Our fraud team wants a rule: alert whenever the same card has 3 or more transactions within 10 minutes. For example, card 5566 transacted at 10:00, 10:04, 10:09 and 10:30. How would you implement this in SQL? After launch, the rule flags 2% of cards daily, but the actual fraud rate is only 0.1%. How do you interpret that and how would you tune it?