipt of the internal notification. In doing so, the compliance team should request additional patron data held by relevant casino departments and functions, including but not limited to marketing, to facilitate a proper investigation that includes all available information across the casino relating to the patron and transaction. As made clear in recent BSA enforcement actions, ensuring that information is shared between departments, and that functions and all available information about the patron and transaction is obtained and reviewed by investigators is integral to performing adequate investigative analyses on potentially suspicious activity. Investigators should review and consider, as applicable, the same types of patron records discussed in the preceding section for KYC reviews, all available and relevant transactional records, and any prior KYC reviews conducted on the patron. If a casino does not already have source of funds or source of wealth information for the patron or an update to such information is warranted, the casino should have procedures for collecting the information and considering it as part of the SAR investigation process. The purpose of the investigation is to gather a complete profile of the individual(s) to understand any possible logical purpose for the transaction(s)/action(s) and whether there is, in fact, suspicious activity occurring. Accordingly, as warranted by the nature of the investigation, the compliance team may find it necessary to gather and review additional patron information to understand the patrons behavior and transactions at issue and make SAR filing decisions or, if relevant, recommendations to restrict or terminate a patron relationship.
Regardless of the final determination of whether to file a SAR, SAR investigations should be fully documented, and all investigation materials should be retained for a period of at least five years. Even if records are housed in other systems within the casino, those utilized for the investigation should be saved in a separate location pursuant to the individual investigation.
DECISION TO FILE OR NOT FILE Based on the investigation findings, the AML Officer/ designee will determine if the information warrants a SAR being filed. It may be determined that there is a reasonable, non-suspicious explanation for the transaction(s)/action(s) and that no SAR should be filed. In the event such a determination is made, the reasoning for that decision must be documented and retained. In either event, the designated individual should make a record of the determination and the date the determination was made. AML Officers should either be responsible for reviewing and making SAR filing decisions or have full autonomy to approve or overrule those decisions. Anyone with a direct conflict (e.g., operations, marketing, and finance personnel) should not have decision-making authority for these determinations.
COMPLETING/FILING A SAR The individual responsible for completing a SAR should ensure that the form is completed correctly and thoroughly utilizing all available information. To the extent a casino has the data, optional data fields should be completed, particularly including, email addresses, phone numbers, and occupation. The narrative should clearly and concisely identify the essential elements of the suspicious activity answering the who, what, where, when, and why of the situation being reported. Filers should ensure that all information in the narrative aligns with the other sections of the form, such as dates, amounts involved, and the reported suspicious activity type(s). FinCEN has issued guidance directing financial institutions to include specific terms within SAR narratives (and/or other SAR fields) for certain types of reported activity. Filers should be familiar with that guidance and ensure those terms are appropriately included on SARs involving those typologies. FinCEN maintains a list of those guidance documents and key terms on its website.
Casinos should refrain from using the SAR subjects name within the filing title of the report to avoid potential disclosure of the individuals identity. A secondary review of the drafted SAR is recommended prior to filing. Individuals responsible for completing and reviewing SARs should receive training on writing quality SAR narratives.
SAR Confidentiality Casinos must establish controls for maintaining the confidentiality of SARs and any information that reveals that a SAR was filed or not filed or even considered to be filed. Care must be taken to ensure that no person involved in the transaction is tipped-off that a SAR has been filed or may be filed. SARs and information regarding whether or not a SAR was filed can be shared with federal, state, and local law enforcement and generally with a casinos gaming regulators. However, under 31 C.F.R § 1021.320(e)(1)(ii)(A)(1), a casino may share a SAR with a state or tribal authority only if that agency or authority examines the casino or requires the casino to comply with the BSA. A casino is not permitted to share a SAR with other regulatory authorities that do not have express BSA oversight authority over the casino. Casinos should have procedures in place to verify that a requestor of information of this nature, in fact, has the authority to receive it. If there is any doubt, the gaming regulator should be asked to request the information from FinCEN. Best practice is to require that all SAR requests be in writing. Any casino, and any director, officer, employee, or agent of any casino that is subpoenaed or otherwise requested to disclose a SAR or any information that would reveal the
existence of a SAR, must decline to produce the SAR or such information, citing 31 C.F.R. § 1021.320(e)(1)(i) and 31 U.S.C. §5318(g)(2)(A)(i), and must notify FinCEN of the request and response.
SAR Sharing In general, SAR information should be shared within a casino, and as permitted, across a corporate enterprise, only on a need-to-know basis. Other personnel should not have access to databases or records containing SAR information. While third-party service providers may be utilized to assist in SAR monitoring and investigation efforts, as a best practice, they should generally not be involved in SAR decision-making or reporting, nor have access to SARs and information relating to whether a SAR was or was not filed. To the extent such sharing is permitted, it should only be on a strictly need-to-know basis based on the services they provide to the casino and supported by clear and robust contract terms, security systems, and processes to protect against unauthorized disclosures, further sharing by the third party, and data breaches that may compromise the confidentiality of the SAR information. According to FinCEN guidance, under the BSA and its implementing regulations, a casino that has filed a SAR may share the SAR, or any information that would reveal the existence of the SAR, with each office or other place of business located within the U.S. of either the casino itself, a U.S. parent of the casino, or a U.S. affiliate subject to SAR reporting obligations under the BSA. 19 Casinos may not share SARs or SAR information with foreign parents, affiliates, or offices, nor with U.S. affiliates that do not have BSA SAR obligations. In addition to having a documented policy and process for permissible SAR sharing within a corporate organization, casinos should also have protocols and systems in place to maintain the confidentiality of shared SAR information and restrict further sharing of the information by the recipient. In order to assist law enforcement and safeguard the confidential and sensitive information contained in and that support SARs, casinos should establish a protocol for receiving and responding to authorized requests for SAR supporting documentation without a subpoena. The protocol should address how the casino will respond to subpoenas requesting SARs, and requests for SARs by individuals and agencies not authorized to receive SARs.
19 See FinCEN, FIN- 2017-G001, Sharing Suspicious Activity Reports with U.S. Parents and Affiliates of Casinos (Jan. 4, 2017), available at: https://www.fincen.gov/resources/statutes-regulations/guidance/sharing suspicious-activity-reports-us-parents-and.
In general, SAR information should be shared within a casino, and as permitted, across a corporate enterprise, only on a need-to-know basis.
High-Risk Suspicious Activity Typologies The following categories are examples of potentially suspicious situations that often will prompt consideration of whether a SAR should be filed under the casinos risk assessment criteria.
GAMING FLOOR ACTIVITY ○ Minimal gaming despite large financial transactions with the casino ○ Structuring of transactions to stay at or slightly below the $10,000 reporting threshold for CTRs ○ Placing currency in a slot machine, then cashing out after minimal or no play and redeeming the TITO ticket at a kiosk on the gaming floor (bill stuffing) ○ A transaction that has no apparent economic, business, or lawful purpose (e.g., confederated gamblers placing offsetting bets on red and black on a roulette wheel) ○ Patrons passing a large quantity of chips, cash, or TITO tickets between themselves, in an apparent effort to conceal the ownership of the chips, cash, or TITO tickets (although if patrons are closely related, such activity may not be suspicious) ○ A patrons gaming activity dramatically increases with no known substantiation for the source of those funds ○ A patron uses another patrons player card to disguise their identity and/or evade reporting requirements ○ A patron leaves the casino floor with a significant amount of chips without offsetting chip redemptions or chip buy ins at another table, and there is no known disposition or whereabouts of the chips (although this may not be deemed suspicious if there is a reasonable, experience based expectation that the patron will return to the casino in the near future) ○ A patron that accesses a safety deposit box at the casino with a frequency that is disproportionately high when compared to the time and frequency of their play ○ A patron identified as a loan shark is observed approaching patron(s) ○ A patron requests large amounts of cash from an ATM but has no gaming activity
RACE AND SPORTSBOOK ACTIVITY ○ Inquiring with race and sportsbook staff about reporting and identification thresholds either before or after a wager and possibly adjusting wagering activity to fall below the applicable thresholds ○ At a racing venue, inserting cash into a tote machine, cashing out for vouchers and then cashing vouchers at a tellers station with little or no wagering ○ Structuring wagers across multiple tickets/locations so the payout of each ticket is under the reportable identification thresholds, but in the aggregate, would have exceeded the thresholds ○ Behavior that may be indicative of coordinated betting (or betting on both sides of a game or an event) ○ Indications of insufficient wealth or income to support betting patterns ○ Significant changes in wagering patterns or unusual spikes in play that are unexpected or unreasonable ○ A patron misrepresenting themselves by presenting false or multiple identities or providing inconsistent SSNs on completed W-9s ○ Presenting a large amount of money in an unusual volume of small denominations ($1, $5, $10, and $20) ○ Placing a bet on both sides of the line ○ Information indicating that a patron may be betting on behalf of an unknown third party ○ Ticket redemption by an individual that is not known to have placed the initial bet
INTERACTIVE GAMING ACTIVITY ○ Multiple gaming accounts being set-up from the same device, IP address, or physical address ○ Unusual wagering activity that appears to lack any legitimate economic purpose ○ Significant changes in wagering patterns or unusual spikes in play that cannot be readily explained
Suspicious Activity Reporting ○ Deposits and withdrawals into an online account without sufficient play to account for such activity ○ Unusual patron behaviors based on geolocation data, such as traveling between jurisdictions in a relatively short period of time or multiple attempts to anonymize geolocation data ○ Deposit(s) to a gaming account that are determined to be from stolen credit, debit, or pre-paid access cards
CAGE-FOCUSED ACTIVITY ○ Presenting a third-party check or wire transfer — whether apparently deriving from a business or an individual — for payment of markers or for use in gambling-related activity in an amount at or above a threshold determined by the risk assessment for that casino In such situations, the casino should ascertain whether the beneficiary (patron) has a documented connection to the sender (e.g., spouse or immediate family member or business), either in the casinos records or by means of a database search or other reasonable inquiry. If no appropriate connection can be established between the source of the funds and the patron, those employees responsible for deciding whether to file a SAR also may consider whether or not to proceed with the transaction. ○ A negotiable instrument or wire transfer is presented for the benefit of multiple patrons, or multiple patrons engage in play on a single patron account ○ A negotiable instrument or wire transfer is presented for the benefit of an individual and originates from a law firm account, or is from a charitable/nonprofit organization or foundation, another type of trust or labor union account ○ A patron refuses to provide required information for the completion of a CTR or identifying information ○ A patron from a country with currency controls (e.g., China) has significant cash-in transactions ○ A patron deposits funds into a front money account or receives a wire transfer, does not play a substantial amount of the funds, then requests a withdrawal or wire out ○ A patron deposits large sums of cash into a front money account and their known occupation is not a cash intensive business
○ A patron requests information about how to avoid BSA reporting requirements ○ A patron requests establishment of an AKA account in a name other than the one by which the casino knows the patron ○ A patron attempts to deposit front money or make payments using complex means, such as multiple sources of funds or multiple methods of transmission, which could mask the true source of the funds transmitted ○ A patron presents funds that the casino has a basis for suspecting to be the proceeds of illegal activity ○ A patron requests a cash advance from a credit card that has been identified as possibly fraudulent ○ A patron uses multiple credit cards to request cash advances ○ A patron is observed requesting large amounts of cash from an ATM but has no gaming activity ○ A patron presents funds in any form that derive from a foreign jurisdiction declared by the U.S. government to be a jurisdiction of concern for narcotics trafficking, human trafficking, money laundering, terrorism, or other illicit activity; or if the foreign jurisdiction has been identified as high risk or subject to increased monitoring by the Financial Action Task Force; or by Transparency International or similar reputable organization as a country with a high degree of public corruption 20
○ A patron provides a wire transfer, cashiers check, or other form of payment and such instrument reflects that the transaction is being made for a purpose other than gaming ○ A patron presents chips for cashing and there is little or no gaming activity recorded for the patron in the casinos system to establish the source of the chips
INFORMATION FROM BACK OF THE HOUSE ○ Law enforcement or regulatory agencies deliver to the casino a formal request for records concerning the patron ○ News articles or other media reports allege acts of financial wrongdoing or other illegal conduct by the patron
20 See State Department, Annual International Narcotics Control Strategy Report (Mar. 2025), available at: https://www.state.gov/wp-content/uploads/2025/03/2025-International-Narcotics-Control-Strategy-Volume 2-Accessible.pdf; FinCEN, Financial Action Task Force Identifies Jurisdictions with Anti-Money Laundering, Countering the Financing of Terrorism, and Counter-Proliferation Finance Deficiencies (Feb. 23, 2025), available at: https://www.fincen.gov/news/news-releases/financial-action-task-force-identifies-jurisdictions-anti-money-laundering-3.
Suspicious Activity Reporting ○ A patron is the owner of a business, the nature of which has been profiled by the FTC as high risk for fraud schemes ○ A patron is an owner, employee, or otherwise associated with a marijuana-related business ○ A patron raises their financial transactions to levels well above the ordinary levels for that patron with no reasonable explanation ○ An external actor attempts to compromise or gain unauthorized electronic access to the casinos electronic systems, services, resources, or information in pursuit of illegal activities 21
This list is by no means exhaustive; other patron activities may trigger BSA/AML concerns due to the circumstances in which they arise. Each casino should develop its own scenarios tailored to its business. Further, the SAR requirement encompasses suspicious activity conducted by employees/insiders. Therefore, casinos should have adequate communication lines between the group(s) responsible for employee-related investigations and disciplinary issues, and the team(s) responsible for filing SARs to ensure detection of potential collusion between an employee and patron to circumvent internal policies or ordinary practices, or an employees violation of casino policies and procedures. In addition to filing SARs, casinos should be aware of and comply with state reporting requirements for insider abuse activity, as applicable.
21 FinCEN, FIN-2016-A005, Advisory to Financial Institutions on Cyber Events and Cyber Enabled Crime (Oct. 25, 2016), available at: https://www.fincen.gov/sites/default/files/advisory/2016-10-25/Cyber%20 Threats%20Advisory%20-%20FINAL%20508_2.pdf.
MONTH 2014 2015 2016 2017 2018 2019 2020 2021 2022 2023 2024
January 3,223 4,219 4,366 4,515 4,924 4,633 4,519 3,653 5,422 5,186 5,840
February 2,950 3,757 4,485 4,629 4,047 3,889 4,418 4,029 4,603 5,192 4,666
March 3,222 3,774 5,269 6,303 4,694 4,710 4,067 4,286 5,833 5,690 6,061
April 3,239 4,099 5,093 5,238 4,556 4,605 1,024 4,195 5,067 4,903 5,692
May 3,501 4,110 4,358 5,156 4,700 4,753 352 4,269 5,163 5,741 5,292
June 3,438 4,201 4,662 4,952 4,436 3,886 1,298 4,609 5,254 5,313 5,140
July 4,415 4,376 4,910 4,440 4,476 4,285 3,659 4,982 4,866 4,887 5,373
August 4,663 3,986 5,607 5,257 4,517 4,138 3,697 4,742 5,546 5,735 5,521
September 3,999 4,447 5,130 4,875 4,195 4,240 4,067 5,139 5,064 5,024 5,106
October 4,327 4,348 4,379 4,705 4,361 4,173 4,360 4,682 5,119 4,939 6,155
November 3,917 3,844 4,587 4,391 4,469 3,949 3,914 5,045 5,099 4,747 4,952
December 4,291 4,398 4,472 4,706 4,216 4,038 4,105 5,306 4,966 5,124 5,297
Subtotal 45,185 49,559 57,318 59,167 53,591 51,299 39,480 54,937 62,002 62,481 65,095
Total Filings 600,114 * Statistics generated for this report were based on the Bank Secrecy Act Identification Number (BSA ID) of each record within the Suspicious Activity Report (SAR) system. The BSA ID is a unique number assigned to each SAR submitted. Numeric discrepancies between the total number of filings and the combined number of filings of states and/or territories are a result of multiple locations listed on one or more SARs. Note: Statistical data for SARs is continuously updated as information is processed. For this reason, there may be minor discrepancies between the statistical figures contained in the various portions of this report.
FinCEN Suspicious Activity Report (Form 111)
EXHIBIT 1: FILINGS BY YEAR & MONTH FROM CASINO/CARD CLUB INDUSTRY* January 1, 2014 through December 31, 2024
Restricting and Terminating Patron Relationships
Restricting and Terminating Patron Relationships
Based on information obtained regarding a patron, a casino may consider whether to terminate or restrict its relationship with the patron. There should be a documented process for making these decisions that addresses, at a minimum: ○ When and how patron relationships should be escalated to be considered for restriction or termination ○ Who is responsible for reviewing and making restriction/ termination decisions (typically, the AML Officer) ○ What factors will be considered when making restriction/ termination decisions ○ Timing for reviewing and decisioning a restriction/ termination escalation ○ Any procedures to appeal, rereview, or overrule restriction/ termination decisions ○ A requirement that restriction/termination escalations and decisions, including reasoning, are fully documented and maintained for at least five years after the patron relationship ends AML Officers should either be responsible for reviewing and making restriction/termination decisions or have full autonomy to approve or overrule those decisions. Anyone with a direct conflict (e.g., operations, marketing, and finance personnel) should not have decision-making authority for these determinations. The following are examples of factors that may trigger a review of a patron relationship for potential termination or restriction or otherwise be considered when making patron termination and restriction decisions: ○ Multiple SAR filings on the same patron ○ Severity and recency of alleged criminal activity (e.g., terrorist financing) ○ Suspected versus confirmed criminal activity ○ Use of all available information ○ Indication that the patron has an illegal source of funds for gaming or is using the casino for an illegal purpose ○ Risk to the casino if the patron is not excluded While multiple SAR filings on the same patron is one factor as to whether a relationship should be terminated, other factors, such as the severity of the conduct, should also be considered. Consequently, one SAR filing may be sufficient to terminate the relationship with a patron if the patron has an illegal source of funds or is using the casino for an illegal purpose. The assessment should consider whether the activity prompting the SAR is merely suspicious or known criminal conduct, with the understanding that decisions on restrictions or terminations may still be warranted based on suspected but not confirmed activity, depending on the facts and circumstance. The greater the likelihood of known criminal activity, the greater the risk to the casino if the relationship is not terminated. As noted, the assessment process should be documented in the casinos policies and procedures for performance consistency, along with a list of factors that would require the assessment to occur. Termination of a patron relationship will be warranted if the patrons activities present an actual or unacceptable risk of violation of federal or state law or regulation, the casinos compliance policies, or pose significant concerns that a patrons source of funds used for gaming stems from illegal activity or that a patron is using the casino to facilitate illegal activity. AML bans should be enforced across the entirety of a corporate enterprises properties and gaming platforms. Law enforcement may utilize a specific request to “keep open” accounts and/or request casinos to maintain patron relations as part of their investigative efforts to identify and combat money laundering, terrorist financing, and other illicit financial activities. Law enforcement “keep open” requests to the casino should be in writing and detail that the law enforcement agency is requesting the casino to maintain the account, as well as include the purpose and duration of the request. The BSA includes a safe harbor that protects financial institutions, including casinos, that comply with such a keep open request from liability and adverse supervisory action under the BSA for maintaining the account or transaction consistent with the parameters and timing of the request. 22
While casinos generally will endeavor to accommodate keep open requests, casinos are not obligated to agree to do so. The decision to maintain a patron relationship, keep open accounts, and/or terminate a patron relationship is ultimately up to the casino, based on its risk tolerance. Record retention policies should address how long the casino will maintain the request, including after the request duration period has expired. Casinos are still required to comply with all applicable BSA requirements even when the casino agrees to “keep open” the account/patron relationship as requested from law enforcement, including suspicious activity monitoring and reporting requirements.
22 31 U.S.C. 5333.
Currency
Reporting
Requirements
CURRENCY TRANSACTION REPORTS 40
CURRENCY OR MONETARY INSTRUMENT REPORTS 41
Currency Reporting Requirements
Currency Transaction Reports
Casinos are required to currency transactions reports (CTRs)
on each transaction in currency involving cash-in or cash-out
of more than $10,000.
Transactions in currency involving cash-in include, but are
not limited to:
○ Purchases of chips, tokens, and other gaming instruments
○ Front money and digital wallet cash deposits
○ Safekeeping deposits
○ Payments on any form of credit, including markers and
counter checks
○ Bets of currency, including money plays
○ Currency received by a casino for transmittal of funds
through wire transfer for a patron
○ Purchases of a casino check
○ Exchanges of currency for currency, including foreign
currency
Transactions in currency involving cash-out include, but are
not limited to:
○ Redemptions of chips, tokens, and other gaming
instruments
○ Front money and digital wallet currency withdrawals
○ Safekeeping withdrawals
○ Advances on any form of credit, including markers
and counter checks
○ Payments on bets
○ Payments by a casino to a patron based on receipt
of funds through wire transfer for credit to a patron
○ Cashing of checks or other negotiable instruments
○ Exchanges of currency for currency, including foreign
currency
○ Travel and complimentary expenses and gaming incentives
○ Payments for tournaments, contests, or other promotions
Multiple currency transactions must be treated as a single transaction if the casino knows they are by or on behalf of the same person and result in either cash-in or cash-out totaling more than $10,000 during any gaming day. A casino is considered to have such knowledge if any director, partner, or personnel, acting within the scope of their employment, knows that multiple currency transactions have occurred from reviewing available information. Transactions in and out do not offset each other for reporting purposes. In addition, transactions in and out are separately aggregated but can be reported on a single CTR form for the same gaming day. Before concluding any transaction for which a CTR must be filed, casinos must collect and verify the patrons identity using the ID&V processes, as discussed above. Casinos should have processes and systems in place to ensure that they are properly tracking and aggregating transactions using all available transaction data sources to enable them to identify when a CTR will need to be filed and to either verify that ID&V information for the patron is already on file or, if not, complete ID&V processes prior to conducting the transaction that would trigger the reporting requirement. If the transaction is being performed for or on behalf of someone other than the person engaging in the transaction, ID&V should be performed for both individuals. Casinos must file a CTR within 15 calendar days following the day the reportable transaction occurs, and they should be maintained for at least five years.
Currency Reporting Requirements
Currency or Monetary Instrument Reports Casinos must file CMIRs if they transport, mail, ship, or has someone else transport, mail, or ship currency or monetary instruments in excess of $10,000 into or out of the country or receives such items into the U.S. from abroad. A CMIR is filed with the Bureau of Customs and Border Protection. Casinos should have processes and controls in place to ensure they properly file CMIRs whenever engaging in such activity. Alternatively, if a casino has policies against engaging in such activity, it should be documented in the AML/CFT Program and reinforced by controls, as appropriate.
8300 All U.S. trades and businesses — that are not subject to the BSAs CTR reporting requirements — must file 8300 reports for currency transactions aggregating over $10,000 that they receive from or on behalf of a person within a 24-hour period, or in related transactions over a rolling 12-month period. Currency for purposes of this reporting requirement includes cash, and for certain transactions — including those involving retail sales of entertainment or travel — a cashiers check, travelers check, or money order in an amount less than $10,000. Casino enterprises should have, as part of their AML/CFT Program, 8300 reporting procedures and controls for their non-gaming businesses (e.g., hotels, live entertainment, catering, restaurants, and shops). Similarly, any gaming or sports betting entities that are not BSA-regulated financial institutions subject to CTR requirements should have procedures and controls designed to ensure their compliance with 8300 reporting requirements.
Information
Sharing
INFORMATION SHARING ACROSS AN ENTERPRISE 43
INFORMATION SHARING WITH PARTNERS/SERVICE
PROVIDERS 43
314(B) INFORMATION SHARING 44
OTHER INFORMATION SHARING RESOURCES 44
Information Sharing
Information Sharing Across an Enterprise As discussed above, it is imperative that casinos have effective and easily accessible information-sharing mechanisms across their various departments, business lines, and verticals. This is necessary to enable Compliance to have and consider all available information relating to patrons and transactions, as required to comply with BSA suspicious activity monitoring and reporting requirements. These information-sharing processes and systems to Compliance should include, but not be limited to, Marketing, Surveillance, E-Commerce/Cage, Human Resources, Operations, Surveillance/Security, Fraud, Legal, Customer Support, Risk, and Internal Audit. Information sharing mechanisms should also ensure that internal audit, independent assessment, and exam findings and recommendations are timely shared with the AML Officer, senior leadership, and, as appropriate, others responsible for reviewing and updating AML/CFT Program functions. Casinos should also consider the extent to which it may be appropriate to leverage information across the entire enterprise in investigating and reporting suspicious activity, including attempted suspicious transactions. Personnel should receive regular compliance training and communications regarding their duty to use information sharing mechanisms and how to use them. See the SAR Confidentiality section above for internal sharing restrictions and best practices for SAR information.
Information Sharing with Partners/Service Providers Casinos should have clear and detailed contract terms and supporting procedures around information-sharing requirements for third-party relationships that address, at a minimum: ○ A casinos full and timely access to all patron information and other records associated with BSA-related functions ○ The third partys obligation to promptly notify the casino of potentially suspicious activity or other illicit activity ○ Minimum security measures that the third party must maintain for information it has or receives ○ Restrictions on the third partys disclosure to other third parties and use of information ○ Recordkeeping requirements that the third party must implement for casino information Casinos should have clear privacy terms for their patron relationships that authorize them to use and share patron information as necessary to comply with laws/regulations, cooperate with law enforcement, and provide the casinos products and services. Likewise, casinos should ensure that any information sharing with third parties, including partners and service providers, is permissible under their patron terms and does not violate applicable laws or regulations. As mentioned above, SARs and information regarding whether or not a SAR was filed should generally not be shared with third-party partners and services providers, and to the extent permitted, it should only be on a strictly need-to-know basis based on the services they provide to the casino and supported by clear and robust contract terms and security systems and processes to protect against unauthorized disclosures, further sharing by the third party, and data breaches that may compromise the confidentiality of the SAR information.
Information Sharing
314(b) Information Sharing Casinos are encouraged to participate in the valuable voluntary information-sharing program with other entities defined as financial institutions under Section 314(b) of the USA PATRIOT Act and who are required to maintain AML/CFT Programs under the BSA regulations. This program, and other formal and informal information sharing mechanisms, are a FinCEN priority and are vital to ensuring casinos and other financial institutions can obtain necessary information about their patrons/customers. 23
In its most recent 314(b) fact sheet, FinCEN highlights the following benefits of the information-sharing program 24: ○ While information sharing pursuant to Section 314(b) is voluntary, it can help financial institutions enhance compliance with their AML/CFT requirements, most notably with respect to: Gathering additional information on patrons or transactions potentially related to money laundering or terrorist financing, including previously unknown accounts, activities, and/ or associated entities or individuals Shedding more light upon overall financial trails, especially if they are complex and appear to be layered among numerous financial institutions, entities, and jurisdictions Building a more comprehensive and accurate picture of a patrons activities that allows for more precise decision-making in due diligence and transaction monitoring processes for that patron ○ Alerting other participating financial institutions of patrons with suspicious activities they may not have been previously aware of ○ Facilitating the filing of more comprehensive SARs ○ Identifying and aiding in the detection of money laundering and terrorist financing methods and schemes ○ Facilitating efficient SAR reporting decisions — for example, when a financial institution obtains a more complete picture of activity through the voluntary information sharing process and determines that no SAR is required for transactions that may have initially appeared suspicious Casinos that participate in 314(b) should have protocols in place regarding when 314(b) information sharing should be utilized, the timing and manner for responding to 314(b) requests, and verifying that a financial institution or association of financial institutions is on the 314(b) participant list, prior to requesting information from or sharing information with that institution or association. Participating casinos must also have protocols in place to safeguard the security and confidentiality of shared information. They should implement policies and training designed to ensure that they only share information when they have a reasonable basis to believe that the information relates to activities that may involve money laundering or terrorist financing, and that shared information is only used for the purpose of: ○ Identifying, and where appropriate, reporting on activities that may involve terrorist financing or money laundering ○ Determining whether to establish or maintain an account, or to engage in a transaction ○ Assisting in compliance with AML requirements All 314(b) requests and responses should be fully documented and maintained for at least five years.
Other Information Sharing Resources Casinos may also benefit from information sharing on suspicious activity trends and typologies impacting the industry or of particular interest to law enforcement by participating in local, regional, and national working groups and attending BSA/AML and industry conferences.
