Alert · reviewed · open
Transaction Risk Skoor 40 (review band) on a $582.68 ach transfer: returns.counterparty_prior_unauthorized.
- Detector
- skoor_review
- Severity
- medium
- Program
- Harbor Marketplace Payouts (simulated)
- Subject
- transfer acht_sim_harb_63czg4a54ua
- Transfer
- acht_sim_harb_63czg4a54ua · $582.68 · ach outgoing
- Skoor at alert
- 40 review
- Hard signal
- no
- Policy
- policy-v1
- Opened
- 2026-09-17 19:30Z
- Closed
- —
- Decision clock
- none · due — no clock
- Escalated
- —
Draft narrative
What happened. An ACH outgoing debit transfer of $582.68 (acht_sim_harb_63czg4a54ua) under the Harbor Marketplace Payouts program was flagged by the skoor_review detector with a Transaction Risk Skoor of 40, placing it in the review band. The triggering signal was one prior unauthorized ACH return associated with the counterparty.
What the evidence shows. The transfer is already SETTLED with return code none, meaning this specific transaction was not itself returned. The single signal driving the score is 'returns.counterparty_prior_unauthorized' with a weight of 40, based on one prior unauthorized return for this counterparty, at a sample size of n=269 and confidence 0.88. The counterparty's country is unknown. The entity, Dune LLC 115, is VERIFIED, not high risk, not PEP, has no review reasons on file, and was last screened 2026-06-20. Program-level KRIs show ach_unauthorized_return_rate at 0 (n=14, ok) and ach_overall_return_rate at 0 (n=14, ok), indicating no elevated return activity at the program level currently. One KRI, manual_review_aging_hours, is in breach at 1438 hours (n=1), which reflects review-queue aging rather than anything specific to this transfer or counterparty.
What was checked. Transfer status and return code, entity verification and screening status, program KRIs for return rates, high-risk share, and PEP flags, and prior dispositions for this alert. No prior dispositions exist for this alert.
What is recommended. The transfer has already settled with no return on this transaction, and the entity is verified with no other risk flags. The alert rests on a single historical signal (one prior unauthorized return) with no corroborating pattern in current program-level return rates. There is nothing here indicating funds need to be held or that a broader pattern is emerging beyond the single signal. Close the alert. Separately, the manual_review_aging_hours KRI breach (1438 hours, n=1) should be noted for operational follow-up, as it is unrelated to this specific transfer's disposition.
- Recommendation
- close
- Confidence
- 0.62
- Model
- claude-sonnet-5
- Drafted
- 2026-09-17 19:30Z
- Rationale
- Transfer status is SETTLED with return code none, so no funds are in a holdable state; 'release' does not apply.
- Single signal (one prior unauthorized return) drives the score; no corroborating signals or elevated program-level return rates (ach_unauthorized_return_rate=0, ach_overall_return_rate=0) support a broader pattern.
- Entity is VERIFIED, not high risk, not PEP, with no open review reasons and recent screening (2026-06-20).
- Counterparty country is unknown, which limits full risk assessment but is not itself a disqualifying factor given the entity's clean verification record.
- manual_review_aging_hours KRI breach (1438 hours, n=1) is noted but reflects queue aging, not evidence specific to this transfer, so it does not change the disposition of this alert.
- No prior dispositions exist to indicate recurring concern for this counterparty or entity.
Evidence
{
"n": 269,
"band": "review",
"skoor": 40,
"signals": [
{
"code": "returns.counterparty_prior_unauthorized",
"detail": "1 prior unauthorized return(s)",
"weight": 40
}
],
"confidence": 0.88,
"routeReason": "detector not auto-closable"
}
Skoor signals
| Signal | Weight | Hard | Detail |
|---|---|---|---|
| returns.counterparty_prior_unauthorized | +40 | 1 prior unauthorized return(s) |
Decision
Sign in as an operator to decide. Operator sign-in →
Dispositions
No disposition yet.
Actions
Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.
No actions requested.