SKOOR Risk Money movement. Skoored by AI.

Alert · reviewed · held

Counterparty Receiver 37 entered the hold band (Skoor 100, n=20): counterparty.unauthorized_returns, counterparty.unauthorized_rate, counterparty.return_rate, counterparty.hold_share, counterparty.review_share, counterparty.new.

Detector
counterparty_hold
Severity
high
Program
Harbor Marketplace Payouts (simulated)
Subject
counterparty cpty_sim_harb_1fd2i6t54k3
Transfer
Skoor at alert
100 hold
Hard signal
no
Policy
policy-v1
Opened
2026-09-17 19:32Z
Closed
Decision clock
none · due — no clock
Escalated

Draft narrative

What happened. Counterparty cpty_sim_harb_1fd2i6t54k3 (Harbor Marketplace Payouts, simulated) was scored by the counterparty_hold detector and entered the hold band with a Skoor of 100 on a sample of 20 scored transfers. The alert auto-opened into the hold band (autoHold true) and was routed for review because the detector is not auto-closable. What the evidence shows. Of 20 scored transfers, 2 were unauthorized returns (weight 40) and the unauthorized rate of 2/20 is above the network threshold (weight 15). The overall return rate is 3/20 (15%, weight 15). 10% of this counterparty's scored transfers fall in the hold band and 30% in the review band (weights 25 and 10). The counterparty was first seen 0 days ago (weight 10), so all history is recent. The detector's own confidence is low (0.38) and hard_signal is false, meaning no single deterministic rule fired; the score is a composite of several moderate signals on a small sample (n=20). Program-level KRIs show ach_unauthorized_return_rate at 0.90% (n=890) flagged as breach and manual_review_aging_hours at 1438 hours (n=18) flagged as breach, both program-wide conditions rather than counterparty-specific findings. No frozen accounts, no sanctioned-country transfers, and counterparty_concentration_top1 is 7.1%, all within normal range. What was checked. Reviewed the alert evidence block (signals, weights, band, skoor, n), the detector's stated confidence and hard_signal flag, the program KRI panel for corroborating or contradicting portfolio-level conditions, and prior dispositions for this alert (none on file). What is recommended. Hold further transfers to or from this counterparty pending manual review. The sample size is small (n=20) and the counterparty is newly seen, so the pattern is not yet established at scale, but two unauthorized returns and a 15% return rate on a new counterparty are sufficient reason to keep transfers from moving before a person examines the underlying transactions. This is a single-counterparty finding; the program-wide ach_unauthorized_return_rate breach is a separate KRI condition and does not by itself establish a broader pattern tied to this alert, so escalation is not recommended at this time.
Recommendation
hold
Confidence
0.60
Model
claude-sonnet-5
Drafted
2026-09-17 19:33Z
Rationale
  • Skoor 100 in the hold band with autoHold true indicates the system already froze movement pending review; nothing in the evidence supports overriding that before a person looks.
  • 2 unauthorized returns out of 20 transfers (10%) is a material signal for a counterparty first seen 0 days ago.
  • Detector confidence is low (0.38) and hard_signal is false, meaning this is a composite score rather than a single deterministic rule, which argues against outright closure but also against escalating past the single alert without more data.
  • Sample size (n=20) is small; a person should confirm whether the unauthorized returns reflect a genuine pattern or isolated incidents before any funds move.
  • Program KRI breaches (ach_unauthorized_return_rate, manual_review_aging_hours) are portfolio-wide and not directly tied to this counterparty's evidence, so they support caution but do not justify escalation on this alert alone.

Evidence

{
  "n": 20,
  "band": "hold",
  "skoor": 100,
  "signals": [
    {
      "code": "counterparty.unauthorized_returns",
      "detail": "drew 2 unauthorized return(s)",
      "weight": 40
    },
    {
      "code": "counterparty.unauthorized_rate",
      "detail": "unauthorized rate 2/20 above the network threshold",
      "weight": 15
    },
    {
      "code": "counterparty.return_rate",
      "detail": "return rate 3/20",
      "weight": 15
    },
    {
      "code": "counterparty.hold_share",
      "detail": "10% of scored transfers in the hold band",
      "weight": 25
    },
    {
      "code": "counterparty.review_share",
      "detail": "30% in the review band",
      "weight": 10
    },
    {
      "code": "counterparty.new",
      "detail": "first seen 0d ago",
      "weight": 10
    }
  ],
  "version": "crs-v1",
  "autoHold": true,
  "confidence": 0.38,
  "routeReason": "detector not auto-closable"
}

Decision

Sign in as an operator to decide. Operator sign-in →

Dispositions

No disposition yet.

Actions

Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.

No actions requested.