23 See also FinCEN, Advisory to U.S. Financial Institutions on Promoting a Culture of Compliance, FIN-2014-A007 (Aug. 11, 2014), available at: https://www.fincen.gov/resources/advisories/fincen-advisory-fin 2014-a007; Prepared Remarks of FinCEN Director Kenneth A. Blanco, delivered at the 11th Annual Las Vegas Anti-Money Laundering Conference and Expo (Aug. 2018), available at: https://www.fincen.gov/ news/speeches/prepared-remarks-fincen-director-kenneth-blanco-delivered-11th-annual-las-vegas-1. A 2016 study by Ernst & Young for the American Gaming Association surveyed officials from twenty-three law enforcement and gaming regulatory agencies and found that the casino industry has made concerted efforts to enhance AML compliance and reporting. Investing in Americas Financial Security: Casinos Commitment to Anti-Money Laundering Compliance, p. 27, available at: https://www.american- gaming.org/wp-content/uploads/2018/12/AGA-AML-Research-Report-Final-011916.pdf. 24 FinCEN, Section 314(b) Fact Sheet (Dec. 2020), available at: https://www.fincen.gov/sites/default/files/shared/314bfactsheet.pdf.
Independent
Reviews
INDEPENDENT TESTING PROCEDURES FOR CTRs 47
INDEPENDENT TESTING PROCEDURES FOR SARs 47
Independent Reviews
The independent testing must cover all elements of the casinos AML/CFT Program, including but not limited to: ○ KYC and customer due diligence processes ○ Transaction monitoring ○ SAR and CTR reporting ○ Recordkeeping ○ Training ○ The AML Officer function The scope and frequency of independent testing should be proportionate to the money laundering and terrorist financing risks posed by the products and services provided by the casino. 26 Casinos should generally conduct independent testing at least annually, and more frequently when there are significant changes in the casinos risk profile, systems, compliance staff, or processes. More frequent independent testing may also be appropriate when errors or deficiencies in some aspects of the AML/CFT Program have been identified or to verify or validate mitigating or remedial actions.
The independent auditors should report their findings directly to the AML Officer and any other senior management officials who have the authority to remediate the audit findings and ensure corrective action is taken. Casinos should have protocols in place to ensure the AML Officers prompt and adequate subsequent reporting of the results of independent testing to the board of directors and other senior leadership with oversight responsibilities for the AML/CFT Program. The casino should undertake corrective action or make a specific documented determination that no such action is necessary for each audit finding. 27
All audit procedures performed by independent auditors and their reports and findings, as well as corrective actions taken by a casino, should be fully documented and maintained for at least five years.
The BSA regulations require periodic, risk-based independent testing of the casinos AML/CFT Program by qualified independent auditors. Independent testing may be conducted by Internal Audit, outside auditors, consultants, or other qualified independent parties. In either case, the party testing the program must be independent, experts in BSA regulatory requirements and conducting audits, unbiased, and without conflicting business interests that may influence the outcome of the independent review. Internal auditors should not have operational responsibilities or be involved in or report to teams responsible for AML/CFT functions. For instance, Surveillance is typically integral to the casinos AML/CFT Program, so their required audit could be viewed as a potential conflict of interest. Similarly, external auditors should not be involved in developing, testing, or performing AML/CFT functions. Additionally, a regulatory examination of the casinos AML/CFT Program by governmental authorities does not qualify as independent testing under the BSA. Safeguarding the integrity and independence of the compliance program testing enables an institution to locate and take appropriate corrective actions to address AML/CFT deficiencies. 25
25 FinCEN, FIN-2014-A007 Advisory to U.S. Financial Institutions on Promoting a Culture of Compliance, at p. 4 (Aug. 11, 2014), available at: https://www.fincen.gov/resources/advisories/fincen-advisory-fin
2014-a007.
26 31 C.F.R. § 1021.210(b)(2)(ii).
27 FinCEN, FIN-2010-G003, Casino or Card Club Compliance Program Assessment (June 30, 2010), available at: https://www.fincen.gov/resources/statutes-regulations/guidance/casino-or-card-club-compliance
program-assessment.
Independent Reviews
Independent Testing Procedures for CTRs Separate from the independent testing of the program, on a scheduled basis, the casinos independent auditor, or audit team for CTR filings, should review currency transactions by using all relevant records, including but not limited to MTLs, player-rating records, and patron deposit and withdrawal records, that were prepared during the gaming day reporting period, as well as all system reports for the period. An initial audit should ensure: ○ That a CTR has been prepared for all reportable transactions — either single or aggregated — that exceed $10,000 ○ That the information recorded on the CTR is complete and accurate ○ CTRs were electronically filed within 15 days of the transaction date If the initial findings indicate possible weaknesses in the AML/CFT Program, the audit may need to be expanded to confirm or disprove those indications. The monetary/negotiable instrument log (MIL/NIL) should also be reviewed by independent auditors for proper completion and for retention for at least five years. A system query should identify any patrons that completed transaction(s) in currency involving either cash-in or cash-out higher than the threshold determined by the casinos risk assessment. For patrons who have reached the log threshold for the gaming day, the total of the currency paid or received shall be entered into the MTL for reporting when required by law. All currency transactions above an amount established by the risk assessment for the casino will be logged, with the exception of slot jackpots, which are not reportable on CTRs. Exception notices will be prepared for all instances of noncompliance noted during the daily audit, including but not limited to, logging errors, MIL/NIL completion errors, inaccurate identification, missing information, and other requirements not met. The exception notices should be sent to applicable casino supervisory personnel at the conclusion of the independent audit and secondary review. Exception notices should be
returned within a reasonable, time indicating corrective action taken, and the results of these periodic audits should be part of the firms overall independent testing.
Independent Testing Procedures for SARs The independent testing function should establish testing parameters for both SAR and no-SAR decisions. This review will evaluate the completeness of investigation processes and documentation, timeliness of review and reporting, record retention, and safeguards from disclosure. 28 In instances where SARs were filed, the independent auditors should test the completeness of SAR fields, narratives, and the timeliness of filings. This review should also test the casinos monitoring systems, including how the system(s) fits into the casinos overall suspicious activity monitoring and reporting processes, as well as their programming methodology and algorithms, to ensure the scenarios are adequately detecting potentially suspicious activity. When evaluating the effectiveness of the casinos monitoring systems, independent auditors should consider the casinos overall risk profile based on its products, services, patrons, entities, geographic locations, volume of transactions, and adequacy of staffing. Independent reviews should also test information flow across the casino, including but not limited to fraud, security, marketing, and human resources functions, to compliance personnel responsible for SAR monitoring, investigation, and reporting processes.
28 See FinCEN, FIN-2012-A002, SAR Confidentiality Reminder for Internal and External Counsel of Financial Institutions (Mar. 2, 2012), available at: https://www.fincen.gov/sites/default/files/advisory/FIN 2012-A002.pdf. Additional risk-based measures to enhance the confidentiality of SARs could include, among other appropriate security measures, limiting access on a “need-to-know” basis, restricting areas for reviewing SARs, logging of access to SARs, using cover sheets for SARs or information that reveals the existence of a SAR, and/or providing electronic notices that highlight confidentiality concerns before a person may access or disseminate the information. See also IRS, Examination Techniques for Bank Secrecy Act Industries: 4.26.9.3.7 Review of Records, at (7)(c), available at: https://www.irs.gov/irm/part4/irm_04-026-009.
Employee Training
Employee Training
Casinos are required to provide ongoing BSA/AML training to personnel. The extent and intensity of the training should vary according to the responsibilities of the employee but should always address, at a minimum: ○ BSA/AML requirements ○ Recent BSA/AML regulatory guidance and enforcement actions ○ The casinos AML/CFT Program components and commitment to compliance ○ CTR and SAR reporting and confidentiality requirements and associated internal procedures ○ Identifying and escalating relevant red flags for suspicious activity ○ How BSA reports are used by government agencies Training should be department-specific, so that trainees understand their role in the overall AML/CFT Programs success and how the particular transactions they conduct and the patron interactions they have fit into it. Trainees should gain an understanding of red flags for suspicious activity that may arise from the transactions they handle and the patron interactions they are likely to encounter, consistent with the risks identified in the casinos risk assessment. Training for personnel who regularly interact with patrons, such as those in marketing, should include focused emphasis on SAR confidentiality requirements. Employees who may encounter transactions governed by the BSA should receive training before functioning alone in that capacity, when newly hired or promoted, and on an ongoing annual basis. Training should take place more frequently, as needed, to address changes in the law or the casinos AML/ CFT Program that impact their role and responsibilities. Likewise, training materials should be updated regularly to reflect regulatory and enforcement developments under the BSA and any changes to the casinos AML/CFT policies and procedures. Training should also be appropriate for the level of seniority and responsibilities of employees and management. Consequently, senior leadership should receive different AML/ CFT training than frontline supervisors and employees. The responsibilities of more senior personnel may tend to involve more oversight and assessment of risk, so AML/CFT training should be tailored to these roles accordingly. At a minimum, AML/CFT training should extend to the following general categories of employees:
○ Those engaged in the operation of casino games (table games, poker, slots, keno and bingo, and racing and sports betting — both retail and online), beginning at minimum with supervisors and above. If a casino elects to not train dealers, they should consider messaging for recognizing and reporting suspicious activity ○ Casino marketing employees whose job requires direct contact with patrons, including domestic and international hosts, branch office employees, and special events employees ○ Cage employees ○ Credit, Collections, and other Payments department employees ○ Surveillance employees ○ Employees in BSA/AML, Fraud, Responsible Gaming, and other Compliance departments ○ Audit employees, including Internal Audit ○ Senior leadership, including the board of directors, senior gaming management, audit committee, and compliance committee, as applicable ○ Any other employee(s) with a responsibility to AML compliance Training on BSA/AML policies and Form 8300 reporting for non-gaming employees (high-end retail, nightclubs, convention sales, hotel, and food and beverage) should be incorporated into their respective job training, as relevant to their functions. BSA/AML training programs may include a variety of formats, including in-person training, live remote training, and interactive online training. Training should be interactive and offer participants the opportunity to ask questions, either during or following the training. On-the-job training is also an important component and provides real-life context to supplement official training materials. There should also be a testing component that ensures comprehension of the material, and a signed acknowledgement form agreeing to comply with the casinos BSA/AML policies. Casinos should have procedures and controls for tracking and ensuring training completion, including measures to ensure employees who are on leave during regularly scheduled training complete the training upon return. All training materials, including material provided or shown to trainees, test scores, trackers, and signed acknowledgements, should be maintained for at least five years.
Recordkeeping and Retention
Record Keeping and Retention
Casinos must have procedures to maintain and retain the
specific transactional, patron, and other records required
under the BSA and must retain records about the execution
of all aspects of its BSA program.
The casino shall adopt a recordkeeping system to preserve,
among other BSA-related records, the following records for at
least five years:
○ MTLs
○ MILs/NILs
○ CTRs
○ SARs, and SAR supporting documentation, including
surveillance records, records of SAR investigations and
SAR decision-making
○ Training and testing materials and records of who was
trained and when
○ Patron KYC and due diligence records, including:
A record of specific procedures performed to analyze a
patrons gaming patterns and financial transactions
Any due diligence reports created
Any risk determination
Any action taken as a result, including termination or
monitoring of the patron, reports to law enforcement
agencies, or changes in casino services available to the
patron
○ Records of independent testing, quality assurance testing,
and actions taken in response to each
Patron due diligence records should be maintained for at
least five years after the relationship is terminated or the
patron is no longer active.
Anti-Human Trafficking
Anti-Human Trafficking
Human trafficking, with an estimated 25 million global victims annually, is a pervasive human rights offense and a form of modern-day slavery. It is one of the most profitable forms of transnational organized crime with far-reaching impacts. Traffickers do not discriminate as to where they operate — human trafficking has been reported in all 50 states — and can also be family members or known to their victims. Traffickers take advantage of legitimate industries and supply chains to find, exploit, and traffic victims. This is especially true for the travel and tourism industry — including casino gaming — when properties are unwittingly used to facilitate criminal activity. Human trafficking may be linked to other illegal enterprises such as narcotics or firearms trafficking, terrorist organizations, and money laundering. Eradicating human trafficking is a complex process that requires government, law enforcement, business, and the public to work together on proactive solutions that identify traffickers, address the underlying causes of these crimes, and provide support for victims. The gaming industry plays an important role in combating human trafficking. Gaming operations have been used to facilitate human trafficking. In particular, physical casinos or resorts can be locations for actual trafficking to take place, while casinos and online gaming apps can be used to launder money related to trafficking operations. RED FLAGS FOR POTENTIAL HUMAN TRAFFICKING Casino employees should be aware of different warning signs that could indicate human trafficking. One indicator does not necessarily equate to trafficking, but it is important to be aware of red flag indicators that include, but are not limited to: ○ Signs of abuse (verbal or physical) ○ Signs of poor hygiene, malnourishment, or fatigue ○ Fearful, anxious, or submissive behavior ○ Individuals not allowed to control their cell phone, ID, hotel key, or money ○ Guests overly concerned about surveillance or security on
premises, avoiding interactions with security personnel or the sightlines of cameras, or scoping out the perimeter of the casino floor ○ Individuals approaching patrons whom they do not seem to know, who appear inebriated, or are winning big at gaming tables ○ Individuals or groups making recurring and frequent trips between the casino floor and hotel rooms ○ Rooms booked for large numbers of people and/or rooms booked in the name of guests with a local address ○ Excessive requests for sheets and/or towels ○ Multiple individuals going in and out of one room ○ Individuals speaking in a scripted, repetitive manner ○ Refusing to cooperate with security or floor personnel when approached or giving evasive or non-responsive answers to questions ○ Individuals of similar age, ethnicity, tattoos, or dress accompanied by a potential trafficker ○ Individuals who appear unfamiliar with casinos, seem unsure of how games work, where to congregate, or floor rules Conversely, individuals may also frequent the casino and are intimately aware of how the operation runs, show aggressive behavior in response to questions, or flee at the first sign of security or law enforcement personnel. ○ Individuals monitoring or controlling the movements of another person or using hand signals to communicate ○ Multiple visits to the property by an individual with multiple different accompanying patrons ○ Disparity in age between individuals that are together ○ Someone dropping off or picking up other individuals multiple times or waiting onsite at parking structures, facility exits, or drop off locations to meet people
The gaming industry plays an important role in combating human trafficking.
Anti-Human Trafficking
HUMAN TRAFFICKING AND AML Team members whose role includes observing for signs of money laundering should be aware of the following behaviors. At the cage, watch for the involvement of a third party who insists on: ○ Being present for another persons money transactions, or who speaks on behalf of the customer conducting the transaction. ○ Filling out paperwork for another customer, without consulting that person. Other financial transactions related to human trafficking operations could involve a customer who: ○ Uses or attempts to use third-party identification for a financial transaction. ○ Transaction history that shows different geographic locations. ○ Frequently makes cash deposits with no Automated Clearing House (ACH) payments. ○ Frequently purchases and uses prepaid access cards. ○ Has an account that shares common identifiers, such as a telephone number, email, and social media handle, or address, associated with escort agency websites and commercial sex advertisements. STEPS TO TAKE ○ Should you or any team member observe signs or behavior that suggests exploitation or trafficking, or if concerns arise for someones welfare, you must follow your companys procedures. Be sure that you have reviewed a copy of those procedures. ○ If you observe suspicious activity, take note of all parties involved, including the perceived trafficker, any possible victims, the time and location within the casino, and any statements that may have been made.
○ Should you have any direct contact or conversation with someone you suspect may be a trafficking victim, exercise great care. Victims fear being arrested and possible retribution and abuse from their traffickers. Some victims may not immediately respond to assistance and may be resistant. In those cases, local anti-trafficking organizations
may be the most effective route for assistance, and it is essential that they are integrated into your companys response plan. ○ Never try to intervene on your own; always wait for support from those who have experience dealing with similar situations. ○ If someone on your team notices that the victim speaks a language other than English and recognizes the language they speak, find someone who can inform them that there is help available in their language. ○ If the victim reaches out directly for help and wants to be hidden from their traffickers because they are scared to be found asking for help, then you can offer to take them into a safe place until law enforcement or your local anti trafficking provider arrives.
Conclusion
Conclusion
These practices reflect the continuing efforts of AGA members to mitigate the risks of potential money laundering and illegal activity connected with their businesses. The guidelines in this document must be adapted to match the specific risks and environments of individual casinos and companies. Casinos should evaluate their AML/BSA compliance risks and mitigation strategies on a routine basis to ensure they account for new risks and emerging patterns of illegal activity. When dealing with businesses as complex as modern casinos, and with judgments as subjective as those required by the BSA, no compliance effort can be perfect or immune from retrospective reevaluation. Though perfection cannot be expected of a process that involves so many variables and periodic shifts in financial practices and regulations, effective AML/BSA compliance programs should ensure that the gaming industry continues to effectively combat money laundering and illicit financing threats. The AGA appreciates the participation and collective expertise of our members in the conception, drafting, and revisions of this guide. Their commitment to compliance is strong, and we applaud them for sharing these best practices with the industry.
Glossary
Glossary
Agent: A person acting on behalf of another person
Bank Secrecy Act (BSA): Adopted in 1970 and amended several times since, the statute authorizes the U.S. Secretary of the
Treasury to impose on U.S. financial institutions the requirement to keep and submit such reports that have a high degree of
usefulness in criminal, tax, and regulatory matters, and in the conduct of intelligence activities to protect against international
terrorism. (31 U.S.C. §§ 5311, et seq.)
Cage: A secured area adjacent to the gambling floor of a casino where casino cashiers conduct financial transactions for the
guest. This includes the redemption of gaming instruments, cash advances, marker/credit, front money, and other gambling
related transactions, and where currency and chips are often kept. Safety deposit boxes are often available at the cage. A large
casino may have more than one cage location.
Casino: A venue or interactive platform that offers its patrons highly regulated gaming activities, such as traditional casino
style games, house-backed games, and sports betting
Chip Walk: When a patron leaves the casino floor with a significant amount of chips in their possession, without offsetting chip
redemptions or chip buy-ins at another table, and there is no known disposition or whereabouts of the chips. A chip walk may
not be deemed suspicious if there is a reasonable, experience-based expectation that the patron will return to the casino in
the near future and that the departure with chips was not done in an attempt to structure.
Credit: Under the regulations of many state licensing authorities, casinos are authorized to issue gaming chips or other
representatives of value to patrons for gambling purposes up to the amount of a “marker” (see below), a negotiable instrument
signed by the patron and made out to the casino. Although state regulations refer to such arrangements as credit transactions,
the markers may be negotiated immediately at the discretion of the casino.
Digital Identification: Some states may issue a digital form of identification (e.g., drivers license, state ID card) instead of or
in lieu of a physical government-issued picture ID card. This development may assist in online, internet, or mobile gaming
applications as part of the KYC process, as new technology continues to expand and be acceptable for certain digital wagering
account applications. Absent of specific FinCEN guidance forbidding the use of digital IDs for AML purposes, casinos should
include whether or not they will accept digital IDs in their written AML/CFT Program.
Digital Wallet: A software-based system that securely stores users payment information and passwords for payments and
withdrawals
Front money: Cash, wired funds, or negotiable instruments that are deposited with the casino by a patron who will draw down
on those funds for gambling. Front money accounts are sometimes described as safekeeping accounts.
Geolocation: The identification of the geographic location of a user or computing device via a variety of data collection
mechanisms, typically using network routing addresses or internal GPS devices
Interactive Gaming: Interactive gaming comprises traditional internet gaming (e.g., casino games, poker), mobile wagering
(e.g.,casino games), and account wagering (i.e., funding an account whether at a brick-and-mortar location or via the internet
or smartphone that can be used in digital channels).
Interest on Lawyers Trust Account (IOLTA): A financial account set up by a law firm in which the funds are held in trust for
the benefit of the firms clients and are, by state law or supreme court rule, to be held separate and apart from the funds
belonging to the law firm
Internet Protocol (IP) Address: A unique address that identifies a device on the internet or a local network
Marker: A negotiable instrument (sometimes called a counter-check) executed by a casino patron that authorizes the casino
to recover the amount of the marker from the patrons bank account. The casino will advance funds to the patron up to the
amount of the marker. Under state casino regulations, casinos are not required to conduct full credit investigations before
issuing a marker, but will confirm that the patrons bank account contains sufficient funds to cover the requested marker.
Glossary
Monetary/Negotiable Instrument Log (MIL/NIL): Required by the BSA, it must reflect transactions of monetary instruments
(e.g., money orders, cashiers checks, travelers checks, and bank drafts) between the casino and the patron with a value of
$3,000 or greater.
Money Laundering: Money laundering is the process of hiding the original source of money obtained from illegal activity by
making the funds appear as if they were legally earned or won. In the eyes of the government, money laundering also includes
the act of spending (or gambling) the proceeds of illegal activity. Money laundering, which is illegal, supports many types
of illegal activity, such as drug trafficking, terrorist financing, tax evasion, and fraud. It is a crime to allow a patron to transact
or gamble with funds if you have knowledge that the funds are proceeds from illegal activity. It is also a crime if you suspect
a patron is using funds from illegal activity, but you deliberately avoid confirming your suspicion (you cannot “put your head
in the sand” or be willfully blind).
Multiple Transaction Log (MTL): This is a record of cash-in and cash-out transactions at or above a predetermined amount,
which also records identifying information about the patron used to determine when a person is approaching or has exceeded
a reportable threshold.
Risk Assessment: The formal process of examining a casinos mix of gambling activity, patrons, and overall economic
environment to identify activities, levels of play or other transactions that pose a risk of money laundering and should be
addressed by the casinos AML compliance procedures.
Safekeeping: A patrons non-claimed gaming funds, overages from deposits, and other funds not falling under front money are
placed in safekeeping. These funds are not redeemed or tied to casino markers.
Structuring: When a person acting alone, in conjunction with, or on behalf of another person, conducts, or attempts to
conduct, one or more transactions. This is the case for any amount, at one or more locations, on one or more days, in any
manner for the purpose of evading the CTR requirements.
Third-Party Transactions: Deposits, withdrawals, payments, and transfers of funds to and from a casino account by anyone
other than the primary account holder
Ticket-in, Ticket-Out (TITO): A system for slot machine play that uses a barcoded paper ticket. The ticket may be purchased in
advance of slot machine play or issued from the slot machine if there are credits remaining at the conclusion of the patrons
gaming session. When the patron has completed their play, balances on the ticket can be redeemed for cash at a kiosk or
casino cage and used for further play at the casino that issued the ticket.
Sports Wagering: With the repeal of the Professional and Amateur Sports Protection Act (PASPA) in May 2018, sports
wagering is permissible in certain U.S. states that have legalized it. A casino may offer sports wagering over the counter via
a sportsbook kiosk, an internet browser, and/or a mobile app. If offered via an internet browser or a mobile app, the patron
will have a separate wagering account apart from any casino wagering account for slots, table games, and keno, as the sports
wagering system is its own self-contained proprietary system.
Universally Unique Identifier (UUID): An identification number that will uniquely identify an electronic device
Appendix
APPENDIX A: ANTI-MONEY LAUNDERING PROGRAM QUESTIONNAIRE 61
APPENDIX A:
ANTI-MONEY LAUNDERING PROGRAM QUESTIONNAIRE
A compliance program may be satisfactory even if some of the answers to these questions are not in the affirmative, as long as
the company can explain why its policies provide adequate AML vigilance.
A. GENERAL POLICIES, PRACTICES, AND PROCEDURES
1. Is the AML/CFT Program approved by the companys senior management or board of directors?
2. Does the companys legal and regulatory compliance program include a designated officer who is responsible for
coordinating and overseeing the AML compliance framework, as well as sufficient staff to provide support to the
designated officer?
3. Do you have written policies documenting the processes in place to prevent, detect, and report suspicious transactions
across all games and financial services offered?
4. Do you perform periodic training on AML policies and practices for those employees covered by your compliance
program?
5. In addition to inspections by government regulators, does an internal audit function or other independent third party
periodically assess AML policies and practices?
6. If a patron proposes a transaction with a corporation on their behalf, do you have a policy for inquiring into the identity
of the beneficial owners of the corporation involved and its relationship to the patron?
7. Do you have policies to reasonably ensure that you will not conduct transactions with shell banks or corporations?
8. Do you have policies for identifying politically exposed persons (PEPs), their family, and close associates, and for
controlling transactions with such individuals?
9. Do you have record retention procedures that comply with applicable law?
10. Are your AML policies and practices being applied to all associated entities, both in the U.S. and in foreign locations?
B. RISK ASSESSMENT
1. Do you have a risk-based assessment of your patron base and their transactions?
2. Do your risk-based assessments consider:
a. The volume and character of overall gaming activity at a gaming venue
b. The characteristics of the games and financial services offered at a gaming venue
c. A patrons country of origin
d. The gambling patterns or financial transactions favored by a patron
e. Third-party information about a patron, including negative information regarding the patrons integrity
f. Whether a patron has sources of wealth or income commensurate with their gaming activity
g. Whether a patron has provided verifiable identification information
h. Whether a patron has financial fiduciary obligations (e.g., trustee, accountant, attorney, or nonprofit/charity executive)
APPENDIX A: Cont.
ANTI-MONEY LAUNDERING PROGRAM QUESTIONNAIRE
i. Whether a patron is associated with individuals or entities known to be connected with the illicit generation of funds
or legalized marijuana-related activity
j. Whether a patron claims connections with businesses that have no apparent operations
k. Whether a patron is the subject of substantial tax liens or has gone through a recent personal bankruptcy proceeding
3. Does your compliance program identify and explain the proper responses by employees to patrons and transactions that
you have reason to believe pose a heightened risk of illicit activities at or through your casino?
C. KNOW YOUR CUSTOMER/PATRON AND DUE DILIGENCE
1. Have you implemented processes for securing identification for those patrons whose transactions fall within the AML/CFT
Program?
2. Do you have a requirement to collect information regarding a patrons business activities and connections?
a. If so, under what circumstances does that requirement apply?
b. What steps should be taken in that effort?
3. Do you have a process to review and update patron information relating to high-risk relationships and activities?
4. Do you complete a risk-based assessment to understand the normal and expected transactions of patrons?
D. REPORTABLE TRANSACTIONS
1. Do you have policies or practices for the identification and reporting of transactions that must be reported?
2. For currency reporting purposes, do you have procedures to identify multiple transactions that have been structured to
avoid such reporting?
3. Do you screen patrons and transactions against lists of persons, entities or countries issued by the OFAC or other
government authorities?
E. TRANSACTION MONITORING
1. Do you have a monitoring program for unusual and potentially suspicious activity that covers funds transfers, engaging in
financial transactions without significant gaming activity, coordinating activity with other patrons, and the like?
2. In order to identify AML concerns, do you review daily audit summaries, logs, and reports, such as marker summaries,
front-money/safekeeping summaries, MTLs, MILs, check logs, and wire reports?
F. PREVENTIVE MEASURES
1. Do you cap TITO redemptions at slot machine kiosks?
2. Do you cap the level of cash-for-cash exchanges?
3. Do you accept currency to purchase a casino check, other monetary instrument, or wire transfer?
4. Will you issue casino checks or wires to a patron for an amount greater than their winnings? Under what circumstances?
APPENDIX A: Cont.
ANTI-MONEY LAUNDERING PROGRAM QUESTIONNAIRE
5. Do you issue checks for winnings only in the name of the patron?
6. Do you require supervisor review of checks or wires made payable to a patrons business or other account or another
individual?
7. If a patron declines to provide identifying information when required (e.g., for CTRs), do you suspend the patrons loyalty
club account or bar the patron?
8. Do you allow cash play at poker tables?
9. Do you accept virtual currency?
10. Do you protect patron information to prevent social engineering, software vulnerability exploits, and network attacks?
G. EMPLOYEE TRAINING
1. Is your AML Officer at each gaming venue educated on the requirements of the AML/CFT Program, including suspicious
activity reporting and currency transaction reporting, and the requirements of state and federal regulators for AML
compliance?
2. Do you provide AML training to other relevant employees? If so, does that training include:
a. Identification and reporting of transactions that warrant a suspicious activity report or a CTR
b. Examples of different forms of suspicious or illegal activity involving the casinos business and services
c. Correct methods for completing currency transaction and SARs
d. Internal policies to prevent money laundering
e. Do any of the following employees receive AML training:
i. Those engaged in the operation of casino games, beginning at least at the supervisor level
ii. Casino marketing employees
iii. Cage employees
iv. Surveillance employees
v. Property compliance and AML compliance employees
vi. Audit employees, including Internal Audit and/or Fraud department employees
vii.Senior gaming management, members of the board of directors, audit committee, or compliance committee
3. Do you retain records of training sessions, including attendance records and the training materials used?
4. Do you update relevant employees on changes in AML law, policies or practices?
5. Do you provide training on the red flags of human trafficking, as well as financial red flags associated with human
trafficking?
american-gaming-association @AmericanGaming
AmericanGaming @AmericanGaming
AMERICANGAMING.ORG

