Alert · reviewed · open
Activity on an entity flagged by screening (PEP status no, high risk).
- Detector
- sanctions_or_pep
- Severity
- high
- Program
- Harbor Marketplace Payouts (simulated)
- Subject
- entity enti_sim_harb_skonrvy3x6
- Transfer
- acht_sim_harb_1hjs04iv8ii · $207.83 · ach outgoing
- Skoor at alert
- 20 clear
- Hard signal
- no
- Policy
- policy-v1
- Opened
- 2026-09-17 19:31Z
- Closed
- —
- Decision clock
- none · due — no clock
- Escalated
- —
Draft narrative
What happened. Alert 05c0086e-f918-4432-8d4f-9141cc44d505 fired on entity enti_sim_harb_skonrvy3x6 under the sanctions_or_pep detector after screening flagged the entity as high risk. The detector routes to review on every hit regardless of score, per routeReason 'detector always reviewed'. The alert was opened 2026-09-17T19:31:46.176Z and tied to one ACH outgoing credit transfer of $207.83 USD (acht_sim_harb_1hjs04iv8ii), settled, with no return code.
What the evidence shows. The transfer-level skoor is 20, band clear, hard_signal false, driven solely by the entity.high_risk signal (weight 20) out of a population of n=1803. The entity record shows verification VERIFIED, pep no, high_risk true, no review reasons listed, and last screened 2026-08-27T13:10:35.000Z, which is within 21 days of alert open and consistent with stale_screening_share=0 at the program level. The transfer itself settled with no return code, so there is no indication of a failed or reversed payment. Program KRIs show most metrics at ok, with pep_flagged_entities, high_risk_entity_share, and hold_aging_hours at watch, and manual_review_aging_hours and ach_unauthorized_return_rate at breach. These KRIs are program-wide and not specific to this entity or transfer; nothing in the entity or transfer record ties this alert to the breached metrics.
What was checked. Reviewed the alert signal (entity.high_risk only, no PEP hit, no sanctioned-country transfers), the transfer record (settled, no return code, small dollar amount relative to declared program volume), the entity record (verified, screened recently, no review reasons), and program KRIs (checked for any direct link to this entity or transfer; none found in the evidence provided). No prior dispositions exist for this alert.
What is recommended. Close the alert. The entity is verified, screened within a normal window, and carries no PEP or sanctions match beyond a static high-risk flag. The associated transfer settled cleanly with no return code. The program-level KRI breaches (manual_review_aging_hours, ach_unauthorized_return_rate) are not linked to this entity or transfer in the evidence and should be tracked separately as program health items, not as grounds to hold this specific alert. A person should confirm no unlisted review reasons exist before closing.
- Recommendation
- close
- Confidence
- 0.72
- Model
- claude-sonnet-5
- Drafted
- 2026-09-17 19:32Z
- Rationale
- Skoor band is clear (20) and hard_signal is false; the only contributing signal is entity.high_risk, a static screening attribute, not a transaction-based anomaly.
- Entity is VERIFIED, pep no, and has no review reasons listed; last screening date is recent (2026-08-27), consistent with stale_screening_share=0.
- Transfer is SETTLED with no return code and a modest dollar amount ($207.83) relative to declared $4,000,000.00 monthly program volume.
- Program KRI breaches (manual_review_aging_hours, ach_unauthorized_return_rate) are aggregate metrics with no evidentiary link to this specific entity or transfer.
- Confidence is not higher because the evidence set is thin: no narrative on why the entity was marked high risk, and no historical transaction pattern for this entity beyond the single cited transfer.
Evidence
{
"n": 1803,
"band": "clear",
"skoor": 20,
"signals": [
{
"code": "entity.high_risk",
"detail": "entity marked high risk by screening",
"weight": 20
}
],
"routeReason": "detector always reviewed"
}
Skoor signals
| Signal | Weight | Hard | Detail |
|---|---|---|---|
| entity.high_risk | +20 | entity marked high risk by screening |
Decision
Sign in as an operator to decide. Operator sign-in →
Dispositions
No disposition yet.
Actions
Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.
No actions requested.