SKOOR Risk Money movement. Skoored by AI.

Alert · reviewed · open

Transaction Risk Skoor 40 (review band) on a $582.68 ach transfer: returns.counterparty_prior_unauthorized.

Detector
skoor_review
Severity
medium
Program
Harbor Marketplace Payouts (simulated)
Subject
transfer acht_sim_harb_63czg4a54ua
Transfer
acht_sim_harb_63czg4a54ua · $582.68 · ach outgoing
Skoor at alert
40 review
Hard signal
no
Policy
policy-v1
Opened
2026-09-17 19:30Z
Closed
Decision clock
none · due — no clock
Escalated

Draft narrative

What happened. An ACH outgoing debit transfer of $582.68 (acht_sim_harb_63czg4a54ua) under the Harbor Marketplace Payouts program was flagged by the skoor_review detector with a Transaction Risk Skoor of 40, placing it in the review band. The triggering signal was one prior unauthorized ACH return associated with the counterparty. What the evidence shows. The transfer is already SETTLED with return code none, meaning this specific transaction was not itself returned. The single signal driving the score is 'returns.counterparty_prior_unauthorized' with a weight of 40, based on one prior unauthorized return for this counterparty, at a sample size of n=269 and confidence 0.88. The counterparty's country is unknown. The entity, Dune LLC 115, is VERIFIED, not high risk, not PEP, has no review reasons on file, and was last screened 2026-06-20. Program-level KRIs show ach_unauthorized_return_rate at 0 (n=14, ok) and ach_overall_return_rate at 0 (n=14, ok), indicating no elevated return activity at the program level currently. One KRI, manual_review_aging_hours, is in breach at 1438 hours (n=1), which reflects review-queue aging rather than anything specific to this transfer or counterparty. What was checked. Transfer status and return code, entity verification and screening status, program KRIs for return rates, high-risk share, and PEP flags, and prior dispositions for this alert. No prior dispositions exist for this alert. What is recommended. The transfer has already settled with no return on this transaction, and the entity is verified with no other risk flags. The alert rests on a single historical signal (one prior unauthorized return) with no corroborating pattern in current program-level return rates. There is nothing here indicating funds need to be held or that a broader pattern is emerging beyond the single signal. Close the alert. Separately, the manual_review_aging_hours KRI breach (1438 hours, n=1) should be noted for operational follow-up, as it is unrelated to this specific transfer's disposition.
Recommendation
close
Confidence
0.62
Model
claude-sonnet-5
Drafted
2026-09-17 19:30Z
Rationale
  • Transfer status is SETTLED with return code none, so no funds are in a holdable state; 'release' does not apply.
  • Single signal (one prior unauthorized return) drives the score; no corroborating signals or elevated program-level return rates (ach_unauthorized_return_rate=0, ach_overall_return_rate=0) support a broader pattern.
  • Entity is VERIFIED, not high risk, not PEP, with no open review reasons and recent screening (2026-06-20).
  • Counterparty country is unknown, which limits full risk assessment but is not itself a disqualifying factor given the entity's clean verification record.
  • manual_review_aging_hours KRI breach (1438 hours, n=1) is noted but reflects queue aging, not evidence specific to this transfer, so it does not change the disposition of this alert.
  • No prior dispositions exist to indicate recurring concern for this counterparty or entity.

Evidence

{
  "n": 269,
  "band": "review",
  "skoor": 40,
  "signals": [
    {
      "code": "returns.counterparty_prior_unauthorized",
      "detail": "1 prior unauthorized return(s)",
      "weight": 40
    }
  ],
  "confidence": 0.88,
  "routeReason": "detector not auto-closable"
}

Skoor signals

SignalWeightHardDetail
returns.counterparty_prior_unauthorized+401 prior unauthorized return(s)

Decision

Sign in as an operator to decide. Operator sign-in →

Dispositions

No disposition yet.

Actions

Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.

No actions requested.