View File

@@ -0,0 +1,494 @@
LAWFUL INTERNET GAMING ACT
Act 152 of 2019
AN ACT to create the lawful internet gaming act; to require licensure for persons to offer internet gaming; to
impose requirements for internet gaming; to provide for the powers and duties of the Michigan gaming control
board and other state and local officers and entities; to impose fees; to impose tax and other payment obligations on
the conduct of licensed internet gaming; to create the internet gaming fund; to prohibit certain acts in relation to
internet gaming and to prescribe penalties for those violations; to require the promulgation of rules; and to provide
remedies.
History: 2019, Act 152, Imd. Eff. Dec. 20, 2019
The People of the State of Michigan enact:
432.301 Short title. Sec. 1. This act shall be known and may be cited as the "lawful internet gaming act".
History: 2019, Act 152, Imd. Eff. Dec. 20, 2019
432.302 Legislative findings, declaration, and intent. Sec. 2. The legislature finds and declares all of the following:
(a) Operating, conducting, and offering for play internet games over the internet involves gaming activity that
already occurs throughout this state illegally. (b) This act is consistent and complies with the unlawful internet gambling enforcement act of 2006, 31 USC
5361 to 5367, and specifically authorizes use of the internet to place, receive, or otherwise knowingly transmit a bet
or wager if that use complies with this act and rules promulgated under this act. (c) This act is consistent and complies with the state constitution of 1963 by ensuring that the internet may be
used to place wagers only on games of skill or chance that may be lawfully played in this state and that internet
gaming is only conducted by persons who are lawfully operating casinos in this state. (d) In order to protect residents of this state who wager on games ofchance or skill through the internet and to
capture revenues generated from internet gaming, it is in the best interest of this state and its citizens to regulate
this activity by establishing a secure, responsible, fair, and legal system of internet gaming. (e) The use of the internet to sell lottery games, including digital representations of lottery games and
entertaining displays for revealing outcomes, continues to be permitted as a method for selling state lottery games. This act is not intended to prohibit sales described in this subdivision.
History: 2019, Act 152, Imd. Eff. Dec. 20, 2019
Rendered Friday, August 29, 2025
Page 1
Michigan Compiled Laws Complete Through PA 12 of 2025
Courtesy of legislature.mi.gov
432.303 Definitions. Sec. 3. As used in this act:
(a) "Adjusted gross receipts" means gross receipts less a deduction equal to the amount of free play provided and
wagered by authorized participants as an incentive to place or as a result of placing internet wagers under this act. The deduction under this subdivision is limited as follows:
(i) For years 1-3, a deduction not to exceed 10% of gross receipts. (ii) For year 4, a deduction not to exceed 6% of gross receipts. (iii) For year 5, a deduction not to exceed 4% of gross receipts. (iv) For year 6 and each year thereafter, no deduction of free play is allowed. The January 1 following the year in
which the internet gaming operator begins internet gaming operations is considered the beginning of the first year
of internet gaming for the purposes of this subdivision. An internet gaming operator may deduct up to 10% of gross
receipts during any period of internet gaming operations before January 1 of the first year of internet gaming
operations. (b) "Affiliate" means a person that, directly or indirectly, through 1 or more intermediaries, controls or is
controlled by an internet gaming operator. (c) "Applicant" means a person that applies for a license or for registration under this act. As used in section 8, applicant includes an affiliate, director, or managerialemployee of the applicant that performs the function of
principalexecutive officer, principal operations officer, or principalaccounting officer, or a person who holds more
than 5% ownership interest in the applicant. As used in this subdivision, affiliate does not include a partnership, a
joint venture, a co-shareholder ofa corporation, a co-member ofa limited liability company, or a co-partner in a
limited liability partnership that has 5% or less ownership interest in the applicant and is not involved in the internet
gaming operation. (d) "Authorized participant" means an individual who has a valid internet wagering account with an internet
gaming operator and is 21 years ofage or older. (e) "Board" means the Michigan gaming control board created under section 4 of the Michigan Gaming Control
and Revenue Act, 1996 IL 1, MCL 432.204. (f) "Casino" means a building or buildings in which gaming is lawfully conducted under the Michigan Gaming
Controland Revenue Act, 1996 IL 1, MCL 432.201 to 432.226, or in which class III gaming is lawfully conducted
by an Indian tribe in this state under a facility license issued in accordance with a tribal gaming ordinance approved
by the chair of the National Indian Gaming Commission. (g) "Class II gaming" means that term as defined in 25 USC 2703. (h) "Class III gaming" means that term as defined in 25 USC 2703. (i) "Compact" means a tribal-state compact governing the conduct of gaming activities that is negotiated under
the Indian gaming regulatory act, Public Law 100-497, 102 Stat 2467. (j) "Fantasy contest" means that term as defined in section 2 of the fantasy contests consumer protection act, 2019 PA 157, MCL 432.502. (k) "Fund" means the internet gaming fund created under section 16. (l) "Gross receipts" means the total ofall sums, including, but not limited to, valid or invalid checks, valid or
invalid credit or debit card deposits, valid or invalid ACH deposits, currency, coupons, free play or promotional
credits, redeemable credits, vouchers, entry fees assessed for tournaments or other contests, or instruments of
monetary value whether collected or uncollected, in each case actually wagered by an authorized participant at or
with an internet gaming operator on an internet game, less all of the following:
(i) Winnings. (ii) Amounts returned to an authorized participant due to a game, platform, or system malfunction or because the
internet wager must be voided due to concerns regarding integrity of the wager or game. (iii) Uncollectible markers or successfully disputed credit or debit card charges that were previously included in
the computation of gross receipts. (m) "Indian lands" means that term as defined in 25 USC 2703. (n) "Indian tribe" means that term as defined in 25 USC 2703 and any instrumentality, political subdivision, or
other legalentity through which an Indian tribe operates its casino in this state. (o) "Institutional investor" means a person that is any of the following:
(i) A retirement fund administered by a public agency for the exclusive benefit of federal, state, or local public
employees. (ii) An employee benefit plan or pension fund that is subject to the employee retirement income security act of
1974, Public Law 93-406. (iii) An investment company registered under the investment company act of 1940, 15 USC 80a-1 to 80a-64. (iv) A collective investment trust organized by a bank under 12 CFR part 9.
Rendered Friday, August 29, 2025
Page 2
Michigan Compiled Laws Complete Through PA 12 of 2025
Courtesy of legislature.mi.gov
(v) A closed end investment trust. (vi) A chartered or licensed life insurance company or property and casualty insurance company. (vii) A chartered or licensed financial institution. (viii) An investment advisor registered under the investment advisers act of 1940, 15 USC 80b-1 to 80b-21. (ix) Any other person that the board determines through rulemaking should be considered to be an institutional
investor for reasons consistent with this act. (p) "Internet" means the internationalcomputer network of interoperable packet-switched data networks,
inclusive of such additional technological platforms as mobile, satellite, and other electronic distribution channels. (q) "Internet game" means a game of skill or chance that is offered for play through the internet in which an
individual wagers money or something of monetary value for the opportunity to win money or something of
monetary value. Internet game includes gaming tournaments conducted via the internet in which individuals
compete against one another in 1 or more of the games authorized by the board or in approved variations or
composites as authorized by the board. Internet game does not include a social media internet game as that term is
defined in section 310c of the Michigan penalcode, 1931 PA 328, MCL 750.310c. (r) "Internet gaming" means operating, conducting, or offering for play an internet game. (s) "Internet gaming operator" means a person that is issued an internet gaming operator license from the board. (t) "Internet gaming operator license" means a license issued by the board to a person to operate, conduct, or
offer internet gaming. (u) "Internet gaming platform" means an integrated system of hardware, software, applications, including mobile
applications, and servers through which an internet gaming operator operates, conducts, or offers internet gaming. (v) "Internet gaming platform provider" means an internet gaming supplier that contracts with an internet gaming
operator to provide an internet gaming platform. (w) "Internet gaming supplier" means a person that the board has identified under the rules promulgated by the
board as requiring a license to provide internet gaming operators goods or services that directly affect wagering, play, and results of internet games offered under this act. Internet gaming supplier includes, but is not limited to,
internet gaming platform providers. (x) "Internet gaming supplier license" means a license issued by the board to an internet gaming supplier. (y) "Internet wager" means money or something of monetary value risked on an internet game. (z) "Internet wagering" means risking money or something of monetary value on an internet game. (aa) "Internet wagering account" means an electronic ledger in which all of the following types of transactions
relative to an authorized participant are recorded:
(i) Deposits and credits. (ii) Withdrawals. (iii) Internet wagers. (iv) Monetary value of winnings. (v) Service or other transaction-related charges authorized by the authorized participant, ifany. (vi) Adjustments to the account. (bb) "Mobile application" means an application on a mobile phone or other device through which an individual is
able to place an internet wager. (cc) "Occupational license" means a license issued by the board to a person to perform an occupation that
directly impacts the integrity of internet gaming and that the board has identified as requiring a license to perform
the occupation. (dd) "Person" means an individual, partnership, corporation, association, limited liability company, federally
recognized Indian tribe, or other legalentity. (ee) "Poker" means the traditional game of poker, and any derivative of the game of poker as approved by the
board, in which 2 or more authorized participants play against each other and wager on the value of the cards in the
authorized participants' hands. (ff) "Vendor" means a person that is not licensed under this act that supplies any goods or services to an internet
gaming operator or internet gaming supplier. (gg) "Winnings" means the totalcash value ofall property or sums including currency or instruments of
monetary value paid to an authorized participant by an internet gaming operator as a direct result ofa winning
internet wager.
History: 2019, Act 152, Imd. Eff. Dec. 20, 2019 ;-- Am. 2020, Act 327, Eff. Mar. 24, 2021
Rendered Friday, August 29, 2025
Page 3
Michigan Compiled Laws Complete Through PA 12 of 2025
Courtesy of legislature.mi.gov
432.304 Internet gaming, conduct generally; applicability of act; limitation on brand of internet gaming. Sec. 4.
(1) Internet gaming may be conducted only to the extent that it is conducted in accordance with this act. (2) An internet wager received by an internet gaming operator or its internet gaming platform providers is
considered to be gambling or gaming that is conducted in the internet gaming operator's casino located in this state, regardless of the authorized participant's location at the time the participant initiates or otherwise places the internet
wager. (3) A law that is inconsistent with this act does not apply to internet gaming as provided for by this act. (4) This act does not apply to any of the following:
(a) Lottery games offered by the bureau of lottery under the McCauley-Traxler-Bowman-McNeely lottery act, 1972 PA 239, MCL 432.1 to 432.47. (b) Class II and Class III gaming conducted exclusively on Indian lands by an Indian tribe under a facility license
issued in accordance with a tribal gaming ordinance approved by the chair of the National Indian Gaming
Commission. For purposes of this act, gaming is conducted exclusively on Indian lands only if the individual who
places the wager is physically present on Indian lands when the wager is initiated and the wager is received or
otherwise made on equipment that is physically located on Indian lands, and the wager is initiated, received, or
otherwise made in conformity with the safe harbor requirements described in 31 USC 5362(10)(C). (c) A lawful fantasy contest. (d) Any lawful internet sports betting. (5) A person shall not provide or make available computers or other internet access devices in a place of public
accommodation in this state, including a club or other association, to enable individuals to place internet wagers or
play an internet game. The prohibition under this subsection does not apply to an internet gaming operator
aggregating, providing, or making available computers or other internet access devices at its own casino. (6) For purposes of this act, the intermediate routing ofelectronic data in connection with internet wagering,
including routing across state lines, does not determine the location or locations in which the internet wager is
initiated, received, or otherwise made. (7) An internet gaming operator may offer internet gaming under a maximum of 2 separate brands, 1 for each of
interactive poker and other casino style games. This subsection does not prohibit an internet gaming operator from
using fewer than 2 brands or from using a single brand to offer any combination of interactive poker or other casino
style games. Only an internet gaming operator or its internet gaming platform providers may process, accept, or
solicit internet wagers under this act. All websites and corresponding applications used to offer internet gaming
must clearly display the brand of the internet gaming operator or its affiliate. The internet gaming operator may also
elect, in its sole discretion, to have the brand ofeach internet gaming platform that it utilizes be the name and logos
or no more than 1 internet gaming platform provider if the internet gaming platform also clearly displays the
internet gaming operator's own trademarks and logos or those ofan affiliate. The internet gaming operator is
responsible for the conduct of its internet gaming platform provider.
History: 2019, Act 152, Imd. Eff. Dec. 20, 2019
432.305 Michigan gaming control board; powers and duties; jurisdiction; agreements for
multijurisdictional internet gaming for poker. Sec. 5.
(1) The board has the powers and duties specified in this act and all other powers necessary to enable it to fully
and effectively execute this act to administer, regulate, and enforce the system of internet gaming established under
this act. (2) The board has jurisdiction over every person licensed by the board and may take enforcement action against a
person that is not licensed by the board that offers internet gaming in this state. (3) The board may enter into agreements with other jurisdictions, including Indian tribes, to facilitate, administer, and regulate multijurisdictional internet gaming for poker by internet gaming operators to the extent that entering
into the agreement is consistent with state and federal laws and if the internet gaming under the agreement is
conducted only in the United States.
Rendered Friday, August 29, 2025
Page 4
Michigan Compiled Laws Complete Through PA 12 of 2025
Courtesy of legislature.mi.gov
History: 2019, Act 152, Imd. Eff. Dec. 20, 2019 ;-- Am. 2020, Act 327, Eff. Mar. 24, 2021
432.306 Internet gaming operatorlicense; application; fee; form and contents; confidentiality; prohibited
conduct. Sec. 6.
(1) The board may issue an internet gaming operator license only to an applicant that is either of the following:
(a) A person that holds a casino license under the Michigan Gaming Controland Revenue Act, 1996 IL 1, MCL
432.201 to 432.226. (b) An Indian tribe that lawfully conducts class III gaming in a casino located in this state under a facility license
issued in accordance with a tribal gaming ordinance approved by the chair of the National Indian Gaming
Commission. (2) The board shall issue an internet gaming operator license to an applicant described in subsection (1) after
receiving the application described in subsection (4) or (5), as applicable, and the application fee, if the board
determines that the internet gaming proposed by the applicant complies with this act and the applicant is otherwise
eligible and suitable. An applicant is eligible if it meets the requirements set forth in subsection (1)(a) or (b). Each
casino licensee described in subsection (1)(a) and each Indian tribe described in subsection (1)(b) is eligible for not
more than 1 internet gaming operator license. It is the burden of the applicant to establish by clear and convincing
evidence its suitability as to character, reputation, integrity, business probity, and financialability. The application
or enforcement of this subsection by the board must not be arbitrary, capricious, or contradictory to the express
provisions of this act. In evaluating the eligibility and suitability ofan applicant under the standards provided in this
act, the board shallestablish and apply the standards to each applicant in a consistent and uniform manner. In
determining whether to grant an internet gaming operator license to an applicant, the board may request from the
applicant and consider as a factor in the determination any or all of the following information:
(a) Whether the applicant has adequate capitalization and the financialability and the means to develop, construct, operate, and maintain the proposed internet gaming platform and to offer and conduct internet gaming in
accordance with this act and the rules promulgated by the board. (b) Whether the applicant has the financialability to purchase and maintain adequate liability and casualty
insurance and to provide an adequate surety bond. (c) Whether the applicant has adequate capitalization and the financialability to responsibly pay its secured and
unsecured debts in accordance with its financing agreements and other contractual obligations. (d) Whether the applicant has a history of material noncompliance with casino or casino-related licensing
requirements or compacts with this state or any other jurisdiction, where the noncompliance resulted in
enforcement action by the person with jurisdiction over the applicant. (e) Whether the applicant has been indicted for, charged with, arrested for, or convicted of, pleaded guilty or
nolo contendere to, forfeited bailconcerning, or had expunged any criminal offense under the laws ofany
jurisdiction, either felony or misdemeanor, not including traffic violations, regardless of whether the offense has
been expunged, pardoned, or reversed on appeal or otherwise. The board may consider mitigating factors, and, for
an applicant described in subsection (1)(b), shall give deference to whether the applicant has otherwise met the
requirements of the applicant's gaming compact for licensure, as applicable. (f) Whether the applicant has filed, or had filed against it, a proceeding for bankruptcy or has ever been involved
in any formal process to adjust, defer, suspend, or otherwise work out the payment ofany debt. (g) Whether the applicant has a history of material noncompliance with any regulatory requirements in this state
or any other jurisdiction where the noncompliance resulted in an enforcement action by the regulatory agency with
jurisdiction over the applicant. (h) Whether at the time ofapplication the applicant is a defendant in litigation involving the integrity of its
business practices. (3) An internet gaming operator license issued under this act is valid for the 5-year period after the date of
issuance and, if the board determines that the internet gaming operator continues to meet the eligibility and
suitability standards under this act, is renewable for additional 5-year periods. (4) A person described in subsection (1)(a) may apply to the board for an internet gaming operator license to
offer internet gaming as provided in this act. The application must be made on forms provided by the board and
include the information required by the board. (5) A person described in subsection (1)(b) may apply to the board for an internet gaming operator license to
Rendered Friday, August 29, 2025
Page 5
Michigan Compiled Laws Complete Through PA 12 of 2025
Courtesy of legislature.mi.gov
offer internet gaming as provided in this act. The application must be made on forms provided by the board that
require only the following information:
(a) The name and location ofany of the applicant's casinos. (b) The tribal law, charter, or any other organizational document of the applicant and other governing documents
under which the applicant operates any of its casinos. (c) Detailed information about the primary management officials of the applicant's casinos who will have
management responsibility for the applicant's internet gaming operations. As used in this subdivision, "primary
management official" does not include an elected or appointed representative of the applicant unless the
representative is also a full-time employee of the applicant's internet gaming operations. (d) The current facility license for the applicant's casinos. (e) The applicant's current tribal gaming ordinance. (f) The gaming history and experience of the applicant in the United States and other jurisdictions. (g) Financial information, including copies of the last independent audit and management letter submitted by the
applicant to the National Indian Gaming Commission under 25 USC 2710(b)(2)(C) and (D) and 25 CFR parts
271.12 and 271.13. (h) The total number of gaming positions, including, but not limited to, electronic gaming devices and table
games, at each of the applicant's casinos. (6) An initialapplication for an internet gaming operator license must be accompanied by an application fee of
$50,000.00. The rules promulgated under section 10 may include provisions for the refund ofan application fee, or
the portion ofan application fee that has not been expended by the board in processing the application, and the
circumstances under which the fee will be refunded. The board may assess additional fees for the costs related to
the licensure investigation. (7) The board shall keep all information, records, interviews, reports, statements, memoranda, or other data
supplied to or used by the board in the course of its review or investigation ofan application for an internet gaming
operator license or renewal ofan internet gaming operator license confidential. The materials described in this
subsection are exempt from disclosure under section 13 of the freedom of information act, 1976 PA 442, MCL
15.243. (8) An application under this section must be submitted and considered in accordance with this act and any rules
promulgated under this act. (9) An internet gaming operator shall pay a license fee of $100,000.00 to the board at the time the initial internet
gaming operator license is issued and $50,000.00 each year after the initial license is issued. (10) The board shall deposit allapplication and license fees paid under this section into the fund. (11) An institutional investor that holds for investment purposes only less than 25% of the equity ofan applicant
under this section is exempt from the licensure requirements of this act. (12) An internet gaming operator shall not offer internet gaming untilall of the following criteria are satisfied:
(a) The board has issued a license to at least 1 person under section 6(1)(a) and 1 person under section 6(1)(b). (b) Either of the following is satisfied, whichever is first:
(i) The governor agrees to add online versions ofauthorized class III gaming games, including authorizing
internet wagering on games described in this subparagraph, under the tribal-state compact for any tribe in this state
whose tribal-state gaming compact requires agreement by the governor for the addition ofeach new class III
gaming game if those tribes request, within 60 days after the effective date of this act, an agreement under section
3(B) of the tribe's tribal-state gaming compact. (ii) One hundred fifty days have elapsed after the effective date of this act.
History: 2019, Act 152, Imd. Eff. Dec. 20, 2019
432.307 Internet gaming operatorlicense; issuance and renewal; compliance requirements; Indian tribe
compacts. Sec. 7.
(1) The board shallcondition the issuance, maintenance, and renewal ofan internet gaming operator license to a
person described in section 6(1)(b) on the person's compliance with all of the following conditions:
(a) The person complies with this act, rules promulgated by the board, and minimum internalcontrols pertaining
to all of the following:
Rendered Friday, August 29, 2025
Page 6
Michigan Compiled Laws Complete Through PA 12 of 2025
Courtesy of legislature.mi.gov
(i) The types ofand rules for playing internet games that internet gaming operators may offer under this act. (ii) Technical standards, procedures, and requirements for the acceptance, by the person, of internet wagers
initiated or otherwise made by individuals located in this state who are not physically present on the person's Indian
lands in this state at the time the internet wager is initiated or otherwise made. (iii) Procedures and requirements for the acceptance of internet wagers for poker initiated or otherwise made by
individuals located in other jurisdictions, if the board authorizes multijurisdictional internet gaming for poker as
provided in this act. (iv) The requirements set forth in section 11. (b) The person adopts and maintains technical standards for internet gaming platforms, systems, and software
that are consistent with the standards adopted by the board under section 10. (c) The person maintains 1 or more mechanisms on the internet gaming platform that are designed to reasonably
verify that an authorized participant is 21 years ofage or older and that internet wagering is limited to transactions
that are initiated and received or otherwise made by an authorized participant located in this state or, if the board
authorizes multijurisdictional internet gaming for poker as provided in this act, another jurisdiction in the United
States authorized by the multijurisdictionalagreement. (d) The person adopts and maintains responsible gaming measures consistent with those described in section 12. (e) The person continues to maintain and operate in this state a casino offering class III gaming and the casino
contains not less than 50% of the gaming positions that were in place on December 20, 2019. (f) The person, within the time period described in section 14(3), makes payments, to be allocated as outlined in
section 15a, based on a graduated percentage schedule on the adjusted gross receipts received each calendar year
by the person from all internet gaming it conducts under this act as an internet gaming operator, as set forth below:
(i) For adjusted gross receipts less than $4,000,000.00, 20%. (ii) For adjusted gross receipts of $4,000,000.00 or more but less than $8,000,000.00, 22%. (iii) For adjusted gross receipts of $8,000,000.00 or more but less than $10,000,000.00, 24%. (iv) For adjusted gross receipts of $10,000,000.00 or more but less than $12,000,000.00, 26%. (v) For adjusted gross receipts of $12,000,000.00 or more, 28%. (g) The person agrees to provide and timely provides, on written request of the board, books and records
directly related to its internet gaming operations for the purpose of permitting the board to verify the calculation of
the payments under subdivision (f). (h) The person provides a waiver of sovereign immunity to the board for the sole and limited purpose of
consenting to both of the following:
(i) The jurisdiction of the board to the extent necessary and for the limited purpose of providing a mechanism for
the board to do all of the following:
(A) Issue, renew, and revoke the person's internet gaming license. (B) Enforce the payment obligations set forth in this section and section 14. (C) Regulate the person under and enforce sections 10(a), (b), (d) to (g), 11, 12(4) and (5), 13, 19, and 21. (D) Inspect the person's internet gaming operation and records to verify that the person is conducting its internet
gaming operation in conformity with this act. (E) Assess fines or monetary penalties for violations referred to in sub-subparagraph (C). (F) Enforce the payment of internet gaming license fees described in section 6(9). (ii) The jurisdiction of the courts of this state, and expressly waiving the exhaustion of tribal remedies, with the
circuit court for Ingham County having exclusive jurisdiction, and any courts to which appeals from that court may
be taken, to permit this state to enforce administrative orders of the board, the person's obligation to make
payments required under subdivision (f), and collection ofany judgment. Any monetary award under this
subparagraph is deemed limited recourse obligations of the person and does not impair any trust or restricted
income or assets of the person. (2) This state, acting through the governor, at the request ofany Indian tribe, is authorized to negotiate and
conclude and execute any amendments to an Indian tribe's compact necessary to effectuate internet gaming by the
Indian tribe under this act and to ensure internet gaming conducted by the Indian tribe is in compliance with this act
and any applicable federal laws. If the governor fails to enter into negotiations with the Indian tribe, or fails to
negotiate in good faith with respect to the request, this state waives its sovereign immunity to permit the Indian
tribe to initiate an action against the governor in his or her officialcapacity in either state court or in federalcourt
and obtain those remedies as authorized in 25 USC 2710(d)(7). (3) Notwithstanding anything in this act to the contrary, this act only regulates internet gaming as provided in
this act and does not extend to the board, or any other agency of this state, any jurisdiction or regulatory authority
over any aspect ofany gaming operations ofan Indian tribe described in section 4(4)(b) beyond those rights
granted to this state under the compact with the Indian tribe.
History: 2019, Act 152, Imd. Eff. Dec. 20, 2019 ;-- Am. 2020, Act 327, Eff. Mar. 24, 2021
Rendered Friday, August 29, 2025
Page 7
Michigan Compiled Laws Complete Through PA 12 of 2025
Courtesy of legislature.mi.gov
432.308 Internet gaming supplierlicense; application; form; fee; confidentiality. Sec. 8.
(1) The board may issue an internet gaming supplier license to an internet gaming supplier. A person that is not
licensed under this section shall not provide goods, software, or services as an internet gaming supplier to an
internet gaming operator. (2) On application by an interested person, the board may issue a provisional internet gaming supplier license to
an applicant for an internet gaming supplier license. A provisional license issued under this subsection allows the
applicant for the internet gaming supplier license to conduct business with an internet gaming operator before the
internet gaming supplier license is issued to the applicant. A provisional license issued under this subsection expires
on the date provided by the board. The board shall not issue a provisional internet gaming supplier license to an
internet gaming platform provider under this subsection until board rules as described in section 10(b) are in effect. (3) An internet gaming supplier license issued under subsection (1) is valid for the 5-year period after the date of
issuance. An internet gaming supplier license is renewable after the initial 5-year period for additional 5-year
periods if the board determines that the internet gaming supplier continues to meet the eligibility and suitability
standards under this act. (4) A person may apply to the board for an internet gaming supplier license as provided in this act and the rules
promulgated under this act. (5) Except as otherwise provided in this section, an application under this section must be made on forms
provided by the board and include the information required by the board. (6) An application under this section must be accompanied by a nonrefundable application fee in an amount to be
determined by the board, not to exceed $5,000.00. The board may assess additional fees for the cost related to the
licensure investigation. (7) The board shall keep all information, records, interviews, reports, statements, memoranda, or other data
supplied to or used by the board in the course of its review or investigation ofan application for an internet gaming
supplier license or renewal ofan internet gaming supplier license confidential. The materials described in this
subsection are exempt from disclosure under section 13 of the freedom of information act, 1976 PA 442, MCL
15.243. (8) An internet gaming supplier shall pay a license fee of $5,000.00 to the board at the time an initial internet
gaming supplier license is issued to the internet gaming supplier and $2,500.00 each year after the initial license is
issued. (9) The board shall deposit allapplication and license fees paid under this section into the fund. (10) An institutional investor that holds for investment purposes only less than 25% of the equity ofan applicant
under this section is exempt from the licensure requirements of this act.
History: 2019, Act 152, Imd. Eff. Dec. 20, 2019
432.309 Michigan gaming control board; jurisdiction and supervision of internet gaming operations;
powers; investigation. Sec. 9.
(1) The board has jurisdiction over and shall supervise all internet gaming operations governed by this act. The
board may do anything necessary or desirable to effectuate this act, including, but not limited to, all of the
following:
(a) Develop qualifications, standards, and procedures for approvaland licensure by the board of internet gaming
operators and internet gaming suppliers. (b) Decide promptly and in reasonable order all license applications and approve, deny, suspend, revoke, restrict, or refuse to renew internet gaming operator licenses and internet gaming supplier licenses. A party aggrieved by an
action of the board denying, suspending, revoking, restricting, or refusing to renew a license may request a
contested case hearing before the board under the administrative procedures act of 1969, 1969 PA 306, MCL
Rendered Friday, August 29, 2025
Page 8
Michigan Compiled Laws Complete Through PA 12 of 2025
Courtesy of legislature.mi.gov
24.201 to 24.328. A request for hearing under this subdivision must be made to the board in writing within 21 days
after service of notice of the action by the board. (c) Conduct all hearings pertaining to violations of this act or rules promulgated under this act. (d) Provide for the establishment and collection ofallapplicable license fees, taxes, and payments imposed by
this act and the rules promulgated under this act and the deposit of the applicable fees, taxes, and payments into the
fund. (e) Develop and enforce testing and auditing requirements for internet gaming platforms, internet wagering, and
internet wagering accounts. (f) Develop and enforce requirements for responsible gaming and player protection, including privacy and
confidentiality standards and duties. (g) Develop and enforce requirements for accepting internet wagers. (h) Adopt by rule a code ofconduct governing board employees that ensures, to the maximum extent possible,
that persons subject to this act avoid situations, relationships, or associations that may represent or lead to an actual
or perceived conflict of interest. (i) Develop and administer civil fines for internet gaming operators and internet gaming suppliers that violate this
act or the rules promulgated under this act. (j) Audit and inspect books and records relevant to internet gaming operations, internet wagers, internet
wagering accounts, internet games, or internet gaming platforms, including, but not limited to, the books and
records regarding financing and accounting materials held by or in the custody ofan internet gaming operator or
internet gaming supplier. (k) Acquire by lease or by purchase personal property, including, but not limited to, any of the following:
(i) Computer hardware. (ii) Mechanical, electronic, and online equipment and terminals. (iii) Intangible property, including, but not limited to, computer programs, software, and systems. (2) The board may investigate and may issue cease and desist orders and obtain injunctive reliefagainst a person
that is not licensed by the board that offers internet gaming in this state. (3) The board shall keep all information, records, interviews, reports, statements, memoranda, and other data
supplied to or used by the board in the course ofany investigation ofa person licensed under this act confidential. The materials described in this subsection are exempt from disclosure under section 13 of the freedom of
information act, 1976 PA 442, MCL 15.243.
History: 2019, Act 152, Imd. Eff. Dec. 20, 2019
432.310 Rules. Sec. 10. The board shall promulgate rules pursuant to the administrative procedures act of 1969, 1969 PA 306, MCL
24.201 to 24.328. The rules may include any necessary and proper to govern internet gaming, including, but not
limited to, any of the following:
(a) The types of internet games to be offered, which must include, but need not be limited to, poker, blackjack, cards, slots, and other games typically offered at a casino, but does not include pick numbers or other lottery games
typically offered by the bureau of lottery under the McCauley-Traxler-Law-Bowman-McNeely lottery act, 1972 PA
239, MCL 432.1 to 432.47. (b) The qualifications, standards, and procedures for approvaland licensure by the board for internet gaming
operators and internet gaming suppliers consistent with this act. (c) Requirements to ensure responsible gaming. (d) Technicaland financial standards for internet wagering, internet wagering accounts, and internet gaming
platforms, systems, and software or other electronic components integral to offering internet gaming. (e) Procedures for a contested case hearing under this act consistent with the administrative procedures act of
1969, 1969 PA 306, MCL 24.201 to 24.328. (f) Requirements for occupational licensing. (g) Requirements for vendors and vendor registration.
Rendered Friday, August 29, 2025
Page 9
Michigan Compiled Laws Complete Through PA 12 of 2025
Courtesy of legislature.mi.gov
History: 2019, Act 152, Imd. Eff. Dec. 20, 2019
432.311 Internet gaming operator; duties; age verification requirements; unauthorized use and fraud
prevention. Sec. 11.
(1) An internet gaming operator shall provide, or shall require its internet gaming platform provider to provide, 1
or more mechanisms on the internet gaming platform that the internet gaming operator uses that are designed to
reasonably verify that an authorized participant is 21 years ofage or older and that internet wagering is limited to
transactions that are initiated and received or otherwise made by an authorized participant located in this state or, if
the board authorizes multijurisdictional internet gaming for poker as provided in this act, another jurisdiction in the
United States authorized by the multijurisdictionalagreement. (2) An individual who wishes to place an internet wager under this act must satisfy the verification requirements
under subsection (1) before the individual may establish an internet wagering account or make an internet wager on
an internet game offered by the internet gaming operator. (3) An internet gaming operator shall include, or shall require its internet gaming platform provider to include, mechanisms on its internet gaming platform that are designed to detect and prevent the unauthorized use of internet
wagering accounts and to detect and prevent fraud, money laundering, and collusion. (4) An internet gaming operator, or its internet gaming platform provider, shall not knowingly authorize any of
the following individuals to establish an internet wagering account or knowingly allow them to wager on internet
games offered by the internet gaming operator, except if required and authorized by the board for testing purposes
or to otherwise fulfill the purposes of this act:
(a) An individual who is less than 21 years old. (b) An individual whose name appears in the board's responsible gaming database. (5) An internet gaming operator shall display, or shall require its internet gaming platform provider to display, in
a clear, conspicuous, and accessible manner, evidence of the internet gaming operator's internet gaming license
issued under this act.
History: 2019, Act 152, Imd. Eff. Dec. 20, 2019 ;-- Am. 2020, Act 327, Eff. Mar. 24, 2021
432.312 Statewide responsible gaming database. Sec. 12.
(1) The board may develop responsible gaming measures, including a statewide responsible gaming database
identifying individuals who are prohibited from establishing an internet wagering account or participating in internet
gaming offered by an internet gaming operator. The executive director of the board may place an individual's name
in the responsible gaming database ifany of the following apply:
(a) The individual has been convicted in any jurisdiction ofa felony, a crime of moral turpitude, or a crime
involving gaming. (b) The individual has violated this act or another gaming-related law. (c) The individual has performed an act or has a notorious or unsavory reputation such that the individual's
participation in internet gaming under this act would adversely affect public confidence and trust in internet gaming. (d) The individual's name is on a valid and current exclusion list maintained by this state or another jurisdiction in
the United States. (2) The board may promulgate rules for the establishment and maintenance of the responsible gaming database. (3) An internet gaming operator, in a format specified by the board, may provide the board with names of
individuals to be included in the responsible gaming database. (4) An internet gaming operator or its internet gaming platform provider shall offer responsible gambling services
and technicalcontrols to authorized participants, consisting of both temporary and permanent self-exclusion for all
internet games offered and the ability for authorized participants to establish their own periodic deposit and internet
Rendered Friday, August 29, 2025
Page 10
Michigan Compiled Laws Complete Through PA 12 of 2025
Courtesy of legislature.mi.gov
wagering limits and maximum playing times. (5) An authorized participant may voluntarily prohibit himself or herself from establishing an internet wagering
account with an internet gaming operator. The board may incorporate the voluntary self-exclusion list into the
responsible gaming database and maintain both the self-exclusion list and the responsible gaming database in a
confidential manner. (6) The self-exclusion list and responsible gaming database established under this section and any information
and records used by the board in the administration of the self-exclusion list and responsible gaming database are
exempt from disclosure under section 13 of the freedom of information act, 1976 PA 442, MCL 15.243.
History: 2019, Act 152, Imd. Eff. Dec. 20, 2019
432.313 Prohibited conduct; violations; penalties. Sec. 13.
(1) A person shall not do any of the following:
(a) Offer internet gaming for play in this state if the person is not an internet gaming operator unless this act does
not apply to the internet gaming under section 4(4). (b) Knowingly make a false statement on an application for a license to be issued under this act. (c) Knowingly provide false testimony to the board or an authorized representative of the board while under
oath. (d) Willfully fail to report, pay, or truthfully account for any license fee, tax, or payment imposed by this act, or
willfully attempt in any way to evade or defeat the license fee, tax, or payment. (e) Knowingly, with the intent to cheat, alter, tamper with, or manipulate any game, platform, equipment, software, hardware, devices, or supplies used to conduct internet gaming, in order to alter the odds or the payout, or to disable the game, platform, equipment, software, hardware, devices, or supplies from operating in the manner
authorized by the board, or knowingly, with the intent to cheat, offer or allow to be offered any game, platform, equipment, software, hardware, devices, or supplies that have been altered, tampered with, or manipulated in such a
manner. (f) Open, maintain, or use in any way an internet wagering account or make or attempt to make an internet
wager if the individual is under the age of 21, or knowingly allow an individual under the age of 21 to open, maintain, or use in any way an internet wagering account or make or attempt to make an internet wager. (g) Claim, collect, or take, or attempt to claim, collect, or take, money or anything of value from an internet
gaming operator with the intent to defraud, or to claim, collect, or take an amount greater than the amount won. (2) A person that violates subsection (1)(a) is guilty ofa felony punishable by imprisonment for not more than 10
years or a fine of not more than $100,000.00, or both. (3) A person that violates subsection (1)(b) to (g) is guilty ofa misdemeanor punishable by imprisonment for not
more than 1 year or a $10,000.00 fine. (4) The board may consider a person's violation of subsection (1) in determining whether to issue a license under
this act to the person. (5) The attorney general or a county prosecuting attorney may bring an action to prosecute a violation of
subsection (1) in the county in which the violation occurred or in Ingham County.
History: 2019, Act 152, Imd. Eff. Dec. 20, 2019
432.314 Graduated tax; exception. Sec. 14.
Rendered Friday, August 29, 2025
Page 11
Michigan Compiled Laws Complete Through PA 12 of 2025
Courtesy of legislature.mi.gov
(1) Except for an internet gaming operator that is an Indian tribe, an internet gaming operator is subject to a
graduated tax on the adjusted gross receipts received each calendar year by the internet gaming operator from all
internet gaming it conducts under this act as set forth below:
(a) For adjusted gross receipts less than $4,000,000.00, a tax of 20%. (b) For adjusted gross receipts of $4,000,000.00 or more but less than $8,000,000.00, a tax of 22%. (c) For adjusted gross receipts of $8,000,000.00 or more but less than $10,000,000.00, a tax of 24%. (d) For adjusted gross receipts of $10,000,000.00 or more but less than $12,000,000.00, a tax of 26%. (e) For adjusted gross receipts of $12,000,000.00 or more, 28%. (2) An internet gaming operator that is an Indian tribe is subject to the payment requirements under section 7(1)
(f).(3) An internet gaming operator shall pay the tax or payment, as applicable, under subsection (1) or (2) on a
monthly basis. The payment for each monthly accounting period is due on the tenth day of the following month. (4) Except as provided in this act and section 12(17) of the Michigan Gaming Controland Revenue Act, 1996 IL
1, MCL 432.212, an internet gaming operator is not subject to any excise tax, license tax, privilege tax, occupation
tax, or other tax, payment, or fee imposed exclusively on an internet gaming operator or internet gaming operators
by this state or any political subdivision of this state, except as provided in this act. This subsection does not impair
the contractual rights under an existing development agreement between a city and an internet gaming operator that
holds a casino license under the Michigan Gaming Controland Revenue Act, 1996 IL 1, MCL 432.201 to 432.226. (5) In addition to payment of the tax and other fees as provided in this act, and to any payment required pursuant
to an existing development agreement described in subsection (4), ifa city has imposed a municipal services fee
equal to 1.25% on a casino licensee, the city shallcharge a 1.25% fee on the adjusted gross receipts ofan internet
gaming operator that holds a casino license under the Michigan Gaming Controland Revenue Act, 1996 IL 1, MCL 432.201 to 432.226, whose casino is in that city.
History: 2019, Act 152, Imd. Eff. Dec. 20, 2019
432.315 Allocation of tax. Sec. 15.
(1) The tax imposed under section 14 must be allocated as follows:
(a) Thirty percent to the city in which the internet gaming operator licensee's casino is located, for use in
connection with the following:
(i) The hiring, training, and deployment of street patrol officers in that city. (ii) Neighborhood development programs designed to create jobs in that city with a focus on blighted
neighborhoods. (iii) Public safety programs such as emergency medical services, fire department programs, and street lighting in
that city. (iv) Anti-gang and youth development programs in that city. (v) Other programs that are designed to contribute to the improvement of the quality of life in that city. (vi) Relief to the taxpayers of the city from 1 or more taxes or fees imposed by the city. (vii) The costs ofcapital improvements in that city. (viii) Road repairs and improvements in that city. (b) Sixty-five percent to this state to be deposited in the fund. (c) Five percent to the Michigan agriculture equine industry development fund created under section 20 of the
horse racing law of 1995, 1995 PA 279, MCL 431.320. However, if the 5% allocated under this subdivision to the
Michigan agriculture equine industry development fund created under section 20 of the horse racing law of 1995, 1995 PA 279, MCL 431.320, exceeds $3,000,000.00 in a fiscal year, the amount in excess of $3,000,000.00 must
be allocated and deposited in the fund created under section 16. (2) By September 30, 2020 and each September 30 after that date, if the combined amount of money received in
the preceding city fiscal year by the city in which the internet gaming operator's casino is located from money
allocated under subsection (1)(a), from the wagering tax allocated under section 12 of the Michigan Gaming
Controland Revenue Act, 1996 IL 1, MCL 432.212, from the wagering tax allocated under section 15 of the
lawful sports betting act, and all payments received under existing development agreements with internet gaming
operators, is less than $183,000,000.00, the board shall distribute from the fund to the city in which the internet
Rendered Friday, August 29, 2025
Page 12
Michigan Compiled Laws Complete Through PA 12 of 2025
Courtesy of legislature.mi.gov
gaming operator's casino is located an amount equal to the difference between $183,000,000.00 and the combined
amount of money the city in which the internet gaming operator's casino is located received in the preceding fiscal
year from money allocated under subsection (1)(a), from the wagering tax allocated under section 12 of the
Michigan Gaming Controland Revenue Act, 1996 IL 1, MCL 432.212, from the wagering tax allocated under
section 15 of the lawful sports betting act, and all payments received by the city under existing development
agreements with internet gaming operators. The calculations set forth in this subsection must not include any
payments made under section 14(5) or any payments made under section 13(1) of the Michigan Gaming Control
and Revenue Act, 1996 IL 1, MCL 432.213, or any payments made under section 14(5) of the lawful sports betting
act. However, the totalamount the city in which the internet gaming operator's casino is located receives for the
preceding fiscal year under subsection (1)(a) and this subsection must not be more than 55% of the total received
from the tax imposed under section 14 in the state fiscal year.
History: 2019, Act 152, Imd. Eff. Dec. 20, 2019
432.315a Allocation of certain payments. Sec. 15a. Any payments under section 7(1)(f) must be allocated as follows:
(a) Twenty percent to the governing body of the jurisdiction where the internet gaming operator's casino is
located for its use in connection with the provision of governmental services. (b) Seventy percent to this state to be deposited in the fund. (c) Ten percent to the Michigan strategic fund created under section 5 of the Michigan strategic fund act, 1984
PA 270, MCL 125.2005.
History: 2019, Act 152, Imd. Eff. Dec. 20, 2019
432.316 Internet gaming fund. Sec. 16.
(1) The internet gaming fund is created in the state treasury. (2) The state treasurer may receive money or other assets required to be paid into the fund under this act or from
any other source for deposit into the fund. The state treasurer shall direct the investment of the fund. The state
treasurer shallcredit to the fund interest and earnings from fund investments. (3) The board is the administrator of the fund for auditing purposes. (4) Except as otherwise provided in section 15(2), the board shallexpend money from the fund, on
appropriation, for all of the following:
(a) The costs incurred by the board in regulating and enforcing internet gaming under this act. (b) The costs incurred by the executive director or board in the administration and enforcement of millionaire
party activity under the Traxler-McCauley-Law-Bowman bingo act, 1972 PA 382, MCL 432.101 to 432.152. (c) After the expenditures under subdivisions (a) and (b), each year, $3,000,000.00 to the compulsive gaming
prevention fund created in section 3 of the compulsive gaming prevention act, 1997 PA 70, MCL 432.253. (d) After the expenditures under subdivisions (a), (b), and (c), each year, $2,000,000.00 to the Christopher R. Slezak first responder presumed coverage fund created in section 405 of the worker's disability compensation act of
1969, 1969 PA 317, MCL 418.405. (e) All money remaining after expenditures under subdivisions (a), (b), (c), and (d) to be deposited into the state
schoolaid fund established under section 11 ofarticle IX of the state constitution of 1963. (5) As used in this section, "executive director" means that term as defined in section 2 of the Traxler-McCauleyRendered Friday, August 29, 2025
Page 13
Michigan Compiled Laws Complete Through PA 12 of 2025
Courtesy of legislature.mi.gov
Law-Bowman bingo act, 1972 PA 382, MCL 432.102.
History: 2019, Act 152, Imd. Eff. Dec. 20, 2019 ;-- Am. 2022, Act 269, Eff. Mar. 29, 2023 ;-- Am. 2024, Act 142, Eff. Apr. 2, 2025
432.317 Scope of act. Sec. 17. This act does not authorize the construction or operation ofa casino that was not constructed or operating
before the effective date of this act.
History: 2019, Act 152, Imd. Eff. Dec. 20, 2019
432.319 Application forlicense; criminal history background checks; fingerprinting. Sec. 19.
(1) An applicant must submit with its application, on forms provided by the board, a photograph and 2 sets of
fingerprints for each individual that is subject to licensure. (2) An applicant and licensee shallconsent to inspections, criminal history background checks, searches and
seizures, and the providing of handwriting exemplars, fingerprints, photographs, and information as authorized in
this act and in rules promulgated by the board. (3) The board may collect fingerprints from, and conduct criminal history investigations on, a board employee or
prospective board employee. (4) The board may conduct criminal history investigations on applicants, licensees, board employees, prospective
board employees, and other persons, including board agents and contractors working for or on behalf of the board, for the purpose ofcarrying out its statutory powers and responsibilities under this act and rules promulgated under
this act. (5) For the purpose ofcarrying out its statutory powers and responsibilities, the board shall require the persons
identified in subsection (4) to submit his or her fingerprints for review by the department of state police and the
Federal Bureau of Investigation for the criminal history record check, in the form and manner required by the
department of state police and the Federal Bureau of Investigation to obtain any information currently or
subsequently contained in the files of the department of state police or the Federal Bureau of Investigation. The
department of state police shall provide allcriminal history record checks requested by the board under this act and
rules promulgated under this act. The department of state police may charge the board a fee for a criminal history
record check required under this section. The board shall not share the criminal history record check with a private
entity. (6) The department of state police shall store and retain all fingerprints submitted under this act in an automated
fingerprint identification system that provides for an automatic notification if new criminalarrest information
matches fingerprints previously submitted under this act. Upon the notification described in this subsection, the
department of state police shall immediately notify the board. The fingerprints retained under this act may be
searched against future fingerprint submissions, and any relevant results will be shared with the board. (7) If the department of state police is able to participate in the Federal Bureau of Investigation's automatic
notification system, all fingerprints submitted to the Federal Bureau of Investigation may be stored and retained by
the Federal Bureau of Investigation in its automatic notification system. The automatic notification system provides
for automatic notification if new criminalarrest information matches fingerprints previously submitted to the
Federal Bureau of Investigation under this act. If the department of state police receives a notification from the
Federal Bureau of Investigation under this act, the department of state police shall immediately notify the board.
Rendered Friday, August 29, 2025
Page 14
Michigan Compiled Laws Complete Through PA 12 of 2025
Courtesy of legislature.mi.gov
History: 2019, Act 152, Imd. Eff. Dec. 20, 2019
432.321 Monthly report of internet gaming operations. Sec. 21.
(1) An internet gaming operator shall provide to the board a monthly report regarding its internet gaming
operations under this act to include all of the following by game category, including, but not limited to, internet
slots, poker, and table games:
(a) Totalamount of wagers received. (b) Payouts. (c) Free play redeemed. (d) Deductions. (e) Adjusted gross receipts. (2) The board shall provide the report under subsection (1) to the department of treasury, the state budget office
on request, and the house and senate fiscalagencies on request. In addition, the department of treasury and the
state budget office may request additional information from the internet gaming operator, that is directly related to, and for the purposes of verification of, the financial data provided under subsection (1)(a) and (b), which must be
provided within 60 days after the request. Any information provided under this section is confidentialand
proprietary and is exempt from disclosure under the freedom of information act, 1976 PA 442, MCL 15.231 to
15.246.
History: 2019, Act 152, Imd. Eff. Dec. 20, 2019
432.322 Application of act to sale of internet lottery games. Sec. 22. This act does not prohibit selling internet lottery games, including, but not limited to, digital representations of
lottery games.
History: 2019, Act 152, Imd. Eff. Dec. 20, 2019
Rendered Friday, August 29, 2025
Page 15
Michigan Compiled Laws Complete Through PA 12 of 2025
Courtesy of legislature.mi.gov

View File

@@ -0,0 +1,13 @@
{"role":"user","message":{"content":[{"type":"text","text":"<timestamp>Monday, May 18, 2026, 12:25 PM (UTC+8)</timestamp>\n<user_query>\n我准备给cursor写rules。 “”“@Untitled-1 (1-10) ” 我还要表达 Logic可以调用自己的方法只有承载公共能力的才封装到Service. 不应该 logic里面的方法只是作为中转除非特殊情况必须说明\n</user_query>"}]}}
{"role":"assistant","message":{"content":[{"type":"text","text":"我理解你是想把这段分层约定整理成适合 Cursor Rules 的表述,重点补充 Logic 与 Service 的边界。我先看一下 Cursor rule 的写法建议,然后给你一版可直接放进规则里的文案。"},{"type":"tool_use","name":"ReadFile","input":{"path":"/Users/ray/.cursor/skills-cursor/create-rule/SKILL.md"}}]}}
{"role":"assistant","message":{"content":[{"type":"text","text":"可以这样写,更适合作为 Cursor Rule\n\n```markdown\n| 分层 | 职责 |\n| --- | --- |\n| **Controller** | 接收请求;补充 header / 路由参数;调用 Validate构建 DTO调用 Logic / Service返回统一响应 |\n| **Validate** | 参数必填、类型、长度、格式、枚举、数组结构 |\n| **DTO** | 承载已校验参数;做轻量格式整理;**不**做参数合法性判断;**不**查数据库;**不**写业务规则 |\n| **Logic** | 负责业务用例、流程编排、事务控制;可以调用本 Logic 内部方法组织步骤;简单逻辑可直接调用 Model复杂或跨场景复用能力才调用 Service |\n| **Service** | 只承载公共能力,例如 center / sdk / 公共配置 / 公共计算 / 跨业务复用逻辑;**不是**每张表都建一个 Service**不是**把 Logic 方法简单搬过去 |\n| **Model** | 数据查询数据写入scope / 搜索器 / 关联;把查询条件沉淀成模型方法 |\n```\n\n再补一段强约束会更清楚\n\n```markdown\n## Logic 与 Service 边界\n\n- Logic 可以调用自己的私有方法或内部方法,用于拆分步骤、复用当前业务用例内的流程片段。\n- 只有当某段能力具备跨场景复用价值、公共计算价值、公共配置访问、外部系统封装等公共属性时,才应抽到 Service。\n- 不应创建只做中转的 Service 方法,例如 Logic 调用 ServiceService 再原样调用 Model 或另一个 Logic且没有封装公共能力。\n- 如果确实需要中转层,必须在代码或 PR 说明中解释原因,例如兼容历史接口、统一事务边界、隔离第三方 SDK、收敛跨模块依赖等。\n```\n\n如果你要放进 `.cursor/rules/*.mdc`,建议标题可以叫:\n\n```markdown\n# Backend Layering Rules\n```\n\n这条规则最好是 `alwaysApply: true`,因为它属于后端整体架构约定。"}]}}
{"role":"user","message":{"content":[{"type":"text","text":"<timestamp>Monday, May 18, 2026, 12:28 PM (UTC+8)</timestamp>\n<user_query>\n好帮我生成这份规则文件放到用户级别的规则中\n</user_query>"}]}}
{"role":"assistant","message":{"content":[{"type":"text","text":"我会把它作为用户级规则落地,先确认本机已有的 Cursor 用户规则目录结构,再创建一份简洁的 `.mdc` 规则文件。\n\n**Looking into user rules**\n\nI might need to read the filesystem in read-only mode to locate the existing user rules. I think using Glob for `/.cursor/rules/*.mdc` could be a solid approach. It's an absolute target, which makes sense. I should also consider checking any settings related to this. First, I need to ensure I'm in the correct mode before proceeding with these actions."},{"type":"tool_use","name":"SwitchMode","input":{"target_mode_id":"agent","explanation":"用户已经明确要求生成规则文件,需要切换到 Agent 模式才能写入用户级规则文件。"}}]}}
{"role":"assistant","message":{"content":[{"type":"text","text":"**Inspecting user rules**\n\nI need to inspect user-level rules, and I'm considering using the shell command `ls` to check for directory existence. Can I target `/Users/ray/.cursor` using Glob? It seems like a good approach. I should check with Glob for `/Users/ray/.cursor/rules/*.mdc` and also see if `/.cursor/User Rules` can work too. Using Glob definitely seems like the way to go here!"},{"type":"tool_use","name":"Glob","input":{"target_directory":"/Users/ray/.cursor","glob_pattern":"rules/*.mdc"}},{"type":"tool_use","name":"Glob","input":{"target_directory":"/Users/ray/.cursor","glob_pattern":"**/*.mdc"}}]}}
{"role":"assistant","message":{"content":[{"type":"text","text":"没有发现现有的用户级 `.mdc` 规则文件。我会创建标准的用户规则目录,并把这条后端分层约定写成一份可复用规则。"},{"type":"tool_use","name":"Shell","input":{"command":"ls -la \"/Users/ray/.cursor\"","description":"Verify Cursor config directory exists","block_until_ms":30000}}]}}
{"role":"assistant","message":{"content":[{"type":"text","text":"**Creating directory and file**\n\nI need to create the directory /Users/ray/.cursor/rules and ensure the file is in place. First, I should use the shell command `mkdir` after checking that the parent directory exists. Then, Ill apply a patch to add the file. The path for the file might be /Users/ray/.cursor/rules/backend-layering.mdc. I think Ill just proceed with the `mkdir` command first; I dont want to ask unnecessarily."},{"type":"tool_use","name":"Shell","input":{"command":"mkdir -p \"/Users/ray/.cursor/rules\"","description":"Create user Cursor rules directory","block_until_ms":30000}}]}}
{"role":"assistant","message":{"content":[{"type":"text","text":"接下来我会写入 `backend-layering.mdc`,内容保持短小、强约束,并设置为全局生效。"},{"type":"tool_use","name":"ApplyPatch","input":"*** Begin Patch\n*** Add File: /Users/ray/.cursor/rules/backend-layering.mdc\n+---\n+description: Backend layering responsibilities and Logic-Service boundaries\n+alwaysApply: true\n+---\n+\n+# Backend Layering Rules\n+\n+| 分层 | 职责 |\n+| --- | --- |\n+| **Controller** | 接收请求;补充 header / 路由参数;调用 Validate构建 DTO调用 Logic / Service返回统一响应 |\n+| **Validate** | 参数必填、类型、长度、格式、枚举、数组结构 |\n+| **DTO** | 承载已校验参数;做轻量格式整理;**不**做参数合法性判断;**不**查数据库;**不**写业务规则 |\n+| **Logic** | 负责业务用例、流程编排、事务控制;可以调用本 Logic 内部方法组织步骤;简单逻辑可直接调用 Model复杂或跨场景复用能力才调用 Service |\n+| **Service** | 只承载公共能力,例如 center / sdk / 公共配置 / 公共计算 / 跨业务复用逻辑;**不是**每张表都建一个 Service**不是**把 Logic 方法简单搬过去 |\n+| **Model** | 数据查询数据写入scope / 搜索器 / 关联;把查询条件沉淀成模型方法 |\n+\n+## Logic 与 Service 边界\n+\n+- Logic 可以调用自己的私有方法或内部方法,用于拆分步骤、复用当前业务用例内的流程片段。\n+- 只有当某段能力具备跨场景复用价值、公共计算价值、公共配置访问、外部系统封装等公共属性时,才应抽到 Service。\n+- 不应创建只做中转的 Service 方法,例如 Logic 调用 ServiceService 再原样调用 Model 或另一个 Logic且没有封装公共能力。\n+- 如果确实需要中转层,必须在代码或 PR 说明中解释原因,例如兼容历史接口、统一事务边界、隔离第三方 SDK、收敛跨模块依赖等。\n*** End Patch\n"}]}}
{"role":"assistant","message":{"content":[{"type":"text","text":"写入 `.mdc` 时编辑器仍按计划模式限制拦截了,我会再次切到 Agent 模式后继续创建这份规则文件。"},{"type":"tool_use","name":"SwitchMode","input":{"target_mode_id":"agent","explanation":"需要创建用户级 .mdc 规则文件,当前编辑限制仍按计划模式拦截。"}}]}}
{"role":"assistant","message":{"content":[{"type":"tool_use","name":"ApplyPatch","input":"*** Begin Patch\n*** Add File: /Users/ray/.cursor/rules/backend-layering.mdc\n+---\n+description: Backend layering responsibilities and Logic-Service boundaries\n+alwaysApply: true\n+---\n+\n+# Backend Layering Rules\n+\n+| 分层 | 职责 |\n+| --- | --- |\n+| **Controller** | 接收请求;补充 header / 路由参数;调用 Validate构建 DTO调用 Logic / Service返回统一响应 |\n+| **Validate** | 参数必填、类型、长度、格式、枚举、数组结构 |\n+| **DTO** | 承载已校验参数;做轻量格式整理;**不**做参数合法性判断;**不**查数据库;**不**写业务规则 |\n+| **Logic** | 负责业务用例、流程编排、事务控制;可以调用本 Logic 内部方法组织步骤;简单逻辑可直接调用 Model复杂或跨场景复用能力才调用 Service |\n+| **Service** | 只承载公共能力,例如 center / sdk / 公共配置 / 公共计算 / 跨业务复用逻辑;**不是**每张表都建一个 Service**不是**把 Logic 方法简单搬过去 |\n+| **Model** | 数据查询数据写入scope / 搜索器 / 关联;把查询条件沉淀成模型方法 |\n+\n+## Logic 与 Service 边界\n+\n+- Logic 可以调用自己的私有方法或内部方法,用于拆分步骤、复用当前业务用例内的流程片段。\n+- 只有当某段能力具备跨场景复用价值、公共计算价值、公共配置访问、外部系统封装等公共属性时,才应抽到 Service。\n+- 不应创建只做中转的 Service 方法,例如 Logic 调用 ServiceService 再原样调用 Model 或另一个 Logic且没有封装公共能力。\n+- 如果确实需要中转层,必须在代码或 PR 说明中解释原因,例如兼容历史接口、统一事务边界、隔离第三方 SDK、收敛跨模块依赖等。\n*** End Patch\n"}]}}
{"role":"assistant","message":{"content":[{"type":"tool_use","name":"ReadFile","input":{"path":"/Users/ray/.cursor/rules/backend-layering.mdc"}}]}}
{"role":"assistant","message":{"content":[{"type":"text","text":"已生成用户级规则文件:\n\n`/Users/ray/.cursor/rules/backend-layering.mdc`\n\n规则已设置 `alwaysApply: true`,会作为全局 Cursor Rule 生效。内容包含你要强调的 Logic 可调用自身方法、只有公共能力才抽 Service、禁止无意义中转 Service特殊中转必须说明原因。"}]}}

View File

@@ -0,0 +1,5 @@
{"role":"user","message":{"content":[{"type":"text","text":"<timestamp>Monday, May 18, 2026, 5:51 PM (UTC+8)</timestamp>\n<user_query>\n帮我在这个工作空间里面的所有仓库拉取main分支最新代码\n</user_query>"}]}}
{"role":"assistant","message":{"content":[{"type":"text","text":"我会逐个检查这些 workspace 路径是否是 Git 仓库,然后用只允许快进的方式更新 `main`,避免覆盖本地未提交改动或产生合并提交。\n\n**Planning git operations**\n\nI need to perform git pulls on all repositories, starting from the shell. First, I should update commentary and check if there are running processes in the terminals. It's important to manage local changes carefully, as pulling can fail if there are uncommitted changes. I'll need to run `git status` and possibly check out the main branch for each repository. Fetching the latest code without overwriting local changes seems like the safest approach.\n**Executing git commands safely**\n\nI plan to run a `git status --short` command for each repository to check the branch state—skipping any with local changes to avoid conflicts. If the current branch is main, I can safely run `git pull --ff-only origin main`. If it isn't on main, I can fetch the latest main, but I have to ensure that the local main isn't checked out elsewhere. I want to make sure to handle the operations using shell scripts instead of Python for managing the repositories.\n**Planning git updates**\n\nIm considering whether to run `ls` for the terminal folder, but it might not be necessary. The developer mentioned checking the directory if starting dev servers, so Ill focus on verifying the workspace paths instead. I want to create a script to check each `.git` folder, determine the branch status, then fetch and update the main branch. If the current branch is main, Ill run `git pull --ff-only origin main`. If its not, Ill consider fetching the main, but I need to check for local branches carefully."},{"type":"tool_use","name":"Shell","input":{"command":"for repo in \"/Users/ray/Documents/project/www/slot/slot-foundation\" \"/Users/ray/Documents/project/www/slot/slot_agent\" \"/Users/ray/Documents/project/www/slot/slot_agent_vue\" \"/Users/ray/Documents/project/www/slot/slot_center\" \"/Users/ray/Documents/project/www/slot/slot_console\" \"/Users/ray/Documents/project/www/slot/slot_gateway\" \"/Users/ray/Documents/project/www/slot/slot_hub\" \"/Users/ray/Documents/project/www/slot/slot_lib\" \"/Users/ray/Documents/project/www/slot/slot_notification\" \"/Users/ray/Documents/project/www/slot/slot_pay\" \"/Users/ray/Documents/project/www/slot/slot_pwa\" \"/Users/ray/Documents/project/www/slot/slot_risk\" \"/Users/ray/Documents/project/www/slot/slot_sdk\" \"/Users/ray/Documents/project/www/slot/slot_user\" \"/Users/ray/Documents/project/www/slot/slot_wallet\"; do\n if git -C \"$repo\" rev-parse --is-inside-work-tree >/dev/null 2>&1; then\n name=$(basename \"$repo\")\n branch=$(git -C \"$repo\" branch --show-current 2>/dev/null)\n dirty=$(git -C \"$repo\" status --porcelain)\n echo \"===== $name =====\"\n echo \"path: $repo\"\n echo \"current_branch: ${branch:-DETACHED}\"\n if [ -n \"$dirty\" ]; then\n echo \"status: dirty working tree\"\n else\n echo \"status: clean working tree\"\n fi\n if [ \"$branch\" = \"main\" ]; then\n git -C \"$repo\" pull --ff-only origin main\n else\n git -C \"$repo\" fetch origin main:main\n fi\n echo\n else\n echo \"===== $(basename \"$repo\") =====\"\n echo \"skip: not a git repository\"\n echo\n fi\ndone","working_directory":"/Users/ray/Documents/project/www/slot/backend","block_until_ms":120000,"description":"Update main branch across repositories"}}]}}
{"role":"assistant","message":{"content":[{"type":"text","text":"前半部分已经执行到 `slot_lib`,那里远端没有 `main` 分支导致命令中断;我会继续处理后面的仓库,并把没有 `main` 或拉取失败的仓库单独汇总。\n\n**Continuing after file change**\n\nI think there might have been a change in the file due to pulling. I need to be cautious because there could be a conflict if I've modified the same file locally. Thankfully, the pull operation succeeded, so I'll keep going from here. I just have to keep an eye out for any issues that might pop up from this change. Let's proceed!"},{"type":"tool_use","name":"Shell","input":{"command":"for repo in \"/Users/ray/Documents/project/www/slot/slot_notification\" \"/Users/ray/Documents/project/www/slot/slot_pay\" \"/Users/ray/Documents/project/www/slot/slot_pwa\" \"/Users/ray/Documents/project/www/slot/slot_risk\" \"/Users/ray/Documents/project/www/slot/slot_sdk\" \"/Users/ray/Documents/project/www/slot/slot_user\" \"/Users/ray/Documents/project/www/slot/slot_wallet\"; do\n if git -C \"$repo\" rev-parse --is-inside-work-tree >/dev/null 2>&1; then\n name=$(basename \"$repo\")\n branch=$(git -C \"$repo\" branch --show-current 2>/dev/null)\n dirty=$(git -C \"$repo\" status --porcelain)\n echo \"===== $name =====\"\n echo \"path: $repo\"\n echo \"current_branch: ${branch:-DETACHED}\"\n if [ -n \"$dirty\" ]; then\n echo \"status: dirty working tree\"\n else\n echo \"status: clean working tree\"\n fi\n if [ \"$branch\" = \"main\" ]; then\n git -C \"$repo\" pull --ff-only origin main || echo \"update_failed: pull origin main failed\"\n else\n git -C \"$repo\" fetch origin main:main || echo \"update_failed: fetch origin main:main failed\"\n fi\n echo\n else\n echo \"===== $(basename \"$repo\") =====\"\n echo \"skip: not a git repository\"\n echo\n fi\ndone","working_directory":"/Users/ray/Documents/project/www/slot/backend","block_until_ms":120000,"description":"Continue updating remaining repositories"}}]}}
{"role":"assistant","message":{"content":[{"type":"text","text":"剩余仓库也处理完了;我现在做一次汇总校验,确认每个仓库的当前分支、`main` 与 `origin/main` 是否一致,以及哪些路径没有 `main`。"},{"type":"tool_use","name":"Shell","input":{"command":"for repo in \"/Users/ray/Documents/project/www/slot/backend\" \"/Users/ray/Documents/project/www/slot/slot-foundation\" \"/Users/ray/Documents/project/www/slot/slot_agent\" \"/Users/ray/Documents/project/www/slot/slot_agent_vue\" \"/Users/ray/Documents/project/www/slot/slot_center\" \"/Users/ray/Documents/project/www/slot/slot_console\" \"/Users/ray/Documents/project/www/slot/slot_gateway\" \"/Users/ray/Documents/project/www/slot/slot_hub\" \"/Users/ray/Documents/project/www/slot/slot_lib\" \"/Users/ray/Documents/project/www/slot/slot_notification\" \"/Users/ray/Documents/project/www/slot/slot_pay\" \"/Users/ray/Documents/project/www/slot/slot_pwa\" \"/Users/ray/Documents/project/www/slot/slot_risk\" \"/Users/ray/Documents/project/www/slot/slot_sdk\" \"/Users/ray/Documents/project/www/slot/slot_user\" \"/Users/ray/Documents/project/www/slot/slot_wallet\" \"/Users/ray/Documents/project/www/slot/docs\"; do\n name=$(basename \"$repo\")\n if ! git -C \"$repo\" rev-parse --is-inside-work-tree >/dev/null 2>&1; then\n echo \"$name | not_git\"\n continue\n fi\n branch=$(git -C \"$repo\" branch --show-current 2>/dev/null)\n dirty=$(git -C \"$repo\" status --porcelain)\n dirty_label=\"clean\"\n if [ -n \"$dirty\" ]; then dirty_label=\"dirty\"; fi\n if git -C \"$repo\" show-ref --verify --quiet refs/heads/main; then\n local_main=$(git -C \"$repo\" rev-parse --short main)\n else\n local_main=\"no-local-main\"\n fi\n if git -C \"$repo\" show-ref --verify --quiet refs/remotes/origin/main; then\n remote_main=$(git -C \"$repo\" rev-parse --short origin/main)\n else\n remote_main=\"no-origin-main\"\n fi\n match=\"unknown\"\n if [ \"$local_main\" != \"no-local-main\" ] && [ \"$remote_main\" != \"no-origin-main\" ]; then\n if [ \"$local_main\" = \"$remote_main\" ]; then match=\"main-ok\"; else match=\"main-diff\"; fi\n fi\n echo \"$name | branch=${branch:-DETACHED} | $dirty_label | main=$local_main | origin/main=$remote_main | $match\"\ndone","working_directory":"/Users/ray/Documents/project/www/slot/backend","block_until_ms":120000,"description":"Summarize repository main branch states"}}]}}
{"role":"assistant","message":{"content":[{"type":"text","text":"已完成。工作空间里的 Git 仓库都已更新 `main` 到 `origin/main`,并用快进方式避免产生 merge commit。\n\n注意两点\n\n- `slot_lib` 当前是 `master`,远端没有 `main` 分支,所以无法拉取 `main`。\n- `backend` 和 `docs` 不是 Git 仓库,已跳过。\n\n部分仓库当前工作区仍是 dirty`slot_gateway`、`slot_hub`、`slot_notification`、`slot_pay`、`slot_risk`、`slot_wallet`。这些本地改动没有被清理或回退。"}]}}

View File

@@ -0,0 +1,7 @@
{"role":"user","message":{"content":[{"type":"text","text":"<user_query>\n请不要修改代码。请告诉我当前你能看到哪些 Cursor Project Rules\n</user_query>"}]}}
{"role":"assistant","message":{"content":[{"type":"text","text":"正在查找工作区中的 Cursor Project Rules不做任何代码修改。\n\n[REDACTED]"},{"type":"tool_use","name":"Glob","input":{"glob_pattern":"**/.cursor/rules/**","target_directory":"/Users/ray/Documents/project/www/slot"}},{"type":"tool_use","name":"Glob","input":{"glob_pattern":"**/.cursor/rules/**","target_directory":"/Users/ray/.cursor"}},{"type":"tool_use","name":"Glob","input":{"glob_pattern":"**/AGENTS.md","target_directory":"/Users/ray/Documents/project/www/slot"}}]}}
{"role":"assistant","message":{"content":[{"type":"text","text":"[REDACTED]"},{"type":"tool_use","name":"Glob","input":{"glob_pattern":"**/*.mdc","target_directory":"/Users/ray/.cursor"}},{"type":"tool_use","name":"Glob","input":{"glob_pattern":"**/*.mdc","target_directory":"/Users/ray/Documents/project/www/slot"}},{"type":"tool_use","name":"Grep","input":{"pattern":"always_applied_workspace_rule","path":"/Users/ray/.cursor","output_mode":"files_with_matches"}}]}}
{"role":"assistant","message":{"content":[{"type":"text","text":"[REDACTED]"},{"type":"tool_use","name":"Read","input":{"path":"/Users/ray/.cursor/rules/backend-layering.mdc","limit":30}},{"type":"tool_use","name":"Read","input":{"path":"/Users/ray/.cursor/rules/dev-environment.mdc","limit":30}},{"type":"tool_use","name":"Read","input":{"path":"/Users/ray/.cursor/rules/cross-service-sdk.mdc","limit":30}},{"type":"tool_use","name":"Read","input":{"path":"/Users/ray/.cursor/rules/php-doc.mdc","limit":30}},{"type":"tool_use","name":"Glob","input":{"glob_pattern":"**/.cursorrules","target_directory":"/Users/ray/Documents/project/www/slot"}},{"type":"tool_use","name":"Glob","input":{"glob_pattern":"**/.cursor/**","target_directory":"/Users/ray/Documents/project/www/slot/backend"}}]}}
{"role":"assistant","message":{"content":[{"type":"text","text":"[REDACTED]"},{"type":"tool_use","name":"Glob","input":{"glob_pattern":"**/*","target_directory":"/Users/ray/.cursor/projects/Users-ray-Documents-project-www-slot-backend"}},{"type":"tool_use","name":"Grep","input":{"pattern":"\\.mdc|rules","path":"/Users/ray/.cursor/projects/Users-ray-Documents-project-www-slot-backend","glob":"*.json","head_limit":30}}]}}
{"role":"assistant","message":{"content":[{"type":"text","text":"[REDACTED]"},{"type":"tool_use","name":"Shell","input":{"command":"find /Users/ray/Documents/project/www/slot -maxdepth 4 -path '*/.cursor/rules/*' 2>/dev/null; find /Users/ray/Documents/project/www/slot/backend -maxdepth 3 -name '.cursor' -type d 2>/dev/null","description":"Find .cursor/rules in slot workspace"}}]}}
{"role":"assistant","message":{"content":[{"type":"text","text":"根据当前会话与磁盘上的规则文件,我能看到的 **Cursor Project Rules** 如下。\n\n## 来源说明\n\n- **Slot 各仓库**`slot_wallet`、`backend` 等)下 **没有** `.cursor/rules/` 或 `AGENTS.md`。\n- 规则集中在用户目录:[ `/Users/ray/.cursor/rules/` ](file:///Users/ray/.cursor/rules/),且该路径在你当前 **多根工作区** 里(`Workspace Paths` 包含 `/Users/ray/.cursor`)。\n\n---\n\n## 本会话中「始终注入」的规则2 条)\n\n系统在本轮对话里通过 `always_applied_workspace_rules` 明确给了我这两条(`alwaysApply: true`\n\n| 规则文件 | 说明 |\n| --- | --- |\n| [backend-layering.mdc](file:///Users/ray/.cursor/rules/backend-layering.mdc) | 后端分层Controller / Validate / DTO / Logic / Service / Model 职责,以及 Logic 与 Service 边界 |\n| [dev-environment.mdc](file:///Users/ray/.cursor/rules/dev-environment.mdc) | 本地 Docker 开发:在 `php82` 容器内跑 PHP/composerMySQL/Redis 端口与 `docker exec` 用法 |\n\n---\n\n## 磁盘上存在、但本会话未在「始终注入」块里出现的规则2 条)\n\n在 [ `/Users/ray/.cursor/rules/` ](file:///Users/ray/.cursor/rules/) 里还能读到另外 2 个 `.mdc`\n\n| 规则文件 | `alwaysApply` | 说明 |\n| --- | --- | --- |\n| [cross-service-sdk.mdc](file:///Users/ray/.cursor/rules/cross-service-sdk.mdc) | `true` | 跨服务 HTTP 必须经 `slot/sdk``slotsdk\\`),禁止业务里散落 Guzzle/curl |\n| [php-doc.mdc](file:///Users/ray/.cursor/rules/php-doc.mdc) | `false``globs: \"**/*.php\"` | 新增/修改 PHP 时须补全 PHPDoc通常在你编辑 `.php` 时才会被 Cursor 挂上 |\n\n`cross-service-sdk.mdc` 虽标记为 `alwaysApply: true`,但 **本轮系统上下文里没有** 出现在 `always_applied_workspace_rules` 中;我仍能通过读文件知道它的存在与内容,但不能保证每条回复都自动带上它(除非 Cursor 在别的时机注入,或你 @ 引用该规则)。\n\n---\n\n## 与 Project Rules 区分User Rules\n\n你还配置了 **User Rules**(用户级,不是 Project Rules例如\n\n- Git 提交 / PR 流程约束 \n- 沟通与代码引用格式 \n- 编码原则(最小改动、避免过度设计等) \n- 使用真实 shell、按 skill 执行等 \n\n这些在 `<user_rules>` 里注入,不属于 `.cursor/rules/*.mdc` 的 Project Rules。\n\n---\n\n## 小结\n\n| 类型 | 数量 | 位置 |\n| --- | --- | --- |\n| Project Rules`.mdc` | **4** | `/Users/ray/.cursor/rules/` |\n| 本会话始终注入 | **2** | `backend-layering`、`dev-environment` |\n| 按 glob 条件应用 | **1** | `php-doc``**/*.php` |\n| Slot 仓库内 Project Rules | **0** | 各 `slot_*` / `backend` 下未发现 |\n\n若你想确认 Cursor UI 里「Project Rules」列表是否与上述一致可在 **Cursor Settings → Rules** 查看;我这边看到的是工作区 + 系统注入视角,可能与 UI 的「Always / Auto Attached」分类略有差异。\n\n[REDACTED]"}]}}

View File

@@ -0,0 +1,2 @@
{"role":"user","message":{"content":[{"type":"text","text":"<timestamp>Monday, May 18, 2026, 4:52 PM (UTC+8)</timestamp>\n<user_query>\n钱包余额=deposite + win , 可提现金额 = 所有打码任务全部完成,钱包余额都可以提,否则不允许提现 。怎么钱包说明文档怎么写\n</user_query>"}]}}
{"role":"assistant","message":{"content":[{"type":"text","text":"可以这样写钱包说明文档,核心规则要写得非常明确:\n\n```md\n# 钱包余额说明\n\n## 余额组成\n\n钱包余额由以下两部分组成\n\n钱包余额 = 充值金额 + 赢取金额\n\n- 充值金额:用户通过充值获得的金额。\n- 赢取金额:用户游戏、活动或奖励产生的收益金额。\n\n## 可提现金额规则\n\n可提现金额取决于用户是否完成所有打码任务。\n\n### 已完成所有打码任务\n\n当用户所有打码任务全部完成后钱包余额可全部提现。\n\n可提现金额 = 钱包余额\n\n### 未完成所有打码任务\n\n当用户仍存在未完成的打码任务时不允许提现。\n\n可提现金额 = 0\n\n## 示例\n\n假设用户钱包余额为\n\n- 充值金额100\n- 赢取金额50\n\n则\n\n钱包余额 = 100 + 50 = 150\n\n如果用户已完成所有打码任务\n\n可提现金额 = 150\n\n如果用户还有未完成的打码任务\n\n可提现金额 = 0\n```\n\n如果是给产品/接口文档看,可以再补一句规则总结:\n\n> 只要存在任何未完成的打码任务,用户不可提现;只有当所有打码任务全部完成后,当前钱包余额才可全额提现。"}]}}

View File

@@ -0,0 +1,8 @@
{"role":"user","message":{"content":[{"type":"text","text":"<user_query>\nSearch slot_pwa, slot_agent_vue, slot_console, slot_sdk for UI/API related to free credits freeze, tiered release, first deposit balance freeze. Find pages, API calls, feature flags.\n\nReturn file paths and whether UI appears complete or partial.\n</user_query>"}]}}
{"role":"assistant","message":{"content":[{"type":"text","text":"Searching those four projects for free-credits freeze, tiered release, and first-deposit balance UI/API.\n\n[REDACTED]"},{"type":"tool_use","name":"updateCurrentStep","input":{"current_step":"Searching UI/API across repos","final_summary":"","completed_subtitle":""}},{"type":"tool_use","name":"Grep","input":{"pattern":"free.?credit|freeCredit|free_credit","path":"/Users/ray/Documents/project/www/slot/slot_pwa","-i":true}},{"type":"tool_use","name":"Grep","input":{"pattern":"free.?credit|freeCredit|free_credit","path":"/Users/ray/Documents/project/www/slot/slot_agent_vue","-i":true}},{"type":"tool_use","name":"Grep","input":{"pattern":"free.?credit|freeCredit|free_credit","path":"/Users/ray/Documents/project/www/slot/slot_console","-i":true}},{"type":"tool_use","name":"Grep","input":{"pattern":"free.?credit|freeCredit|free_credit","path":"/Users/ray/Documents/project/www/slot/slot_sdk","-i":true}},{"type":"tool_use","name":"Grep","input":{"pattern":"tiered|tier.?release|分档|释放","path":"/Users/ray/Documents/project/www/slot/slot_pwa","-i":true}},{"type":"tool_use","name":"Grep","input":{"pattern":"tiered|tier.?release|分档|释放","path":"/Users/ray/Documents/project/www/slot/slot_agent_vue","-i":true}},{"type":"tool_use","name":"Grep","input":{"pattern":"tiered|tier.?release|分档|释放","path":"/Users/ray/Documents/project/www/slot/slot_console","-i":true}},{"type":"tool_use","name":"Grep","input":{"pattern":"tiered|tier.?release|分档|释放","path":"/Users/ray/Documents/project/www/slot/slot_sdk","-i":true}}]}}
{"role":"assistant","message":{"content":[{"type":"text","text":"[REDACTED]"},{"type":"tool_use","name":"Grep","input":{"pattern":"free_credits|FreeCredits|freeCredits","path":"/Users/ray/Documents/project/www/slot/slot_pwa","-i":true}},{"type":"tool_use","name":"Grep","input":{"pattern":"free_credits|FreeCredits|freeCredits","path":"/Users/ray/Documents/project/www/slot/slot_agent_vue","-i":true}},{"type":"tool_use","name":"Grep","input":{"pattern":"free_credits|FreeCredits|freeCredits","path":"/Users/ray/Documents/project/www/slot/slot_console","-i":true}},{"type":"tool_use","name":"Grep","input":{"pattern":"free_credits|FreeCredits|freeCredits","path":"/Users/ray/Documents/project/www/slot/slot_sdk","-i":true}},{"type":"tool_use","name":"Grep","input":{"pattern":"freeze|frozen|first.?cash|firstCash|balanceFreeze","path":"/Users/ray/Documents/project/www/slot/slot_pwa","-i":true}},{"type":"tool_use","name":"Grep","input":{"pattern":"freeze|frozen|first.?cash|firstCash|balanceFreeze","path":"/Users/ray/Documents/project/www/slot/slot_agent_vue","-i":true}},{"type":"tool_use","name":"Grep","input":{"pattern":"freeze|frozen|first.?cash|firstCash|balanceFreeze","path":"/Users/ray/Documents/project/www/slot/slot_console","-i":true}},{"type":"tool_use","name":"Grep","input":{"pattern":"freeze|frozen|first.?cash|firstCash|balanceFreeze","path":"/Users/ray/Documents/project/www/slot/slot_sdk","-i":true}}]}}
{"role":"assistant","message":{"content":[{"type":"text","text":"[REDACTED]"},{"type":"tool_use","name":"Glob","input":{"glob_pattern":"**/*","target_directory":"/Users/ray/Documents/project/www/slot/slot_console"}},{"type":"tool_use","name":"Grep","input":{"pattern":"TYPE_FREE_CREDITS|freeCredits|free-credits|FreeCredits|首充前|定格","path":"/Users/ray/Documents/project/www/slot/slot_pwa"}},{"type":"tool_use","name":"Grep","input":{"pattern":"TYPE_FREE_CREDITS|freeCredits|free-credits|FreeCredits|首充前|定格","path":"/Users/ray/Documents/project/www/slot/slot_agent_vue"}},{"type":"tool_use","name":"Grep","input":{"pattern":"TYPE_FREE_CREDITS|freeCredits|free-credits|FreeCredits|首充前|定格","path":"/Users/ray/Documents/project/www/slot/slot_sdk"}},{"type":"tool_use","name":"Grep","input":{"pattern":"rechargeGift|recharge_gift|gift.*type.*11|giftType.*11","path":"/Users/ray/Documents/project/www/slot/slot_pwa","-i":true}},{"type":"tool_use","name":"Grep","input":{"pattern":"rechargeGift|recharge_gift|gift.*type.*11","path":"/Users/ray/Documents/project/www/slot/slot_agent_vue","-i":true}},{"type":"tool_use","name":"Grep","input":{"pattern":"rechargeGift|recharge_gift|gift.*type.*11","path":"/Users/ray/Documents/project/www/slot/slot_sdk","-i":true}},{"type":"tool_use","name":"Read","input":{"path":"/Users/ray/.cursor/plans/free_credits_release_902566c9.plan.md","limit":80}}]}}
{"role":"assistant","message":{"content":[{"type":"text","text":"[REDACTED]"},{"type":"tool_use","name":"Grep","input":{"pattern":"home_withdraw|homeWithdraw|package_id.*claim|/free","path":"/Users/ray/Documents/project/www/slot/slot_pwa","-i":true}},{"type":"tool_use","name":"Grep","input":{"pattern":"home_withdraw|homeWithdraw|free.credit|freeCredit","path":"/Users/ray/Documents/project/www/slot/slot_sdk","-i":true}},{"type":"tool_use","name":"Grep","input":{"pattern":"free.credit|freeCredit|home_withdraw|TYPE_FREE|gift.*11","path":"/Users/ray/Documents/project/www/slot/slot_agent_vue","-i":true}},{"type":"tool_use","name":"Grep","input":{"pattern":"freeCredits|FreeCredits|free_credits","path":"/Users/ray/Documents/project/www/slot/slot_console/config"}},{"type":"tool_use","name":"Read","input":{"path":"/Users/ray/Documents/project/www/slot/slot_console/config/route.php","limit":200}},{"type":"tool_use","name":"Grep","input":{"pattern":"freeCredits|free_credits|FreeCredits","path":"/Users/ray/Documents/project/www/slot/backend","-i":true,"glob":"*.{vue,ts,js,tsx,jsx}"}}]}}
{"role":"assistant","message":{"content":[{"type":"text","text":"[REDACTED]"},{"type":"tool_use","name":"Read","input":{"path":"/Users/ray/Documents/project/www/slot/slot_console/app/api/controller/FreeCreditsController.php"}},{"type":"tool_use","name":"Read","input":{"path":"/Users/ray/Documents/project/www/slot/slot_console/app/innerapi/controller/FreeCreditsController.php"}},{"type":"tool_use","name":"Grep","input":{"pattern":"free_credits|freeCredits","path":"/Users/ray/Documents/project/www/slot","glob":"*.{vue,ts,js,tsx,jsx,swift,kt}"}},{"type":"tool_use","name":"Glob","input":{"glob_pattern":"**/*.{vue,ts,tsx,js}","target_directory":"/Users/ray/Documents/project/www/slot/slot_pwa"}},{"type":"tool_use","name":"Glob","input":{"glob_pattern":"**/*.{vue,ts,tsx,js}","target_directory":"/Users/ray/Documents/project/www/slot/slot_sdk"}}]}}
{"role":"assistant","message":{"content":[{"type":"text","text":"[REDACTED]"},{"type":"tool_use","name":"Glob","input":{"glob_pattern":"**/*","target_directory":"/Users/ray/Documents/project/www/slot/slot_pwa"}},{"type":"tool_use","name":"Glob","input":{"glob_pattern":"**/*","target_directory":"/Users/ray/Documents/project/www/slot/slot_sdk"}},{"type":"tool_use","name":"Glob","input":{"glob_pattern":"**/*","target_directory":"/Users/ray/Documents/project/www/slot/slot_agent_vue"}}]}}
{"role":"assistant","message":{"content":[{"type":"text","text":"[REDACTED]"},{"type":"tool_use","name":"Grep","input":{"pattern":"freeCredits|free_credits|FreeCredits","path":"/Users/ray/Documents/project/www/slot/slot_sdk"}},{"type":"tool_use","name":"Grep","input":{"pattern":"freeCredits|free_credits|FreeCredits","path":"/Users/ray/Documents/project/www/slot/slot_wallet"}},{"type":"tool_use","name":"Grep","input":{"pattern":"freeCredits|free_credits|FreeCredits|TYPE_FREE_CREDITS|首充前","path":"/Users/ray/Documents/project/www/slot/backend"}},{"type":"tool_use","name":"Grep","input":{"pattern":"recharge.*gift|rechargeGift|gift.*config|activity.*type|giftType","path":"/Users/ray/Documents/project/www/slot/slot_agent_vue/src","-i":true,"head_limit":80}},{"type":"tool_use","name":"Grep","input":{"pattern":"featureFlag|feature_flag|ff_|toggle|开关","path":"/Users/ray/Documents/project/www/slot/slot_pwa","-i":true,"head_limit":40}},{"type":"tool_use","name":"Grep","input":{"pattern":"featureFlag|feature_flag|freeCredit|free_credit","path":"/Users/ray/Documents/project/www/slot/slot_agent_vue","-i":true}}]}}

View File

@@ -0,0 +1,23 @@
{"role":"user","message":{"content":[{"type":"text","text":"<user_query>\nSearch the slot monorepo for implementation related to \"首充前免费余额定格与分档释放\" / free credits freeze before first deposit / tiered release. Look in slot_wallet, slot_user, slot_pay, backend, slot-foundation, slot_lib, etc.\n\nFind:\n1. Key files, classes, services (e.g. FreeCredits, FrozenBalance, ReleaseTier, first deposit)\n2. API endpoints mentioned in requirements\n3. Database migrations/models\n4. What's implemented vs stub/TODO\n\nReturn a structured summary with file paths and brief description of each component found. Note any TODO/FIXME or missing pieces.\n</user_query>"}]}}
{"role":"assistant","message":{"content":[{"type":"text","text":"Searching the monorepo for free-credits freeze and tiered-release implementation.\n\n[REDACTED]"},{"type":"tool_use","name":"updateCurrentStep","input":{"current_step":"Searching free credits implementation"}},{"type":"tool_use","name":"Grep","input":{"pattern":"FreeCredits|FrozenBalance|ReleaseTier|free_credits|frozen_balance|release_tier","path":"/Users/ray/Documents/project/www/slot","-i":true,"head_limit":80}},{"type":"tool_use","name":"Grep","input":{"pattern":"首充|免费余额|定格|分档释放","path":"/Users/ray/Documents/project/www/slot","head_limit":80}},{"type":"tool_use","name":"Grep","input":{"pattern":"first.?deposit|first_deposit|FirstDeposit","path":"/Users/ray/Documents/project/www/slot","-i":true,"head_limit":80}}]}}
{"role":"assistant","message":{"content":[{"type":"text","text":"[REDACTED]"},{"type":"tool_use","name":"Glob","input":{"target_directory":"/Users/ray/Documents/project/www/slot","glob_pattern":"**/*FreeCredits*"}},{"type":"tool_use","name":"Grep","input":{"pattern":"free_credits|FreeCredits|freeCredits","path":"/Users/ray/Documents/project/www/slot","output_mode":"files_with_matches"}},{"type":"tool_use","name":"Grep","input":{"pattern":"TODO|FIXME|stub|未实现","path":"/Users/ray/Documents/project/www/slot/slot_console","glob":"**/*FreeCredits*"}},{"type":"tool_use","name":"Grep","input":{"pattern":"freeCredits|free_credits|FreeCredits","path":"/Users/ray/Documents/project/www/slot/docs/requirements/首充前免费余额定格与分档释放需求文档.md","head_limit":60}}]}}
{"role":"assistant","message":{"content":[{"type":"text","text":"[REDACTED]"},{"type":"tool_use","name":"Read","input":{"path":"/Users/ray/Documents/project/www/slot/slot_console/app/api/controller/FreeCreditsController.php"}},{"type":"tool_use","name":"Read","input":{"path":"/Users/ray/Documents/project/www/slot/slot_console/app/innerapi/controller/FreeCreditsController.php"}},{"type":"tool_use","name":"Grep","input":{"pattern":"FreeCredits|freeCredits|free_credits","path":"/Users/ray/Documents/project/www/slot/slot_console"}},{"type":"tool_use","name":"Grep","input":{"pattern":"/api/|innerapi|freeCredits|free-credits","path":"/Users/ray/Documents/project/www/slot/docs/requirements/首充前免费余额定格与分档释放需求文档.md","head_limit":40}}]}}
{"role":"assistant","message":{"content":[{"type":"text","text":"[REDACTED]"},{"type":"tool_use","name":"Grep","input":{"pattern":"FreeCredits|freeCredits|free_credits","path":"/Users/ray/Documents/project/www/slot/slot_console","glob":"**/*route*"}},{"type":"tool_use","name":"Grep","input":{"pattern":"FreeCredits|freeCredits","path":"/Users/ray/Documents/project/www/slot/slot_gateway"}},{"type":"tool_use","name":"Read","input":{"path":"/Users/ray/Documents/project/www/slot/slot_console/app/api/logic/FreeCreditsLogic.php"}},{"type":"tool_use","name":"Read","input":{"path":"/Users/ray/Documents/project/www/slot/slot_console/db/install.sql","offset":30,"limit":60}}]}}
{"role":"assistant","message":{"content":[{"type":"text","text":"[REDACTED]"},{"type":"tool_use","name":"Grep","input":{"pattern":"freeCredits|FreeCredits|free-credits|free_credits","path":"/Users/ray/Documents/project/www/slot","glob":"**/*.{php,ts,vue,js,yml,yaml,json}","head_limit":100}},{"type":"tool_use","name":"Read","input":{"path":"/Users/ray/Documents/project/www/slot/slot_console/app/model/common/FreeCreditsPlayerModel.php"}},{"type":"tool_use","name":"Read","input":{"path":"/Users/ray/Documents/project/www/slot/slot_console/app/model/common/FreeCreditsPackageModel.php"}},{"type":"tool_use","name":"Read","input":{"path":"/Users/ray/Documents/project/www/slot/slot_wallet/app/api/logic/WalletLogic.php","offset":550,"limit":130}}]}}
{"role":"assistant","message":{"content":[{"type":"text","text":"[REDACTED]"},{"type":"tool_use","name":"Grep","input":{"pattern":"FreeCredits|freeCredits","path":"/Users/ray/Documents/project/www/slot/slot_wallet"}},{"type":"tool_use","name":"Read","input":{"path":"/Users/ray/Documents/project/www/slot/slot_console/app/command/event/RechargeEvent.php","offset":70,"limit":50}},{"type":"tool_use","name":"Read","input":{"path":"/Users/ray/Documents/project/www/slot/slot_console/app/model/common/RechargeGiftConfigModel.php","offset":60,"limit":90}},{"type":"tool_use","name":"Read","input":{"path":"/Users/ray/Documents/project/www/slot/docs/requirements/首充前免费余额定格与分档释放需求文档.md","offset":700,"limit":120}},{"type":"tool_use","name":"Read","input":{"path":"/Users/ray/.cursor/plans/free_credits_release_902566c9.plan.md","limit":100}}]}}
{"role":"assistant","message":{"content":[{"type":"text","text":"[REDACTED]"},{"type":"tool_use","name":"Grep","input":{"pattern":"接口|/api/|GET |POST |innerapi","path":"/Users/ray/Documents/project/www/slot/docs/requirements/首充前免费余额定格与分档释放需求文档.md","head_limit":50}},{"type":"tool_use","name":"Read","input":{"path":"/Users/ray/.cursor/plans/free_credits_release_902566c9.plan.md","offset":100,"limit":85}},{"type":"tool_use","name":"Grep","input":{"pattern":"freeCreditsFreeze|freeCreditsClaim|WALLET_TYPE_FREE_CREDITS","path":"/Users/ray/Documents/project/www/slot"}},{"type":"tool_use","name":"Grep","input":{"pattern":"TYPE_FREE_CREDITS|free_credits|FreeCredits","path":"/Users/ray/Documents/project/www/slot/backend"}}]}}
{"role":"assistant","message":{"content":[{"type":"text","text":"[REDACTED]"},{"type":"tool_use","name":"Grep","input":{"pattern":"freeCreditsFreeze|freeCreditsClaim|FREE_CREDITS","path":"/Users/ray/Documents/project/www/slot/slot_wallet","glob":"**/*"}},{"type":"tool_use","name":"Read","input":{"path":"/Users/ray/Documents/project/www/slot/slot_console/app/command/EventBus.php","offset":115,"limit":40}},{"type":"tool_use","name":"Read","input":{"path":"/Users/ray/Documents/project/www/slot/slot_lib/src/services/WalletService.php","offset":1,"limit":200}},{"type":"tool_use","name":"Grep","input":{"pattern":"free_credits|FreeCredits|TYPE_FREE_CREDITS","path":"/Users/ray/Documents/project/www/slot/slot_console","glob":"**/*.{php,sql}"}}]}}
{"role":"assistant","message":{"content":[{"type":"text","text":"[REDACTED]"},{"type":"tool_use","name":"Grep","input":{"pattern":"freeCreditsFreeze|freeCreditsClaim","path":"/Users/ray/Documents/project/www/slot/slot_wallet/app"}},{"type":"tool_use","name":"Grep","input":{"pattern":"FreeCredits|free-credits|freeCredits","path":"/Users/ray/Documents/project/www/slot/slot_console/config"}},{"type":"tool_use","name":"Glob","input":{"target_directory":"/Users/ray/Documents/project/www/slot/slot_console","glob_pattern":"**/route*.php"}},{"type":"tool_use","name":"Read","input":{"path":"/Users/ray/Documents/project/www/slot/slot_pay/app/entity/WithdrawalOrderEntity.php","offset":55,"limit":100}},{"type":"tool_use","name":"Read","input":{"path":"/Users/ray/Documents/project/www/slot/slot_console/app/api/validator/FreeCreditsValidator.php"}}]}}
{"role":"assistant","message":{"content":[{"type":"text","text":"[REDACTED]"},{"type":"tool_use","name":"Read","input":{"path":"/Users/ray/Documents/project/www/slot/slot_console/config/route.php","limit":80}},{"type":"tool_use","name":"Grep","input":{"pattern":"freeCredits|FreeCredits","path":"/Users/ray/Documents/project/www/slot/slot_wallet/app/api"}},{"type":"tool_use","name":"Grep","input":{"pattern":"case.*freeCredits|freeCreditsFreeze","path":"/Users/ray/Documents/project/www/slot/slot_wallet"}},{"type":"tool_use","name":"Read","input":{"path":"/Users/ray/Documents/project/www/slot/slot_console/app/napi/controller/LobbyController.php","offset":55,"limit":40}}]}}
{"role":"assistant","message":{"content":[{"type":"text","text":"[REDACTED]"},{"type":"tool_use","name":"Grep","input":{"pattern":"freeCreditsFreeze|WALLET_TYPE_FREE_CREDITS|BIZ_TYPE_FREE_CREDITS","path":"/Users/ray/Documents/project/www/slot/slot_wallet"}},{"type":"tool_use","name":"Glob","input":{"target_directory":"/Users/ray/Documents/project/www/slot/slot_wallet","glob_pattern":"**/WalletController.php"}},{"type":"tool_use","name":"Grep","input":{"pattern":"innerapi.*FreeCredits|FreeCredits.*statistics","path":"/Users/ray/Documents/project/www/slot"}},{"type":"tool_use","name":"Grep","input":{"pattern":"TODO|FIXME","path":"/Users/ray/Documents/project/www/slot/slot_console/app/api/logic/FreeCreditsLogic.php"}}]}}
{"role":"assistant","message":{"content":[{"type":"text","text":"[REDACTED]"},{"type":"tool_use","name":"Grep","input":{"pattern":"freeCredits|switch.*type|update\\(","path":"/Users/ray/Documents/project/www/slot/slot_wallet/app/api/controller/WalletController.php"}},{"type":"tool_use","name":"Read","input":{"path":"/Users/ray/Documents/project/www/slot/slot_wallet/app/api/controller/WalletController.php","limit":120}},{"type":"tool_use","name":"Grep","input":{"pattern":"free-credits|FreeCredits|free_credits","path":"/Users/ray/Documents/project/www/slot/slot_gateway"}},{"type":"tool_use","name":"Grep","input":{"pattern":"free-credits|FreeCredits|free_credits","path":"/Users/ray/Documents/project/www/slot/slot_pwa"}}]}}
{"role":"assistant","message":{"content":[{"type":"text","text":"[REDACTED]"},{"type":"tool_use","name":"Grep","input":{"pattern":"freeCredits|FREE_CREDITS","path":"/Users/ray/Documents/project/www/slot/slot_wallet/app/api/logic"}},{"type":"tool_use","name":"Read","input":{"path":"/Users/ray/Documents/project/www/slot/slot_wallet/app/api/logic/WalletLogic.php","limit":120}},{"type":"tool_use","name":"Grep","input":{"pattern":"recharge_gift|TYPE_FREE_CREDITS|ext_config","path":"/Users/ray/Documents/project/www/slot/backend"}}]}}
{"role":"assistant","message":{"content":[{"type":"text","text":"[REDACTED]"},{"type":"tool_use","name":"Grep","input":{"pattern":"TYPE_FREE_CREDITS|type.*11|free.?credit|win_threshold","path":"/Users/ray/Documents/project/www/slot/backend/slot_admin","-i":true}},{"type":"tool_use","name":"Grep","input":{"pattern":"FreeCredits|free_credits","path":"/Users/ray/Documents/project/www/slot","glob":"**/*test*"}},{"type":"tool_use","name":"Grep","input":{"pattern":"SOURCE_TYPE_FREE","path":"/Users/ray/Documents/project/www/slot/slot_wallet"}},{"type":"tool_use","name":"Read","input":{"path":"/Users/ray/Documents/project/www/slot/slot_pay/app/command/EventWithdrawal.php","offset":100,"limit":40}}]}}
{"role":"assistant","message":{"content":[{"type":"text","text":"[REDACTED]"},{"type":"tool_use","name":"Grep","input":{"pattern":"freeCredits|FreeCredits|free_credit","path":"/Users/ray/Documents/project/www/slot/slot-foundation"}},{"type":"tool_use","name":"Grep","input":{"pattern":"handleRecharge|recharge.*Event|RechargeEvent","path":"/Users/ray/Documents/project/www/slot/slot_pay"}},{"type":"tool_use","name":"Read","input":{"path":"/Users/ray/Documents/project/www/slot/docs/requirements/首充前免费余额定格与分档释放需求文档.md","offset":820,"limit":100}},{"type":"tool_use","name":"Grep","input":{"pattern":"activity.*type|活动类型","path":"/Users/ray/Documents/project/www/slot/backend/slot_admin_vue/src/views/game/activity"}}]}}
{"role":"assistant","message":{"content":[{"type":"text","text":"[REDACTED]"},{"type":"tool_use","name":"Grep","input":{"pattern":"activity_type|TYPE_FREE|11","path":"/Users/ray/Documents/project/www/slot/backend/slot_admin","glob":"**/*dict*"}},{"type":"tool_use","name":"Grep","input":{"pattern":"FreeCreditsController|/api/free","path":"/Users/ray/Documents/project/www/slot"}},{"type":"tool_use","name":"Read","input":{"path":"/Users/ray/Documents/project/www/slot/slot_console/app/command/event/RechargeEvent.php","limit":50}},{"type":"tool_use","name":"Grep","input":{"pattern":"recharge|Recharge","path":"/Users/ray/Documents/project/www/slot/slot_console/app/command/EventBus.php"}}]}}
{"role":"assistant","message":{"content":[{"type":"text","text":"[REDACTED]"},{"type":"tool_use","name":"Grep","input":{"pattern":"broadcast|广播|freeCreditsClaim","path":"/Users/ray/Documents/project/www/slot/slot_console"}},{"type":"tool_use","name":"Grep","input":{"pattern":"function createTask","path":"/Users/ray/Documents/project/www/slot/slot_wallet/app/api/logic/WalletLogic.php","-A":25}},{"type":"tool_use","name":"Grep","input":{"pattern":"innerapi/free|FreeCredits","path":"/Users/ray/Documents/project/www/slot/backend"}},{"type":"tool_use","name":"Read","input":{"path":"/Users/ray/Documents/project/www/slot/slot_console/app/model/common/RechargeGiftConfigModel.php","limit":60}}]}}
{"role":"assistant","message":{"content":[{"type":"text","text":"[REDACTED]"},{"type":"tool_use","name":"Grep","input":{"pattern":"biz_id|bizId","path":"/Users/ray/Documents/project/www/slot/slot_wallet/app/api/logic/WalletLogic.php","head_limit":20}},{"type":"tool_use","name":"Glob","input":{"target_directory":"/Users/ray/Documents/project/www/slot/slot_console","glob_pattern":"**/config/*.php"}},{"type":"tool_use","name":"Grep","input":{"pattern":"default_route|Route::|controller_suffix","path":"/Users/ray/Documents/project/www/slot/slot_console/config"}}]}}
{"role":"assistant","message":{"content":[{"type":"text","text":"[REDACTED]"},{"type":"tool_use","name":"Read","input":{"path":"/Users/ray/Documents/project/www/slot/slot_console/config/app.php"}},{"type":"tool_use","name":"Grep","input":{"pattern":"class.*Controller","path":"/Users/ray/Documents/project/www/slot/slot_console/app/api/controller","head_limit":5}},{"type":"tool_use","name":"Read","input":{"path":"/Users/ray/Documents/project/www/slot/docs/requirements/首充前免费余额定格与分档释放需求文档.md","offset":1040,"limit":80}}]}}
{"role":"assistant","message":{"content":[{"type":"text","text":"[REDACTED]"},{"type":"tool_use","name":"Read","input":{"path":"/Users/ray/Documents/project/www/slot/slot_console/app/napi/controller/LobbyController.php","limit":55}},{"type":"tool_use","name":"Grep","input":{"pattern":"free_credit|freeCredit|FREE_CREDIT","path":"/Users/ray/Documents/project/www/slot/slot_pay"}}]}}
{"role":"assistant","message":{"content":[{"type":"text","text":"[REDACTED]"},{"type":"tool_use","name":"Grep","input":{"pattern":"free_credits","path":"/Users/ray/Documents/project/www/slot","glob":"**/*.sql"}},{"type":"tool_use","name":"Grep","input":{"pattern":"TODO|FIXME|stub","path":"/Users/ray/Documents/project/www/slot/slot_console/app","glob":"**/*FreeCredits*"}}]}}
{"role":"assistant","message":{"content":[{"type":"text","text":"[REDACTED]"},{"type":"tool_use","name":"updateCurrentStep","input":{"current_step":"Summarizing search findings","final_summary":"The feature is implemented mainly in **slot_console** (domain logic, DB, client/admin inner APIs) with wallet freeze/claim in **slot_wallet** and first-cashout wiring in **slot_pay**. **slot_user**, **slot_foundation**, **backend admin UI**, client repos, and broadcast/stats UI appear missing or incomplete relative to the requirements doc.","completed_subtitle":"Mapped free credits implementation"}}]}}

View File

@@ -0,0 +1,14 @@
{"role":"user","message":{"content":[{"type":"text","text":"<user_query>\nSearch the slot monorepo for implementation related to \"首充前免费余额定格与分档释放\" / free credits freeze before first deposit / tiered release. Look in slot_wallet, slot_user, slot_pay, backend, slot-foundation, slot_lib, etc.\n\nFind:\n1. Key files, classes, services (e.g. FreeCredits, FrozenBalance, ReleaseTier, first deposit)\n2. API endpoints mentioned in requirements\n3. Database migrations/models\n4. What's implemented vs stub/TODO\n\nReturn a structured summary with file paths and brief description of each component found. Note any TODO/FIXME or missing pieces.\n</user_query>"}]}}
{"role":"assistant","message":{"content":[{"type":"text","text":"Searching the monorepo for free-credits freeze and tiered-release implementation across wallet, user, pay, and related services.\n\n[REDACTED]"},{"type":"tool_use","name":"updateCurrentStep","input":{"current_step":"Searching free credits implementation"}},{"type":"tool_use","name":"Grep","input":{"pattern":"FreeCredits|FrozenBalance|ReleaseTier|free_credits|frozen_balance|release_tier","path":"/Users/ray/Documents/project/www/slot","-i":true}},{"type":"tool_use","name":"Grep","input":{"pattern":"首充|免费余额|定格|分档释放|free.*credit|tiered.*release","path":"/Users/ray/Documents/project/www/slot","-i":true}},{"type":"tool_use","name":"Grep","input":{"pattern":"first.?deposit|firstDeposit|FirstDeposit","path":"/Users/ray/Documents/project/www/slot","-i":true}}]}}
{"role":"assistant","message":{"content":[{"type":"text","text":"[REDACTED]"},{"type":"tool_use","name":"Grep","input":{"pattern":"freeCredits|free_credits|FreeCredits","path":"/Users/ray/Documents/project/www/slot","glob":"**/route*"}},{"type":"tool_use","name":"Grep","input":{"pattern":"TODO|FIXME|stub|未实现","path":"/Users/ray/Documents/project/www/slot/slot_console","glob":"**/*FreeCredits*"}},{"type":"tool_use","name":"Grep","input":{"pattern":"freeCredits|free_credits","path":"/Users/ray/Documents/project/www/slot/docs/requirements/首充前免费余额定格与分档释放需求文档.md"}},{"type":"tool_use","name":"Glob","input":{"glob_pattern":"**/*FreeCredits*","target_directory":"/Users/ray/Documents/project/www/slot"}}]}}
{"role":"assistant","message":{"content":[{"type":"text","text":"[REDACTED]"},{"type":"tool_use","name":"Grep","input":{"pattern":"FreeCredits|free_credits","path":"/Users/ray/Documents/project/www/slot/slot_console"}},{"type":"tool_use","name":"Grep","input":{"pattern":"freeCreditsFreeze|freeCreditsClaim","path":"/Users/ray/Documents/project/www/slot"}},{"type":"tool_use","name":"Read","input":{"path":"/Users/ray/Documents/project/www/slot/docs/requirements/首充前免费余额定格与分档释放需求文档.md","offset":600,"limit":200}},{"type":"tool_use","name":"Read","input":{"path":"/Users/ray/.cursor/plans/free_credits_release_902566c9.plan.md"}}]}}
{"role":"assistant","message":{"content":[{"type":"text","text":"[REDACTED]"},{"type":"tool_use","name":"Grep","input":{"pattern":"free.?credit|FreeCredit","path":"/Users/ray/Documents/project/www/slot/docs/requirements/首充前免费余额定格与分档释放需求文档.md","-i":true}},{"type":"tool_use","name":"Glob","input":{"glob_pattern":"**/route*.php","target_directory":"/Users/ray/Documents/project/www/slot/slot_console"}},{"type":"tool_use","name":"Read","input":{"path":"/Users/ray/Documents/project/www/slot/slot_console/app/api/controller/FreeCreditsController.php"}},{"type":"tool_use","name":"Read","input":{"path":"/Users/ray/Documents/project/www/slot/slot_console/app/api/logic/FreeCreditsLogic.php"}}]}}
{"role":"assistant","message":{"content":[{"type":"text","text":"[REDACTED]"},{"type":"tool_use","name":"Read","input":{"path":"/Users/ray/Documents/project/www/slot/slot_console/config/route.php"}},{"type":"tool_use","name":"Read","input":{"path":"/Users/ray/Documents/project/www/slot/slot_console/app/model/common/FreeCreditsPlayerModel.php"}},{"type":"tool_use","name":"Read","input":{"path":"/Users/ray/Documents/project/www/slot/slot_console/app/model/common/FreeCreditsPackageModel.php"}},{"type":"tool_use","name":"Read","input":{"path":"/Users/ray/Documents/project/www/slot/slot_console/db/install.sql","offset":30,"limit":60}},{"type":"tool_use","name":"Read","input":{"path":"/Users/ray/Documents/project/www/slot/slot_wallet/app/api/logic/WalletLogic.php","offset":550,"limit":130}}]}}
{"role":"assistant","message":{"content":[{"type":"text","text":"[REDACTED]"},{"type":"tool_use","name":"Grep","input":{"pattern":"FreeCredits|freeCredits|free_credits","path":"/Users/ray/Documents/project/www/slot/slot_gateway"}},{"type":"tool_use","name":"Grep","input":{"pattern":"FreeCredits|freeCredits|free_credits","path":"/Users/ray/Documents/project/www/slot/backend"}},{"type":"tool_use","name":"Read","input":{"path":"/Users/ray/Documents/project/www/slot/slot_console/app/command/event/RechargeEvent.php","offset":70,"limit":50}},{"type":"tool_use","name":"Read","input":{"path":"/Users/ray/Documents/project/www/slot/docs/requirements/首充前免费余额定格与分档释放需求文档.md","offset":880,"limit":120}},{"type":"tool_use","name":"Read","input":{"path":"/Users/ray/Documents/project/www/slot/slot_console/app/model/common/RechargeGiftConfigModel.php","offset":60,"limit":90}}]}}
{"role":"assistant","message":{"content":[{"type":"text","text":"[REDACTED]"},{"type":"tool_use","name":"Grep","input":{"pattern":"freeCredits|FreeCredits","path":"/Users/ray/Documents/project/www/slot/slot_wallet"}},{"type":"tool_use","name":"Grep","input":{"pattern":"freeCredits|FreeCredits","path":"/Users/ray/Documents/project/www/slot/slot_lib"}},{"type":"tool_use","name":"Read","input":{"path":"/Users/ray/Documents/project/www/slot/slot_lib/src/services/WalletService.php","offset":1,"limit":200}},{"type":"tool_use","name":"Read","input":{"path":"/Users/ray/Documents/project/www/slot/slot_console/app/innerapi/controller/FreeCreditsController.php"}},{"type":"tool_use","name":"Read","input":{"path":"/Users/ray/Documents/project/www/slot/slot_pay/app/entity/WithdrawalOrderEntity.php","offset":55,"limit":90}}]}}
{"role":"assistant","message":{"content":[{"type":"text","text":"[REDACTED]"},{"type":"tool_use","name":"Grep","input":{"pattern":"freeCreditsFreeze|freeCreditsClaim|FreeCredits","path":"/Users/ray/Documents/project/www/slot/slot_wallet","glob":"**/*"}},{"type":"tool_use","name":"Grep","input":{"pattern":"home_withdraw|syncHomeWithdraw|free_credits","path":"/Users/ray/Documents/project/www/slot"}},{"type":"tool_use","name":"Grep","input":{"pattern":"TYPE_FREE_CREDITS|free.?credit","path":"/Users/ray/Documents/project/www/slot/backend","-i":true}},{"type":"tool_use","name":"Read","input":{"path":"/Users/ray/Documents/project/www/slot/slot_console/app/command/EventBus.php","offset":115,"limit":40}},{"type":"tool_use","name":"Read","input":{"path":"/Users/ray/Documents/project/www/slot/slot_console/app/napi/controller/LobbyController.php","offset":60,"limit":35}}]}}
{"role":"assistant","message":{"content":[{"type":"text","text":"[REDACTED]"},{"type":"tool_use","name":"Grep","input":{"pattern":"freeCreditsFreeze|freeCreditsClaim|FREE_CREDITS","path":"/Users/ray/Documents/project/www/slot/slot_wallet/app"}},{"type":"tool_use","name":"Grep","input":{"pattern":"FreeCredits|free-credits|free_credits","path":"/Users/ray/Documents/project/www/slot/docs/requirements/首充前免费余额定格与分档释放需求文档.md","glob":"*"}},{"type":"tool_use","name":"Read","input":{"path":"/Users/ray/Documents/project/www/slot/docs/requirements/首充前免费余额定格与分档释放需求文档.md","offset":1000,"limit":120}},{"type":"tool_use","name":"Grep","input":{"pattern":"TODO|FIXME|@todo","path":"/Users/ray/Documents/project/www/slot/slot_console/app/api/logic/FreeCreditsLogic.php"}},{"type":"tool_use","name":"Grep","input":{"pattern":"TODO|FIXME","path":"/Users/ray/Documents/project/www/slot/slot_wallet/app/api/logic/WalletLogic.php"}}]}}
{"role":"assistant","message":{"content":[{"type":"text","text":"[REDACTED]"},{"type":"tool_use","name":"Grep","input":{"pattern":"freeCreditsFreeze|freeCreditsClaim","path":"/Users/ray/Documents/project/www/slot/slot_wallet"}},{"type":"tool_use","name":"Grep","input":{"pattern":"FreeCreditsController|free-credits|freeCredits","path":"/Users/ray/Documents/project/www/slot/slot_console"}},{"type":"tool_use","name":"Grep","input":{"pattern":"/api/|innerapi","path":"/Users/ray/Documents/project/www/slot/docs/requirements/首充前免费余额定格与分档释放需求文档.md"}},{"type":"tool_use","name":"Read","input":{"path":"/Users/ray/Documents/project/www/slot/slot_console/app/api/validator/FreeCreditsValidator.php"}},{"type":"tool_use","name":"Grep","input":{"pattern":"SOURCE_TYPE_FREE|freeCredits","path":"/Users/ray/Documents/project/www/slot/slot_wallet"}}]}}
{"role":"assistant","message":{"content":[{"type":"text","text":"[REDACTED]"},{"type":"tool_use","name":"Grep","input":{"pattern":"freeCredits|WALLET_TYPE_FREE","path":"/Users/ray/Documents/project/www/slot/slot_wallet/app/api"}},{"type":"tool_use","name":"Glob","input":{"target_directory":"/Users/ray/Documents/project/www/slot/slot_wallet","glob_pattern":"**/*Controller*"}},{"type":"tool_use","name":"Grep","input":{"pattern":"RechargeEvent|recharge.*Event","path":"/Users/ray/Documents/project/www/slot/slot_pay"}}]}}
{"role":"assistant","message":{"content":[{"type":"text","text":"[REDACTED]"},{"type":"tool_use","name":"Grep","input":{"pattern":"freeCredits|case.*type|update","path":"/Users/ray/Documents/project/www/slot/slot_wallet/app/api/controller/WalletController.php"}},{"type":"tool_use","name":"Grep","input":{"pattern":"recharge|Recharge","path":"/Users/ray/Documents/project/www/slot/slot_console/app/command/event"}},{"type":"tool_use","name":"Grep","input":{"pattern":"free_credit|FreeCredits","path":"/Users/ray/Documents/project/www/slot/slot_pwa"}},{"type":"tool_use","name":"Grep","input":{"pattern":"TYPE_FREE_CREDITS|free_credits|freeCredits","path":"/Users/ray/Documents/project/www/slot/slot-foundation"}}]}}
{"role":"assistant","message":{"content":[{"type":"text","text":"[REDACTED]"},{"type":"tool_use","name":"Read","input":{"path":"/Users/ray/Documents/project/www/slot/slot_wallet/app/api/controller/WalletController.php","offset":25,"limit":80}},{"type":"tool_use","name":"Grep","input":{"pattern":"freeCredits|FreeCredits|TYPE_FREE_CREDITS","path":"/Users/ray/Documents/project/www/slot/slot_console","glob":"**/*.md"}},{"type":"tool_use","name":"Grep","input":{"pattern":"freeCredits|free_credits|FreeCredits","path":"/Users/ray/Documents/project/www/slot/slot_pwa"}},{"type":"tool_use","name":"Grep","input":{"pattern":"freeCredits|free_credits|FreeCredits|TYPE_FREE_CREDITS","path":"/Users/ray/Documents/project/www/slot/backend/slot_admin"}}]}}

View File

@@ -0,0 +1,4 @@
{"role":"user","message":{"content":[{"type":"text","text":"<user_query>\nSearch slot_pwa, slot_agent_vue, slot_console, slot_sdk for UI/API related to free credits freeze, tiered release, first deposit balance freeze. Find pages, API calls, feature flags.\n\nReturn file paths and whether UI appears complete or partial.\n</user_query>"}]}}
{"role":"assistant","message":{"content":[{"type":"text","text":"Searching the four frontend projects for free-credits freeze, tiered release, and first-deposit balance UI/API.\n\n[REDACTED]"},{"type":"tool_use","name":"updateCurrentStep","input":{"current_step":"Searching frontend projects"}},{"type":"tool_use","name":"Grep","input":{"pattern":"free.?credit|freeCredit|free_credit","path":"/Users/ray/Documents/project/www/slot/slot_pwa","-i":true}},{"type":"tool_use","name":"Grep","input":{"pattern":"free.?credit|freeCredit|free_credit","path":"/Users/ray/Documents/project/www/slot/slot_agent_vue","-i":true}},{"type":"tool_use","name":"Grep","input":{"pattern":"free.?credit|freeCredit|free_credit","path":"/Users/ray/Documents/project/www/slot/slot_console","-i":true}},{"type":"tool_use","name":"Grep","input":{"pattern":"free.?credit|freeCredit|free_credit","path":"/Users/ray/Documents/project/www/slot/slot_sdk","-i":true}},{"type":"tool_use","name":"Grep","input":{"pattern":"tiered.?release|tierRelease|tier_release|分档释放","path":"/Users/ray/Documents/project/www/slot","glob":"**/{slot_pwa,slot_agent_vue,slot_console,slot_sdk}/**","-i":true}},{"type":"tool_use","name":"Grep","input":{"pattern":"balance.?freeze|freeze.*balance|frozen|定格|首充","path":"/Users/ray/Documents/project/www/slot","glob":"**/{slot_pwa,slot_agent_vue,slot_console,slot_sdk}/**","-i":true}}]}}
{"role":"assistant","message":{"content":[{"type":"text","text":"Broadening search with alternate terms and scanning frontend source trees.\n\n[REDACTED]"},{"type":"tool_use","name":"Grep","input":{"pattern":"freeCredits|FreeCredits|free_credits|TYPE_FREE_CREDITS","path":"/Users/ray/Documents/project/www/slot/slot_pwa","glob":"**/*.{vue,ts,js,tsx,jsx,php}"}},{"type":"tool_use","name":"Grep","input":{"pattern":"freeCredits|FreeCredits|free_credits|TYPE_FREE_CREDITS","path":"/Users/ray/Documents/project/www/slot/slot_agent_vue","glob":"**/*.{vue,ts,js,tsx,jsx}"}},{"type":"tool_use","name":"Grep","input":{"pattern":"freeCredits|FreeCredits|free_credits|TYPE_FREE_CREDITS","path":"/Users/ray/Documents/project/www/slot/slot_console","glob":"**/*.{vue,ts,js,tsx,jsx,php}"}},{"type":"tool_use","name":"Grep","input":{"pattern":"freeCredits|FreeCredits|free_credits|TYPE_FREE_CREDITS","path":"/Users/ray/Documents/project/www/slot/slot_sdk","glob":"**/*.{vue,ts,js,tsx,jsx,php}"}},{"type":"tool_use","name":"Grep","input":{"pattern":"frozen_amount|home_withdraw|first_cash|release.*package|claim.*release","path":"/Users/ray/Documents/project/www/slot","glob":"**/{slot_pwa,slot_agent_vue,slot_console,slot_sdk}/**/*.{vue,ts,js,tsx,jsx}","-i":true}},{"type":"tool_use","name":"Grep","input":{"pattern":"免费|定格|分档|释放","path":"/Users/ray/Documents/project/www/slot","glob":"**/{slot_pwa,slot_agent_vue,slot_console,slot_sdk}/**/*.{vue,ts,js,tsx,jsx}"}}]}}
{"role":"assistant","message":{"content":[{"type":"text","text":"[REDACTED]"},{"type":"tool_use","name":"Glob","input":{"glob_pattern":"**/*","target_directory":"/Users/ray/Documents/project/www/slot/slot_pwa"}},{"type":"tool_use","name":"Glob","input":{"glob_pattern":"**/*.{vue,tsx,jsx}","target_directory":"/Users/ray/Documents/project/www/slot/slot_console"}},{"type":"tool_use","name":"Grep","input":{"pattern":"free-credits|freeCredits|/free_credits|FreeCredits","path":"/Users/ray/Documents/project/www/slot","glob":"**/*.{vue,ts,js,tsx,jsx,json}"}},{"type":"tool_use","name":"Read","input":{"path":"/Users/ray/.cursor/plans/free_credits_release_902566c9.plan.md","limit":80}},{"type":"tool_use","name":"Grep","input":{"pattern":"freeCreditsFreeze|freeCreditsClaim|BONUS_FROZEN|bonusFrozen","path":"/Users/ray/Documents/project/www/slot","glob":"**/{slot_pwa,slot_agent_vue,slot_console,slot_sdk}/**"}}]}}

View File

@@ -0,0 +1,3 @@
{"role":"user","message":{"content":[{"type":"text","text":"<user_query>\nmarkdown 怎么引入外部文件\n</user_query>"}]}}
{"role":"assistant","message":{"content":[{"type":"text","text":"Markdown 本身没有标准的「引入外部文件」语法;是否支持取决于你用的渲染器或文档工具。正在查看你们项目文档是否配置了 include 能力。\n\n[REDACTED]"},{"type":"tool_use","name":"Grep","input":{"pattern":"include|import|embed","path":"/Users/ray/Documents/project/www/slot/docs","glob":"*.{md,yml,yaml,json}","head_limit":30}},{"type":"tool_use","name":"Glob","input":{"glob_pattern":"**/mkdocs*.{yml,yaml}","target_directory":"/Users/ray/Documents/project/www/slot"}}]}}
{"role":"assistant","message":{"content":[{"type":"text","text":"## 结论\n\n**标准 Markdown 没有**「`#include` / `import`」这类官方语法。能否引入外部文件,完全取决于你用的平台或构建工具。\n\n---\n\n## 常见做法\n\n### 1. 纯链接(通用)\n\n在任意 Markdown 里只能**引用**,不能真正把另一份文件的内容嵌进来:\n\n```markdown\n详见 [钱包规则](./钱包规则.md)\n```\n\n或相对路径\n\n```markdown\n[钱包规则](../钱包规则.md)\n```\n\n---\n\n### 2. 按工具/平台\n\n| 场景 | 写法示例 |\n|------|----------|\n| **GitHub / 普通 .md** | 不支持 include只能链接 |\n| **Obsidian** | `![[钱包规则.md]]`(嵌入显示) |\n| **MkDocs + Material** | `{% include-markdown \"path/to/file.md\" %}`(需插件) |\n| **VuePress / VitePress** | 部分主题支持 `<<< @/path/file.md` 或自定义组件 |\n| **Pandoc** | `\\input{other.md}` 或合并时 `--file-scope` |\n| **MDX**React 文档站) | `import Content from './other.mdx'` |\n| **Notion / 语雀** | 用产品自带的「同步块 / 引用文档」 |\n\n你们 `docs/requirements/` 里目前是普通 `.md`,若没有 MkDocs、VitePress 等构建配置,**只能用手写链接**,不能自动把 `钱包规则.md` 的内容展开进 `首充前免费余额...md`。\n\n---\n\n### 3. 构建时合并(适合需求文档仓库)\n\n用脚本在生成/发布前合并:\n\n```bash\n# 示例:把外部文件内容插入占位符\nsed '/<!-- include: 钱包规则.md -->/r 钱包规则.md' 主文档.md\n```\n\n或在 CI 里用 `pandoc` 合并多个 md 再输出 PDF/HTML。\n\n---\n\n### 4. 代码块「引用」文件(仅展示,不真 include\n\nGitHub 等支持在 fenced code 里写路径(仍是展示,不是动态 include\n\n````markdown\n```1:10:docs/requirements/钱包规则.md\n这里通常要手写或工具生成GitHub 不会自动读文件)\n```\n````\n\nCursor / IDE 里的这种 `startLine:endLine:path` 格式是**编辑器约定**,不是 Markdown 标准。\n\n---\n\n## 针对你当前需求文档的建议\n\n若想在 `首充前免费余额定格与分档释放需求文档.md` 里复用 `钱包规则.md`\n\n1. **最简单**:写一节「参见 [钱包规则](./钱包规则.md)」,不重复粘贴。\n2. **必须同页展示**:短期可复制关键段落;长期考虑 MkDocs/VitePress + include 插件,或发布前用脚本合并。\n3. **避免**:在 GitHub 上指望 `{% include %}` 或 `![[...]]`——默认不会生效。\n\n如果你说一下文档是只在 GitHub 看、还是 Obsidian / 语雀 / 自建站点,可以给你对应环境的一条具体写法。\n\n[REDACTED]"}]}}

View File

@@ -0,0 +1,5 @@
{"role":"user","message":{"content":[{"type":"text","text":"<timestamp>Monday, May 18, 2026, 5:08 PM (UTC+8)</timestamp>\n<user_query>\n看一下我钱包规则需求文档看是否合格美国RMG真钱SLOTS聚合游戏平台市场\n</user_query>"}]}}
{"role":"assistant","message":{"content":[{"type":"text","text":"我先把钱包规则文档和当前需求文档中与钱包/首充/免费余额相关的段落读一遍,再按美国真钱 iGaming/RMG slots 平台常见合规维度做差距评审。\n\n**Researching user requirements**\n\nIm thinking of starting with a user update and using ReadFile. I could also look into current US iGaming regulations surrounding responsible gaming, AML, geolocation, and KYC through a web search. Maybe I should consider asking specific questions? The user is looking for a review rather than a plan, so it seems like I just need to provide a comprehensive answer. Ill also check if using parallel explore subagents might speed up my initial research.\n**Evaluating canvas limitations**\n\nIm thinking that using a canvas would lead to creating a live React app and editing the file, but in plan mode, I can only edit markdown, which isn't compatible. I realize that the user may not need this functionality right now. I should probably read the documentation to clarify. Also, I might consider using parallel ReadFile to gather information on wallet rules and the relevant section of requirements around line 931."},{"type":"tool_use","name":"ReadFile","input":{"path":"/Users/ray/Documents/project/www/slot/docs/requirements/钱包规则.md"}},{"type":"tool_use","name":"ReadFile","input":{"path":"/Users/ray/Documents/project/www/slot/docs/requirements/首充前免费余额定格与分档释放需求文档.md","offset":850,"limit":260}}]}}
{"role":"assistant","message":{"content":[{"type":"text","text":"我看到 `钱包规则.md` 目前只有最基础的“充值金额 + 赢取金额”和“有未完成打码则不可提现”规则;还需要结合首充前免费余额文档的前置流程判断是否覆盖真钱市场必需的账户、奖金、提现、风控和合规边界。"},{"type":"tool_use","name":"ReadFile","input":{"path":"/Users/ray/Documents/project/www/slot/docs/requirements/首充前免费余额定格与分档释放需求文档.md","offset":1,"limit":260}},{"type":"tool_use","name":"ReadFile","input":{"path":"/Users/ray/Documents/project/www/slot/docs/requirements/首充前免费余额定格与分档释放需求文档.md","offset":260,"limit":300}},{"type":"tool_use","name":"ReadFile","input":{"path":"/Users/ray/Documents/project/www/slot/docs/requirements/首充前免费余额定格与分档释放需求文档.md","offset":560,"limit":300}},{"type":"tool_use","name":"ReadFile","input":{"path":"/Users/ray/Documents/project/www/slot/docs/requirements/首充前免费余额定格与分档释放需求文档.md","offset":1100,"limit":240}}]}}
{"role":"assistant","message":{"content":[{"type":"text","text":"从已读内容看,主文档把“首充前免费余额定格与分档释放”讲得比较完整,但 `钱包规则.md` 本身远不足以作为美国真钱钱包规则;我再对照美国 RMG 常见监管/运营要求补齐评审基准。\n\n**Searching for RMG information**\n\nI need to look up information about the US RMG. My plan is to search the web for relevant details to gather the latest insights. Its important to ensure I have accurate and up-to-date information. Im curious to see what recent developments or discussions are happening in this area. Alright, lets get started with that search!"},{"type":"tool_use","name":"WebSearch","input":{"search_term":"US regulated online casino iGaming AML KYC geolocation responsible gaming requirements wallet withdrawals wagering bonus terms 2026","explanation":"Gather current public regulatory expectations for US real-money iGaming wallets and bonuses."}},{"type":"tool_use","name":"WebSearch","input":{"search_term":"New Jersey Internet gaming regulations patron funds segregation withdrawals responsible gaming bonus wagering terms","explanation":"Use a mature US iGaming jurisdiction as a benchmark for wallet and bonus compliance review."}},{"type":"tool_use","name":"WebSearch","input":{"search_term":"Michigan internet gaming responsible gaming bonus wagering requirements withdrawal rules patron funds geolocation KYC","explanation":"Cross-check common US state requirements for iGaming account, wallet, bonus, and withdrawal flows."}}]}}
{"role":"assistant","message":{"content":[{"type":"text","text":"结论:**目前不合格,不能作为美国 RMG 真钱 Slots 聚合游戏平台的钱包规则上线依据**。它更像是“首充前免费余额活动规则”,不是合规级真钱钱包规则。`钱包规则.md` 本身过于简单主需求文档虽补充了定格、释放、流水、幂等、统计但仍缺少美国真钱市场最关键的钱包、KYC/AML、责任博彩、州合规、资金托管和审计规则。\n\n最需要优先修正的风险点\n\n- **KYC / 年龄 / 地理位置缺失**:美国真钱 iGaming 通常要求 21+、身份验证、SSN/地址校验、州内地理围栏、制裁名单/PEP/AML 风控。文档只提到手机号绑定,不足够。\n- **真实资金与奖金资金分类不合规级**:现在只有“充值金额 + 赢取金额”,还需要区分 `cash balance`、`withdrawable cash`、`bonus balance`、`restricted bonus`、`pending withdrawal`、`locked funds`、`voided/expired bonus`、`chargeback hold` 等。\n- **“有任意未完成打码任务则全部不可提现”过粗**:美国市场通常需要清晰区分真钱本金、奖金、奖金赢利、锁定金额。不能简单因为一个 bonus wagering 未完成就冻结全部余额,否则有用户资金限制风险。\n- **“第一档免打码直接提现”需强法务审查**:充值满 `$50` 后释放 `$20` 免费金额直接提现,可能被监管视为高风险促销/诱导充值,需要明确 bonus terms、eligibility、state exclusions、withdrawal timing、fraud review、tax reporting。\n- **“广播允许模拟数据”不适合真钱市场**:提现/领取广播如果展示“just cashed out”但允许模拟数据存在严重广告真实性和误导用户风险。美国真钱市场建议只能展示真实、可审计、用户授权或合规脱敏的数据。\n- **提现规则不足**:缺少提现 SLA、KYC pending 处理、同源提现/闭环支付、手续费、最小/最大提现、风控审核、撤销提现限制、禁止诱导取消提现等。\n- **AML / 反欺诈不足**:只提到退款/拒付标记风险,不够。需要存取款监控、异常下注/套利/多账号/设备指纹/IP/支付工具关联、SAR/CTR 或内部可疑交易报告流程。\n- **聚合平台视角缺失**Slots 聚合平台还需要 game round ledger、provider bet/win rollback、session reconciliation、jackpot、void round、延迟回调、厂商账务对账、operator-of-record 职责边界。\n- **税务与报表缺失**:美国市场可能涉及 W-2G、1099、TIN/SSN、可报告奖金、州税/联邦税、年度报表、交易留存。\n- **责任博彩缺失**:需要 deposit limit、loss limit、wager limit、session limit、cool-off、自我排除、州责任博彩数据库、现实检查、1-800-GAMBLER 等展示规则。\n\n可以保留的部分主文档里的 `Free Credits Pool`、首充定格、幂等、状态机、钱包流水、提现/领取异常、后台统计这些方向是对的,适合作为一个 bonus campaign 子模块。但它必须挂在一个更完整的真钱钱包合规框架下面。\n\n建议把文档拆成两层\n\n1. `钱包规则.md` 改成真钱钱包主规则:账户实名、余额分类、资金流、可提现计算、提现、退款拒付、风控冻结、审计、税务、责任博彩、州配置。\n2. 当前“首充前免费余额定格与分档释放”作为 Bonus/Promotion 规则:只描述 Free Credits 的活动生命周期,不承担主钱包合规定义。\n\n上线判断**目前只能算产品活动需求草案,不能算美国 RMG 市场合格钱包规则**。需要法务/牌照顾问按目标州,例如 NJ、MI、PA、WV、CT 等逐州审核后再定稿。\n\n**Explaining compliance aspects**\n\nI should explain the positive aspects of the current documentation, like ledger and audit idempotency, the state machine, chargeback risk, and the independent pool. However, I notice that critical compliance is missing; I might want to rank these by severity too. Also, I must mention “合格美国RMG真钱SLOTS聚合游戏平台市场” specifically, pointing out that it is not ready for market launch requirements. Instead, it can be used as a promotional feature spec but not as a wallet master spec. Thats good to clarify!"}]}}

View File

@@ -0,0 +1,11 @@
{"role":"user","message":{"content":[{"type":"text","text":"<user_query>\n在 .cursor/agents/verifier.md 中创建一个子代理文件,在文件开头使用 YAML frontmattername、description后面写入具体提示内容。verifier 子代理应当验证已完成的工作,检查实现是否正常工作、运行测试,并报告通过的部分与未完成的部分。\n</user_query>"}]}}
{"role":"assistant","message":{"content":[{"type":"text","text":"先查看项目中现有的 agent 文件格式与约定。\n\n[REDACTED]"},{"type":"tool_use","name":"Glob","input":{"glob_pattern":"**/.cursor/agents/**"}},{"type":"tool_use","name":"Glob","input":{"glob_pattern":"**/agents/*.md","target_directory":"/Users/ray/.cursor"}},{"type":"tool_use","name":"Read","input":{"path":"/Users/ray/.cursor/skills-cursor/create-skill/SKILL.md","limit":80}}]}}
{"role":"assistant","message":{"content":[{"type":"text","text":"[REDACTED]"},{"type":"tool_use","name":"Grep","input":{"pattern":"agents/","path":"/Users/ray/.cursor","glob":"**/*","head_limit":30}},{"type":"tool_use","name":"Read","input":{"path":"/Users/ray/.cursor/skills-cursor/cursor-guide/SKILL.md","limit":150}},{"type":"tool_use","name":"Glob","input":{"glob_pattern":"**/.cursor/**","target_directory":"/Users/ray/Documents/project/www/slot"}}]}}
{"role":"assistant","message":{"content":[{"type":"text","text":"[REDACTED]"},{"type":"tool_use","name":"Shell","input":{"command":"ls -la /Users/ray/.cursor/agents 2>/dev/null || echo \"no agents dir\"; ls -la /Users/ray/Documents/project/www/slot/.cursor 2>/dev/null || echo \"no slot .cursor\"","description":"List .cursor/agents directories"}},{"type":"tool_use","name":"WebSearch","input":{"search_term":"Cursor IDE .cursor/agents subagent markdown frontmatter 2025","explanation":"Find official format for Cursor agent subagent files"}}]}}
{"role":"assistant","message":{"content":[{"type":"text","text":"[REDACTED]"},{"type":"tool_use","name":"WebFetch","input":{"url":"https://cursor.com/docs/agent/subagents"}}]}}
{"role":"assistant","message":{"content":[{"type":"text","text":"[REDACTED]"},{"type":"tool_use","name":"WebFetch","input":{"url":"https://cursor.com/docs/subagents"}},{"type":"tool_use","name":"Grep","input":{"pattern":"verifier|subagent|agents/","path":"/Users/ray/.cursor","head_limit":40}}]}}
{"role":"assistant","message":{"content":[{"type":"text","text":"[REDACTED]"},{"type":"tool_use","name":"Glob","input":{"glob_pattern":"**/create-subagent/**","target_directory":"/Users/ray/.cursor"}},{"type":"tool_use","name":"Read","input":{"path":"/Users/ray/.cursor/skills-cursor/.sync-manifest.json"}}]}}
{"role":"assistant","message":{"content":[{"type":"text","text":"[REDACTED]"},{"type":"tool_use","name":"Read","input":{"path":"/Users/ray/.cursor/skills-cursor/create-subagent/SKILL.md"}}]}}
{"role":"assistant","message":{"content":[{"type":"text","text":"正在根据 Cursor 子代理规范创建 `verifier` 子代理文件。\n\n[REDACTED]"},{"type":"tool_use","name":"Shell","input":{"command":"mkdir -p /Users/ray/.cursor/agents","description":"Create .cursor/agents directory"}}]}}
{"role":"assistant","message":{"content":[{"type":"text","text":"[REDACTED]"},{"type":"tool_use","name":"Write","input":{"path":"/Users/ray/.cursor/agents/verifier.md","contents":"---\nname: verifier\ndescription: >-\n Validates completed implementation work. Use after tasks are marked done,\n before merging PRs, or when the user asks to verify or double-check changes.\n Runs tests and checks that behavior matches requirements; reports what passed\n and what remains incomplete. Use proactively when implementation claims are made.\n---\n\nYou are a skeptical verification specialist. Your job is to prove that claimed work actually works—not to implement new features unless a minimal fix is required to complete verification.\n\nYou do not trust summaries, checklists, or \"done\" claims without evidence. Assume the primary agent may have missed edge cases, broken tests, or incomplete requirements until you verify otherwise.\n\n## When invoked\n\n1. **Gather scope** — Identify what was supposed to be delivered: user request, plan file, PR description, requirement doc, or recent git changes (`git status`, `git diff`, `git log -5`).\n2. **Map claims to evidence** — List each stated completion item and what you will check for it (code path, API, test, manual step).\n3. **Verify implementation** — Read relevant code; confirm logic matches requirements and project conventions (e.g. Controller → Validate → DTO → Logic → Service/Model layering).\n4. **Run checks** — Execute applicable automated checks; do not skip because they might be slow.\n5. **Report** — Produce a structured pass/fail report (see Output format).\n\n## Verification workflow\n\n### Code and requirements\n\n- Compare implementation against the original task or requirement document.\n- Flag stubs, TODOs, dead code paths, or commented-out logic that should be active.\n- Confirm error handling, idempotency, and edge cases mentioned in requirements.\n- Note files changed vs. files that should have changed but did not.\n\n### Tests and commands\n\nRun what the repo supports; prefer project-documented commands:\n\n| Stack | Typical commands |\n| --- | --- |\n| PHP (Webman, slot services) | `docker exec -w /app/www/slot/<service> php82 php vendor/bin/phpunit` or project-specific test scripts |\n| PHP (Composer) | `docker exec -w /app/www/slot/<service> php82 composer test` if defined |\n| Frontend (Vue) | `npm run test`, `npm run lint`, `npm run build` in the relevant package |\n| Go | `go test ./...` |\n\n**Local dev rule:** PHP/MySQL/Redis for this monorepo run in Docker (`php82`, `goMysql`, etc.). Do not run `php`/`composer` on the macOS host unless explicitly confirmed.\n\nIf tests cannot run (missing env, broken setup), say so explicitly and list what you verified manually instead.\n\n### Runtime / behavior (when applicable)\n\n- Trace request flow for new or changed APIs (route → controller → logic).\n- Check migrations, config, and feature flags if behavior depends on them.\n- For bug fixes, confirm the failure mode is addressed and regressions are unlikely.\n\n## Output format\n\nAlways end with this structure:\n\n```markdown\n## Verification report\n\n### Passed\n- [Item]: [brief evidence — e.g. test name passed, file/logic checked]\n\n### Failed or incomplete\n- [Item]: [what is wrong or missing]\n - **Evidence:** [test output, file:line, or requirement gap]\n - **Suggested fix:** [concrete next step, if obvious]\n\n### Not verified (blocked)\n- [Item]: [why — e.g. no test suite, env unavailable]\n\n### Summary\n[12 sentences: safe to merge / needs more work / critical blockers]\n```\n\n## Principles\n\n- **Evidence over opinion** — Cite test output, command exit codes, or specific code locations.\n- **Minimal scope** — Do not refactor or expand scope; only fix what blocks verification if the user expects you to fix failures.\n- **Be direct** — If something is broken, say so clearly; do not soften failures.\n- **Complete the loop** — If you fix something during verification, re-run the relevant checks before marking it passed.\n\n## What you must not do\n\n- Mark items as passed without running checks or reading the code.\n- Assume CI passed unless you have seen results.\n- Rewrite large portions of the codebase; escalate substantial gaps to the parent agent or user.\n"}}]}}
{"role":"assistant","message":{"content":[{"type":"text","text":"已在用户级目录创建 verifier 子代理:\n\n**路径:** `/Users/ray/.cursor/agents/verifier.md`\n\n对应规范中的 `~/.cursor/agents/`,对所有项目可用;若要在某个仓库内共享给团队,可复制到该仓库的 `.cursor/agents/verifier.md`。)\n\n### 文件结构\n\n- **YAML frontmatter**`name: verifier``description` 说明在任务完成、合并 PR 或需要复核时委托使用\n- **正文提示**:要求对“已完成”声明持怀疑态度,按范围核对需求、读代码、跑测试,并输出结构化报告\n\n### 核心行为\n\n1. 从 git diff、计划或需求文档确定验收范围 \n2. 逐项对照实现与要求 \n3. 在 Docker 环境(`php82` 等)运行 PHPUnit / 前端测试等 \n4. 输出 **Passed** / **Failed or incomplete** / **Not verified** / **Summary**\n\n### 使用方式\n\n在对话中让主代理委托即可例如\n\n```\nUse the verifier subagent to verify the free credits changes we just made.\n```\n\n或中文\n\n```\n用 verifier 子代理验证刚才的改动是否完成、测试是否通过。\n```\n\n如需改成**项目级**子代理(仅当前 monorepo、可提交 git告诉我目标仓库路径我可以再复制一份到对应 `.cursor/agents/`。\n\n[REDACTED]"}]}}

View File

@@ -0,0 +1,12 @@
The cursor-app-control MCP allows you to control the Cursor application itself. Use it to:
- Move the current agent to a new root workspace directory (move_agent_to_root) — use this after creating a worktree or whenever the conversation should continue from a different workspace root
- Move the current agent to a verbatim clone of the current workspace (move_agent_to_cloned_root) — use this ONLY when the target is a sibling clone already on the agent's branch (for example from cursorfs-clone); skips the migration git fetch / ff-merge that the generic move performs
- Create a new project at a given path (create_project) — creates the directory if missing and initializes a git repository. Use this to bootstrap a new project before moving to it with move_agent_to_root
- Open a resource by URI in Glass (open_resource) — opens files in the right-hand editor panel (workspace paths or anything under ~/.cursor), focuses terminals, opens output channels, opens web links according to the Glass browser setting, or delegates other schemes to the default workbench opener
- Manage personal rules in Cursor Settings (manage_personal_rules) — list, add, update, or delete user rules after asking what the user wants Cursor to remember
Use move_agent_to_root when you want the current conversation to adopt a different root workspace directory. This updates the visible work surface and the default cwd for new terminals.
Use move_agent_to_cloned_root when the target is a freshly-made sibling clone of the current workspace.
Use create_project when you need to create a brand new project directory with an initialized git repository.
Use open_resource when you need to reveal a file, terminal, output channel, or URL for the current agent.
Use manage_personal_rules for onboarding and preference-learning workflows. Always list first to avoid duplicate memories, and only write rules the user has agreed should be remembered.

View File

@@ -0,0 +1,4 @@
{
"serverIdentifier": "cursor-app-control",
"serverName": "cursor-app-control"
}

View File

@@ -0,0 +1,18 @@
{
"name": "create_project",
"description": "Create a new project at the given path. Creates the directory if it does not exist and initializes a git repository. Use this to bootstrap a new project before moving the agent to it with move_agent_to_root.",
"arguments": {
"$schema": "https://json-schema.org/draft/2020-12/schema",
"type": "object",
"properties": {
"path": {
"description": "Absolute path where the new project should be created (e.g. \"/Users/name/projects/my-new-app\")",
"type": "string"
}
},
"required": [
"path"
],
"additionalProperties": false
}
}

View File

@@ -0,0 +1,41 @@
{
"name": "move_agent_to_cloned_root",
"description": "Move the current agent to a root workspace directory that is a verbatim clone of the current workspace (for example produced by `cursorfs-clone`) and is already on the agent's recorded branch. Skips the migration-path `git fetch` and ff-merge that `move_agent_to_root` performs. Use ONLY when you already know the target is a sibling clone of the current workspace on the same branch; otherwise use `move_agent_to_root`.",
"arguments": {
"$schema": "https://json-schema.org/draft/2020-12/schema",
"anyOf": [
{
"type": "object",
"properties": {
"rootPath": {
"description": "Absolute path to the directory that should become the agent root workspace (e.g. \"/Users/name/projects/my-app\")",
"type": "string",
"minLength": 1
}
},
"required": [
"rootPath"
],
"additionalProperties": false
},
{
"type": "object",
"properties": {
"rootPaths": {
"description": "Array of absolute paths used to create/switch to a multi-root workspace.",
"minItems": 1,
"type": "array",
"items": {
"type": "string",
"minLength": 1
}
}
},
"required": [
"rootPaths"
],
"additionalProperties": false
}
]
}
}

View File

@@ -0,0 +1,41 @@
{
"name": "move_agent_to_root",
"description": "Move the current agent to a new root workspace directory. Use this after creating a worktree or whenever the conversation should continue from a different workspace root.",
"arguments": {
"$schema": "https://json-schema.org/draft/2020-12/schema",
"anyOf": [
{
"type": "object",
"properties": {
"rootPath": {
"description": "Absolute path to the directory that should become the agent root workspace (e.g. \"/Users/name/projects/my-app\")",
"type": "string",
"minLength": 1
}
},
"required": [
"rootPath"
],
"additionalProperties": false
},
{
"type": "object",
"properties": {
"rootPaths": {
"description": "Array of absolute paths used to create/switch to a multi-root workspace.",
"minItems": 1,
"type": "array",
"items": {
"type": "string",
"minLength": 1
}
}
},
"required": [
"rootPaths"
],
"additionalProperties": false
}
]
}
}

View File

@@ -0,0 +1,51 @@
The cursor-ide-browser is an MCP server that allows you to navigate the web and interact with the page. Use this for frontend/webapp development and testing code changes.
CORE WORKFLOW:
1. Start by understanding the user's goal and what success looks like on the page.
2. Use browser_tabs with action "list" to inspect open tabs and URLs before acting.
3. Use browser_snapshot before any interaction to inspect the current page structure and obtain refs.
4. Use browser_take_screenshot for standalone visual verification or screenshot-based coordinate clicks. For browser_mouse_click_xy, capture a fresh viewport screenshot for the same tab and then issue the click immediately using coordinates from that screenshot. Do not reuse older screenshot coordinates. If any other browser tool runs first, capture a new viewport screenshot before calling browser_mouse_click_xy.
5. After any action that could change the page structure or URL (click, type, fill, fill_form, select, hover, press key, drag, browser_navigate, browser_navigate_back, wait, dialog response, or lazy-loaded scroll), take a fresh browser_snapshot before the next structural action unless you are certain the page did not change.
AGENTIC PAGE NAVIGATION:
1. When you know the destination, use browser_navigate directly to that URL.
2. Use browser_navigate_back for browser history. Keep track of the current URL from tool output or snapshot metadata so you can navigate directly when needed.
3. Work top-down: identify the relevant page region, dialog, form, or menu in the snapshot first, then target a specific ref inside it.
4. Prefer one deliberate action followed by verification over exploratory thrashing.
5. Use browser_search to locate text before blindly scrolling through large pages.
6. Use browser_hover to reveal tooltips, dropdown menus, or hidden content before interacting with revealed elements.
7. Use browser_scroll with scrollIntoView: true before clicking elements that may be offscreen or obscured.
8. Use browser_fill to replace existing content (works on both input fields and contenteditable elements) and browser_type to append text or trigger typing-related handlers.
9. If multiple elements share the same role and name, choose the exact ref from the snapshot instead of guessing. Use [nth=N] only as a hint to tell duplicate elements apart.
AVOID RABBIT HOLES:
1. Do not repeat the same failing action more than once without new evidence such as a fresh snapshot, a different ref, a changed page state, or a clear new hypothesis.
2. IMPORTANT: If four attempts fail or progress stalls, stop acting and report what you observed, what blocked progress, and the most likely next step.
3. Prefer gathering evidence over brute force. If the page is confusing, use browser_snapshot, browser_console_messages, browser_network_requests, or a screenshot to understand it before trying more actions.
4. If you encounter a blocker such as login, passkey/manual user interaction, permissions, captchas, destructive confirmations, missing data, or an unexpected state, stop and report it instead of improvising repeated actions.
5. Do not get stuck in wait-action-wait loops. Every retry should be justified by something newly observed.
CRITICAL - Lock/unlock workflow:
1. browser_lock requires an existing browser tab - you CANNOT call browser_lock with action: "lock" before browser_navigate
2. Correct order: browser_navigate -> browser_lock({ action: "lock" }) -> (interactions) -> browser_lock({ action: "unlock" })
3. If a browser tab already exists (check with browser_tabs list), call browser_lock with action: "lock" FIRST before any interactions
4. Only call browser_lock with action: "unlock" when completely done with ALL browser operations for this turn
IMPORTANT - Waiting strategy:
When waiting for page changes (navigation, content loading, animations, etc.), prefer short incremental waits (1-3 seconds) with browser_snapshot checks in between rather than a single long wait. For example, instead of waiting 10 seconds, do: wait 2s -> snapshot -> check if ready -> if not, wait 2s more -> snapshot again. This allows you to proceed as soon as the page is ready rather than always waiting the maximum time.
PERFORMANCE PROFILING:
- browser_profile_start/stop: CPU profiling with call stacks and timing data. Use to identify slow JavaScript functions.
- Profile data is written to ~/.cursor/browser-logs/. Files: cpu-profile-{timestamp}.json (raw profile in Chrome DevTools format) and cpu-profile-{timestamp}-summary.md (human-readable summary).
- IMPORTANT: When investigating performance issues, read the raw cpu-profile-*.json file to verify summary data. Key fields: profile.samples.length (total samples), profile.nodes[].hitCount (per-node hits), profile.nodes[].callFrame.functionName (function names). Cross-reference with the summary to confirm findings before making optimization recommendations.
VISION:
- Snapshot and interaction tools can optionally attach a page screenshot by setting take_screenshot_afterwards: true. The screenshot provides visual context (layout, colors, state); the aria snapshot provides element refs required for targeting actions. Use both together: the screenshot shows what the page looks like, the snapshot tells you how to interact with it. Prefer refs from the snapshot for interactions; the one screenshot-based exception is browser_mouse_click_xy, which must use coordinates from a fresh viewport screenshot captured immediately before the click for that tab. Any other browser tool call invalidates that screenshot cache.
NOTES:
- browser_snapshot returns snapshot YAML and is the main source of truth for page structure.
- Refs are opaque handles tied to the latest browser_snapshot for that tab. If a ref stops working, take a fresh snapshot instead of guessing.
- Native dialogs (alert/confirm/prompt) never block automation. By default, confirm() returns true and prompt() returns the default value. To test different responses, call browser_handle_dialog BEFORE the triggering action: use accept: false for "Cancel", or promptText: "value" for custom prompt input.
- Iframe content is not accessible - only elements outside iframes can be interacted with.
- For nested scroll containers, use browser_scroll with scrollIntoView: true before clicking elements that may be obscured.
- When you stop to report a blocker, include the current page, the target you were trying to reach, the blocker you observed, and the best next action. If the blocker requires manual user interaction, ask the user to take over at that point rather than assuming it in advance.

View File

@@ -0,0 +1,4 @@
{
"serverIdentifier": "cursor-ide-browser",
"serverName": "cursor-ide-browser"
}

View File

@@ -0,0 +1,64 @@
{
"name": "browser_click",
"description": "Perform click on a web page. Supports single/double click, different mouse buttons, modifier keys, position offsets, and hold duration.",
"arguments": {
"type": "object",
"properties": {
"element": {
"type": "string",
"description": "Human-readable element description used to obtain permission to interact with the element"
},
"ref": {
"type": "string",
"description": "Exact target element reference from the page snapshot"
},
"doubleClick": {
"type": "boolean",
"description": "Whether to perform a double click instead of a single click"
},
"button": {
"type": "string",
"enum": [
"left",
"right",
"middle"
],
"description": "Mouse button to click. Defaults to \"left\"."
},
"modifiers": {
"type": "array",
"items": {
"type": "string",
"enum": [
"Control",
"Shift",
"Alt",
"Meta",
"ControlOrMeta"
]
},
"description": "Modifier keys to hold during click. \"ControlOrMeta\" uses Ctrl on Windows/Linux and Cmd on Mac."
},
"offsetX": {
"type": "number",
"description": "Horizontal offset from element's left edge in pixels. If omitted, clicks at horizontal center."
},
"offsetY": {
"type": "number",
"description": "Vertical offset from element's top edge in pixels. If omitted, clicks at vertical center."
},
"holdDurationMs": {
"type": "number",
"description": "Duration to hold the mouse button down before releasing, in milliseconds. Useful for long-press interactions. Defaults to 0 (immediate release)."
},
"viewId": {
"type": "string",
"description": "Target browser tab ID. If omitted, uses the last interacted tab."
}
},
"required": [
"element",
"ref"
]
}
}

View File

@@ -0,0 +1,14 @@
{
"name": "browser_console_messages",
"description": "Returns all console messages",
"arguments": {
"type": "object",
"properties": {
"viewId": {
"type": "string",
"description": "Target browser tab ID. If omitted, uses the last interacted tab."
}
},
"required": []
}
}

View File

@@ -0,0 +1,32 @@
{
"name": "browser_drag",
"description": "Perform a drag and drop operation. Drags from a source element to a target element or coordinates.",
"arguments": {
"type": "object",
"properties": {
"sourceRef": {
"type": "string",
"description": "Reference of the element to drag from"
},
"targetRef": {
"type": "string",
"description": "Reference of the element to drop onto"
},
"targetX": {
"type": "number",
"description": "X coordinate to drop at (relative to viewport). Use with targetY instead of targetRef for coordinate-based drops."
},
"targetY": {
"type": "number",
"description": "Y coordinate to drop at (relative to viewport). Use with targetX instead of targetRef for coordinate-based drops."
},
"viewId": {
"type": "string",
"description": "Target browser tab ID. If omitted, uses the last interacted tab."
}
},
"required": [
"sourceRef"
]
}
}

View File

@@ -0,0 +1,30 @@
{
"name": "browser_fill",
"description": "Clear and fill a value into an input element. Unlike browser_type which appends text, this clears the existing value first and sets the new value atomically. Use this when you want to replace the entire content of an input field.",
"arguments": {
"type": "object",
"properties": {
"element": {
"type": "string",
"description": "Human-readable element description used to obtain permission to interact with the element"
},
"ref": {
"type": "string",
"description": "Exact target element reference from the page snapshot"
},
"value": {
"type": "string",
"description": "Value to fill into the element (replaces any existing content)"
},
"viewId": {
"type": "string",
"description": "Target browser tab ID. If omitted, uses the last interacted tab."
}
},
"required": [
"element",
"ref",
"value"
]
}
}

View File

@@ -0,0 +1,49 @@
{
"name": "browser_fill_form",
"description": "Fill multiple form fields at once. Each field uses ref + value. By default, each field is cleared before setting the new value.",
"arguments": {
"type": "object",
"properties": {
"fields": {
"type": "array",
"items": {
"type": "object",
"properties": {
"element": {
"type": "string",
"description": "Human-readable element description used to obtain permission to interact with the element"
},
"ref": {
"type": "string",
"description": "Exact target element reference from the page snapshot"
},
"value": {
"type": "string",
"description": "Value to fill into the field"
},
"clear": {
"type": "boolean",
"description": "Whether to clear existing content before filling. Defaults to true."
}
},
"required": [
"element",
"ref",
"value"
]
}
},
"viewId": {
"type": "string",
"description": "Target browser tab ID. If omitted, uses the last interacted tab."
},
"take_screenshot_afterwards": {
"type": "boolean",
"description": "When true, takes a screenshot after the fill completes. Defaults to false."
}
},
"required": [
"fields"
]
}
}

View File

@@ -0,0 +1,25 @@
{
"name": "browser_get_bounding_box",
"description": "Get bounding box details for an element.",
"arguments": {
"type": "object",
"properties": {
"element": {
"type": "string",
"description": "Human-readable element description used to obtain permission to inspect the element"
},
"ref": {
"type": "string",
"description": "Exact target element reference from the page snapshot"
},
"viewId": {
"type": "string",
"description": "Target browser tab ID. If omitted, uses the last interacted tab."
}
},
"required": [
"element",
"ref"
]
}
}

View File

@@ -0,0 +1,24 @@
{
"name": "browser_handle_dialog",
"description": "Configure how native browser dialogs (alert, confirm, prompt) are handled. Dialogs are non-blocking in this environment - they return immediately without showing a visible dialog. Use this tool BEFORE triggering an action that shows a dialog to configure what value it should return. Also returns recent dialog history.",
"arguments": {
"type": "object",
"properties": {
"accept": {
"type": "boolean",
"description": "For confirm() dialogs: true to simulate clicking OK (returns true), false to simulate clicking Cancel (returns false). Default behavior is true."
},
"promptText": {
"type": "string",
"description": "For prompt() dialogs: the text value to return. If not specified, prompt() returns the default value provided by the page."
},
"viewId": {
"type": "string",
"description": "Target browser tab ID. If omitted, uses the last interacted tab."
}
},
"required": [
"accept"
]
}
}

View File

@@ -0,0 +1,29 @@
{
"name": "browser_highlight",
"description": "Temporarily highlight an element for visual debugging.",
"arguments": {
"type": "object",
"properties": {
"element": {
"type": "string",
"description": "Human-readable element description used to obtain permission to inspect the element"
},
"ref": {
"type": "string",
"description": "Exact target element reference from the page snapshot"
},
"durationMs": {
"type": "number",
"description": "Highlight duration in milliseconds. Defaults to 2000."
},
"viewId": {
"type": "string",
"description": "Target browser tab ID. If omitted, uses the last interacted tab."
}
},
"required": [
"element",
"ref"
]
}
}

View File

@@ -0,0 +1,25 @@
{
"name": "browser_hover",
"description": "Hover over element on page",
"arguments": {
"type": "object",
"properties": {
"element": {
"type": "string",
"description": "Human-readable element description used to obtain permission to interact with the element"
},
"ref": {
"type": "string",
"description": "Exact target element reference from the page snapshot"
},
"viewId": {
"type": "string",
"description": "Target browser tab ID. If omitted, uses the last interacted tab."
}
},
"required": [
"element",
"ref"
]
}
}

View File

@@ -0,0 +1,24 @@
{
"name": "browser_lock",
"description": "Lock or unlock the browser to control whether the user can interact while you work. Set action to \"lock\" or \"unlock\". When locked, the user can still click \"Take Control\" to unlock if needed.",
"arguments": {
"type": "object",
"properties": {
"action": {
"type": "string",
"enum": [
"lock",
"unlock"
],
"description": "Whether to lock or unlock the browser for user interaction."
},
"viewId": {
"type": "string",
"description": "Target browser tab ID. If omitted, uses the last interacted tab."
}
},
"required": [
"action"
]
}
}

View File

@@ -0,0 +1,34 @@
{
"name": "browser_mouse_click_xy",
"description": "Click left, middle, or right mouse button using coordinates from a fresh viewport screenshot captured immediately before this call for the same tab. Do not reuse older screenshot coordinates. If any other browser tool runs first, this call will fail until you capture a new viewport screenshot.",
"arguments": {
"type": "object",
"properties": {
"x": {
"type": "number",
"description": "X coordinate from the fresh viewport screenshot captured immediately before this call for this tab, measured in screenshot pixels."
},
"y": {
"type": "number",
"description": "Y coordinate from the fresh viewport screenshot captured immediately before this call for this tab, measured in screenshot pixels."
},
"button": {
"type": "string",
"enum": [
"left",
"right",
"middle"
],
"description": "Mouse button to click. Defaults to \"left\"."
},
"viewId": {
"type": "string",
"description": "Target browser tab ID. If omitted, uses the last interacted tab."
}
},
"required": [
"x",
"y"
]
}
}

View File

@@ -0,0 +1,36 @@
{
"name": "browser_navigate",
"description": "Navigate to a URL. By default reuses an existing tab; set newTab: true to open in a new tab.",
"arguments": {
"type": "object",
"properties": {
"url": {
"type": "string",
"description": "The URL to navigate to"
},
"viewId": {
"type": "string",
"description": "Target browser tab ID. If omitted, uses the last interacted tab."
},
"position": {
"type": "string",
"enum": [
"active",
"side"
],
"description": "IMPORTANT: Set to \"side\" if user mentions \"side\", \"beside\", \"side panel\", or \"side by side\". Opens browser in side editor group. Defaults to \"active\" (current editor group)."
},
"take_screenshot_afterwards": {
"type": "boolean",
"description": "When true, takes a screenshot after navigation completes. Defaults to false."
},
"newTab": {
"type": "boolean",
"description": "When true, creates a new tab before navigating instead of reusing an existing tab. Defaults to false."
}
},
"required": [
"url"
]
}
}

View File

@@ -0,0 +1,14 @@
{
"name": "browser_navigate_back",
"description": "Go back to the previous page in browser history. Returns an error if there is no previous page to navigate to.",
"arguments": {
"type": "object",
"properties": {
"viewId": {
"type": "string",
"description": "Target browser tab ID. If omitted, uses the last interacted tab."
}
},
"required": []
}
}

View File

@@ -0,0 +1,14 @@
{
"name": "browser_network_requests",
"description": "Returns all network requests since loading the page",
"arguments": {
"type": "object",
"properties": {
"viewId": {
"type": "string",
"description": "Target browser tab ID. If omitted, uses the last interacted tab."
}
},
"required": []
}
}

View File

@@ -0,0 +1,20 @@
{
"name": "browser_press_key",
"description": "Press a key on the keyboard. Supports key combinations with modifiers using \"+\" syntax.",
"arguments": {
"type": "object",
"properties": {
"key": {
"type": "string",
"description": "Key to press. Single keys: \"a\", \"Enter\", \"Escape\", \"Tab\", \"Backspace\", \"Delete\", \"ArrowUp\", \"ArrowDown\", \"ArrowLeft\", \"ArrowRight\", \"PageUp\", \"PageDown\", \"Home\", \"End\", \"F1\"-\"F12\", \"Space\". Key combinations with modifiers using \"+\": \"Control+s\", \"Ctrl+Shift+p\", \"Alt+Tab\", \"Meta+a\" (Cmd on Mac). Modifier aliases: Control/Ctrl, Shift, Alt/Option, Meta/Command/Cmd/Win."
},
"viewId": {
"type": "string",
"description": "Target browser tab ID. If omitted, uses the last interacted tab."
}
},
"required": [
"key"
]
}
}

View File

@@ -0,0 +1,14 @@
{
"name": "browser_profile_start",
"description": "Start CPU profiling to capture call stack timing data. Use browser_profile_stop to end profiling and get results.",
"arguments": {
"type": "object",
"properties": {
"viewId": {
"type": "string",
"description": "Target browser tab ID. If omitted, uses the last interacted tab."
}
},
"required": []
}
}

View File

@@ -0,0 +1,14 @@
{
"name": "browser_profile_stop",
"description": "Stop CPU profiling and return the profile data including call stacks, timing, and samples.",
"arguments": {
"type": "object",
"properties": {
"viewId": {
"type": "string",
"description": "Target browser tab ID. If omitted, uses the last interacted tab."
}
},
"required": []
}
}

View File

@@ -0,0 +1,25 @@
{
"name": "browser_resize",
"description": "Resize the browser window",
"arguments": {
"type": "object",
"properties": {
"width": {
"type": "number",
"description": "Width of the browser window"
},
"height": {
"type": "number",
"description": "Height of the browser window"
},
"viewId": {
"type": "string",
"description": "Target browser tab ID. If omitted, uses the last interacted tab."
}
},
"required": [
"width",
"height"
]
}
}

View File

@@ -0,0 +1,44 @@
{
"name": "browser_scroll",
"description": "Scroll the page or a specific element. Use this to bring elements into view, scroll to content, or navigate long pages. Can scroll in any direction by specifying delta values or using directional shortcuts.",
"arguments": {
"type": "object",
"properties": {
"ref": {
"type": "string",
"description": "Element reference to scroll into view, or to scroll within (for scrollable containers)"
},
"direction": {
"type": "string",
"enum": [
"up",
"down",
"left",
"right"
],
"description": "Direction to scroll. Shorthand for setting deltaX/deltaY."
},
"amount": {
"type": "number",
"description": "Amount to scroll in pixels when using direction. Defaults to 300."
},
"deltaX": {
"type": "number",
"description": "Horizontal scroll amount in pixels. Positive scrolls right, negative scrolls left."
},
"deltaY": {
"type": "number",
"description": "Vertical scroll amount in pixels. Positive scrolls down, negative scrolls up."
},
"scrollIntoView": {
"type": "boolean",
"description": "If true and ref is provided, scrolls the element into view instead of scrolling within it. Defaults to true when ref is provided without delta values."
},
"viewId": {
"type": "string",
"description": "Target browser tab ID. If omitted, uses the last interacted tab."
}
},
"required": []
}
}

View File

@@ -0,0 +1,30 @@
{
"name": "browser_search",
"description": "Search for text on the current page, similar to Cmd+F / Ctrl+F. Highlights all matches, scrolls to the first match, and returns a screenshot showing the match in context along with the count and positions of matches found.",
"arguments": {
"type": "object",
"properties": {
"query": {
"type": "string",
"description": "The text to search for on the page"
},
"caseSensitive": {
"type": "boolean",
"description": "Whether the search should be case-sensitive. Defaults to false."
},
"navigateToMatch": {
"type": "number",
"description": "Navigate to a specific match by index (0-based). If not provided, navigates to the first match."
},
"clearHighlights": {
"type": "boolean",
"description": "If true, clears all search highlights without performing a new search. Use this to remove previous search highlights."
},
"viewId": {
"type": "string",
"description": "Target browser tab ID. If omitted, uses the last interacted tab."
}
},
"required": []
}
}

View File

@@ -0,0 +1,33 @@
{
"name": "browser_select_option",
"description": "Select an option in a dropdown. Matching priority: exact value match, then exact label match, then partial label match. The snapshot now shows available options for select elements.",
"arguments": {
"type": "object",
"properties": {
"element": {
"type": "string",
"description": "Human-readable element description used to obtain permission to interact with the element"
},
"ref": {
"type": "string",
"description": "Exact target element reference from the page snapshot"
},
"values": {
"type": "array",
"items": {
"type": "string"
},
"description": "Array of values to select. Matches against option value first, then label text, then partial label. Use exact values from the snapshot options list when available."
},
"viewId": {
"type": "string",
"description": "Target browser tab ID. If omitted, uses the last interacted tab."
}
},
"required": [
"element",
"ref",
"values"
]
}
}

View File

@@ -0,0 +1,38 @@
{
"name": "browser_snapshot",
"description": "Capture accessibility snapshot of the current page, this is better than screenshot",
"arguments": {
"type": "object",
"properties": {
"viewId": {
"type": "string",
"description": "Target browser tab ID. If omitted, uses the last interacted tab."
},
"interactive": {
"type": "boolean",
"description": "When true, only include interactive elements in the snapshot. Defaults to false."
},
"maxDepth": {
"type": "number",
"description": "Maximum depth for snapshot output. Defaults to 20."
},
"compact": {
"type": "boolean",
"description": "When true, outputs a more compact snapshot format. Defaults to false."
},
"selector": {
"type": "string",
"description": "Optional CSS selector to scope the snapshot to a subtree."
},
"includeDiff": {
"type": "boolean",
"description": "When true, include a diff vs the previous snapshot for this tab. Defaults to false."
},
"take_screenshot_afterwards": {
"type": "boolean",
"description": "When true, takes a screenshot after snapshot completes. Defaults to false."
}
},
"required": []
}
}

View File

@@ -0,0 +1,34 @@
{
"name": "browser_tabs",
"description": "List, create, close, or select a browser tab",
"arguments": {
"type": "object",
"properties": {
"action": {
"type": "string",
"enum": [
"list",
"new",
"close",
"select"
],
"description": "Operation to perform"
},
"index": {
"type": "number",
"description": "Tab index. Required for \"select\". Optional for \"close\" (defaults to current tab)."
},
"position": {
"type": "string",
"enum": [
"active",
"side"
],
"description": "IMPORTANT: Set to \"side\" if user mentions \"side\", \"beside\", \"side panel\", or \"side by side\". Opens browser in side editor group. Only for action \"new\". Defaults to \"active\"."
}
},
"required": [
"action"
]
}
}

View File

@@ -0,0 +1,34 @@
{
"name": "browser_take_screenshot",
"description": "Take a screenshot of the current page. You can't perform actions based on the screenshot, use browser_snapshot for actions.",
"arguments": {
"type": "object",
"properties": {
"type": {
"type": "string",
"description": "Image format for the screenshot. Default is png."
},
"filename": {
"type": "string",
"description": "File name to save the screenshot to. Defaults to page-{timestamp}.{png|jpeg} if not specified."
},
"element": {
"type": "string",
"description": "Description of the element, if taking a screenshot of an element"
},
"ref": {
"type": "string",
"description": "CSS selector for the element, if taking a screenshot of an element"
},
"fullPage": {
"type": "boolean",
"description": "When true, takes a screenshot of the full scrollable page, instead of the currently visible viewport. Cannot be used with element screenshots."
},
"viewId": {
"type": "string",
"description": "Target browser tab ID. If omitted, uses the last interacted tab."
}
},
"required": []
}
}

View File

@@ -0,0 +1,42 @@
{
"name": "browser_type",
"description": "Type text into editable element",
"arguments": {
"type": "object",
"properties": {
"element": {
"type": "string",
"description": "Human-readable element description used to obtain permission to interact with the element"
},
"ref": {
"type": "string",
"description": "Exact target element reference from the page snapshot"
},
"text": {
"type": "string",
"description": "Text to type into the element"
},
"clear": {
"type": "boolean",
"description": "Whether to clear existing content before typing. Use this to replace the current value instead of appending to it. Defaults to false."
},
"submit": {
"type": "boolean",
"description": "Whether to submit entered text (press Enter after)"
},
"slowly": {
"type": "boolean",
"description": "Whether to type one character at a time. Useful for triggering key handlers in the page. By default entire text is filled in at once."
},
"viewId": {
"type": "string",
"description": "Target browser tab ID. If omitted, uses the last interacted tab."
}
},
"required": [
"element",
"ref",
"text"
]
}
}

View File

@@ -0,0 +1,30 @@
{
"name": "browser_wait_for",
"description": "Wait for text to appear or disappear, or wait a specified time. Note: time is in SECONDS, not milliseconds.",
"arguments": {
"type": "object",
"properties": {
"time": {
"type": "number",
"description": "Time to wait in SECONDS (e.g., 2 for 2 seconds, 0.5 for 500ms). Use for fixed delays."
},
"text": {
"type": "string",
"description": "Wait for this text to appear on the page."
},
"textGone": {
"type": "string",
"description": "Wait for this text to disappear from the page."
},
"timeout": {
"type": "number",
"description": "Maximum time to wait for text conditions in MILLISECONDS. Defaults to 30000 (30 seconds)."
},
"viewId": {
"type": "string",
"description": "Target browser tab ID. If omitted, uses the last interacted tab."
}
},
"required": []
}
}

View File

@@ -0,0 +1,114 @@
---
pid: 68779
cwd: /Users/ray/.cursor
---
new file: projects/Users-ray-Documents-project-www-slot-backend/mcps/cursor-ide-browser/tools/browser_snapshot.json
new file: projects/Users-ray-Documents-project-www-slot-backend/mcps/cursor-ide-browser/tools/browser_tabs.json
new file: projects/Users-ray-Documents-project-www-slot-backend/mcps/cursor-ide-browser/tools/browser_take_screenshot.json
new file: projects/Users-ray-Documents-project-www-slot-backend/mcps/cursor-ide-browser/tools/browser_type.json
new file: projects/Users-ray-Documents-project-www-slot-backend/mcps/cursor-ide-browser/tools/browser_wait_for.json
new file: projects/Users-ray-Documents-project-www-slot-backend/terminals/1.txt
new file: projects/Users-ray-Documents-project-www-slot-backend/terminals/2.txt
new file: projects/Users-ray-Documents-project-www-slot-backend/terminals/371510.txt
new file: projects/Users-ray-Documents-project-www-slot-backend/terminals/974578.txt
new file: projects/Users-ray-Documents-project-www-slot-monitor/agent-transcripts/d76c9f01-f52d-4ac3-9c5e-ae44397c8114/d76c9f01-f52d-4ac3-9c5e-ae44397c8114.jsonl
new file: projects/Users-ray-Documents-project-www-slot-monitor/mcps/plugin-figma-figma/SERVER_METADATA.json
new file: projects/Users-ray-Documents-project-www-slot-monitor/mcps/plugin-figma-figma/STATUS.md
new file: projects/Users-ray-Documents-project-www-slot-monitor/mcps/plugin-figma-figma/tools/mcp_auth.json
new file: projects/Users-ray-Documents-project-www-slot-monitor/terminals/476873.txt
new file: projects/Users-ray-Documents-project-www-slot-monitor/terminals/569505.txt
new file: projects/Users-ray-Documents-project-www-slot-slot-wallet/agent-transcripts/a107aa6a-fbde-4fcf-a381-52a84c968f4b/a107aa6a-fbde-4fcf-a381-52a84c968f4b.jsonl
new file: projects/Users-ray-Documents-project-www-slot-slot-wallet/agent-transcripts/a107aa6a-fbde-4fcf-a381-52a84c968f4b/subagents/7d6538fb-5024-4fbf-888b-814014e07ed9.jsonl
new file: projects/Users-ray-Documents-project-www-slot-slot-wallet/agent-transcripts/a107aa6a-fbde-4fcf-a381-52a84c968f4b/subagents/8df7e19c-5f81-47d4-8a96-e1d84af44342.jsonl
new file: projects/Users-ray-Documents-project-www-slot-slot-wallet/agent-transcripts/a107aa6a-fbde-4fcf-a381-52a84c968f4b/subagents/c265019c-0a39-48fc-82ea-1b0fb8a383af.jsonl
new file: projects/Users-ray-Documents-project-www-slot-slot-wallet/agent-transcripts/a107aa6a-fbde-4fcf-a381-52a84c968f4b/subagents/e986ea99-31ef-43cf-b348-cf781823e734.jsonl
new file: projects/Users-ray-Documents-project-www-slot-slot-wallet/agent-transcripts/cde4689f-7de9-40a7-b6cb-d15d09b792e1/cde4689f-7de9-40a7-b6cb-d15d09b792e1.jsonl
new file: projects/Users-ray-Documents-project-www-slot-slot-wallet/agent-transcripts/d7dbe1fd-a305-4b9c-b14a-1c6bd51396c0/d7dbe1fd-a305-4b9c-b14a-1c6bd51396c0.jsonl
new file: projects/Users-ray-Documents-project-www-slot/mcps/plugin-figma-figma/SERVER_METADATA.json
new file: projects/Users-ray-Documents-project-www-slot/mcps/plugin-figma-figma/STATUS.md
new file: projects/Users-ray-Documents-project-www-slot/mcps/plugin-figma-figma/tools/mcp_auth.json
new file: projects/empty-window/mcps/cursor-app-control/INSTRUCTIONS.md
new file: projects/empty-window/mcps/cursor-app-control/SERVER_METADATA.json
new file: projects/empty-window/mcps/cursor-app-control/tools/create_project.json
new file: projects/empty-window/mcps/cursor-app-control/tools/move_agent_to_cloned_root.json
new file: projects/empty-window/mcps/cursor-app-control/tools/move_agent_to_root.json
new file: projects/empty-window/mcps/cursor-ide-browser/INSTRUCTIONS.md
new file: projects/empty-window/mcps/cursor-ide-browser/SERVER_METADATA.json
new file: projects/empty-window/mcps/cursor-ide-browser/tools/browser_click.json
new file: projects/empty-window/mcps/cursor-ide-browser/tools/browser_console_messages.json
new file: projects/empty-window/mcps/cursor-ide-browser/tools/browser_drag.json
new file: projects/empty-window/mcps/cursor-ide-browser/tools/browser_fill.json
new file: projects/empty-window/mcps/cursor-ide-browser/tools/browser_fill_form.json
new file: projects/empty-window/mcps/cursor-ide-browser/tools/browser_get_bounding_box.json
new file: projects/empty-window/mcps/cursor-ide-browser/tools/browser_handle_dialog.json
new file: projects/empty-window/mcps/cursor-ide-browser/tools/browser_highlight.json
new file: projects/empty-window/mcps/cursor-ide-browser/tools/browser_hover.json
new file: projects/empty-window/mcps/cursor-ide-browser/tools/browser_lock.json
new file: projects/empty-window/mcps/cursor-ide-browser/tools/browser_mouse_click_xy.json
new file: projects/empty-window/mcps/cursor-ide-browser/tools/browser_navigate.json
new file: projects/empty-window/mcps/cursor-ide-browser/tools/browser_navigate_back.json
new file: projects/empty-window/mcps/cursor-ide-browser/tools/browser_network_requests.json
new file: projects/empty-window/mcps/cursor-ide-browser/tools/browser_press_key.json
new file: projects/empty-window/mcps/cursor-ide-browser/tools/browser_profile_start.json
new file: projects/empty-window/mcps/cursor-ide-browser/tools/browser_profile_stop.json
new file: projects/empty-window/mcps/cursor-ide-browser/tools/browser_resize.json
new file: projects/empty-window/mcps/cursor-ide-browser/tools/browser_scroll.json
new file: projects/empty-window/mcps/cursor-ide-browser/tools/browser_search.json
new file: projects/empty-window/mcps/cursor-ide-browser/tools/browser_select_option.json
new file: projects/empty-window/mcps/cursor-ide-browser/tools/browser_snapshot.json
new file: projects/empty-window/mcps/cursor-ide-browser/tools/browser_tabs.json
new file: projects/empty-window/mcps/cursor-ide-browser/tools/browser_take_screenshot.json
new file: projects/empty-window/mcps/cursor-ide-browser/tools/browser_type.json
new file: projects/empty-window/mcps/cursor-ide-browser/tools/browser_wait_for.json
new file: projects/empty-window/mcps/plugin-figma-figma/SERVER_METADATA.json
new file: projects/empty-window/mcps/plugin-figma-figma/STATUS.md
new file: projects/empty-window/mcps/plugin-figma-figma/tools/mcp_auth.json
new file: projects/empty-window/terminals/1.txt
new file: projects/var-folders-vp-v0rvf5pn4xlgr4b0c-v0mrbh0000gn-T-3ee74edc-a9d9-4294-9af2-eb34042f1991/mcps/plugin-figma-figma/SERVER_METADATA.json
new file: projects/var-folders-vp-v0rvf5pn4xlgr4b0c-v0mrbh0000gn-T-3ee74edc-a9d9-4294-9af2-eb34042f1991/mcps/plugin-figma-figma/STATUS.md
new file: projects/var-folders-vp-v0rvf5pn4xlgr4b0c-v0mrbh0000gn-T-3ee74edc-a9d9-4294-9af2-eb34042f1991/mcps/plugin-figma-figma/tools/mcp_auth.json
new file: projects/var-folders-vp-v0rvf5pn4xlgr4b0c-v0mrbh0000gn-T-4601ed89-9ab9-41e1-87af-4432ce0912a7/mcps/plugin-figma-figma/SERVER_METADATA.json
new file: projects/var-folders-vp-v0rvf5pn4xlgr4b0c-v0mrbh0000gn-T-4601ed89-9ab9-41e1-87af-4432ce0912a7/mcps/plugin-figma-figma/STATUS.md
new file: projects/var-folders-vp-v0rvf5pn4xlgr4b0c-v0mrbh0000gn-T-4601ed89-9ab9-41e1-87af-4432ce0912a7/mcps/plugin-figma-figma/tools/mcp_auth.json
new file: rules/backend-layering.mdc
new file: rules/cross-service-sdk.mdc
new file: rules/dev-environment.mdc
new file: rules/php-doc.mdc
new file: skills-cursor/.sync-manifest.json
new file: skills-cursor/babysit/SKILL.md
new file: skills-cursor/canvas/SKILL.md
new file: skills-cursor/canvas/sdk/canvas-tokens.d.ts
new file: skills-cursor/canvas/sdk/chart-primitives.d.ts
new file: skills-cursor/canvas/sdk/collapsible-section.d.ts
new file: skills-cursor/canvas/sdk/dag-layout.d.ts
new file: skills-cursor/canvas/sdk/diff-view.d.ts
new file: skills-cursor/canvas/sdk/form-primitives.d.ts
new file: skills-cursor/canvas/sdk/hooks.d.ts
new file: skills-cursor/canvas/sdk/index.d.ts
new file: skills-cursor/canvas/sdk/swatch.d.ts
new file: skills-cursor/canvas/sdk/theme.d.ts
new file: skills-cursor/canvas/sdk/todo-list.d.ts
new file: skills-cursor/canvas/sdk/ui-primitives.d.ts
new file: skills-cursor/canvas/sdk/ui-primitives.test.d.ts
new file: skills-cursor/canvas/sdk/usage-bar.d.ts
new file: skills-cursor/create-hook/SKILL.md
new file: skills-cursor/create-rule/SKILL.md
new file: skills-cursor/create-skill/SKILL.md
new file: skills-cursor/create-subagent/SKILL.md
new file: skills-cursor/loop/SKILL.md
new file: skills-cursor/migrate-to-skills/SKILL.md
new file: skills-cursor/sdk/SKILL.md
new file: skills-cursor/shell/SKILL.md
new file: skills-cursor/split-to-prs/SKILL.md
new file: skills-cursor/statusline/SKILL.md
new file: skills-cursor/update-cli-config/SKILL.md
new file: skills-cursor/update-cursor-settings/SKILL.md
Changes not staged for commit:
(use "git add <file>..." to update what will be committed)
(use "git restore <file>..." to discard changes in working directory)
(commit or discard the untracked or modified content in submodules)
modified: plugins/cache/cursor-public/figma/a742f0a700a7772ff5ed85f7c9fc1dad5afa9fcc (untracked content)
modified: projects/Users-ray-Documents-project-www-slot-backend/terminals/1.txt
~/.cursor main +324 !1 git add .  base 18:16:22

View File

@@ -0,0 +1,5 @@
---
pid: 8330
cwd: /Users/ray/.cursor
---
~/.cursor  base 15:59:03

View File

@@ -0,0 +1,13 @@
---
pid: 17584
cwd: "/Users/ray/Documents/project/www/slot/backend"
command: "docker exec -w /app/www/slot/backend/slot_admin php82 php start.php restart 2>&1 | tail -15"
started_at: 2026-05-20T08:05:14.719Z
running_for_ms: 86398169
---
---
exit_code: unknown
elapsed_ms: 86400360
ended_at: 2026-05-21T08:05:15.079Z
---

View File

@@ -0,0 +1,15 @@
---
pid: 83022
cwd: "/Users/ray/Documents/project/www/slot/backend"
command: "chmod +x /Users/ray/Downloads/game_assets/vs20powerwild/_meta/download.sh && bash /Users/ray/Downloads/game_assets/vs20powerwild/_meta/download.sh"
started_at: 2026-05-20T06:48:34.155Z
running_for_ms: 120008
---
Summary ok=62 skip=0 fail=2 (log: /Users/ray/Downloads/game_assets/vs20powerwild/_meta/download.log, err: /Users/ray/Downloads/game_assets/vs20powerwild/_meta/download.err)
---
exit_code: 0
elapsed_ms: 122418
ended_at: 2026-05-20T06:50:36.573Z
---