Alert · reviewed · open
Transaction Risk Skoor 30 (review band) on a $564.69 ach transfer: returns.counterparty_prior_any, returns.entity_rate_gt_threshold.
- Detector
- skoor_review
- Severity
- medium
- Program
- Harbor Marketplace Payouts (simulated)
- Subject
- transfer acht_sim_harb_6nxvn0ng8jg
- Transfer
- acht_sim_harb_6nxvn0ng8jg · $564.69 · ach outgoing
- Skoor at alert
- 30 review
- Hard signal
- no
- Policy
- policy-v1
- Opened
- 2026-09-17 19:31Z
- Closed
- —
- Decision clock
- none · due — no clock
- Escalated
- —
Draft narrative
What happened. A $564.69 outgoing ACH debit transfer (acht_sim_harb_6nxvn0ng8jg) from Juniper LLC 121 under the Harbor Marketplace Payouts program was scored 30 (review band) by the skoor_review detector on two signals: a prior non-NSF return on the counterparty and an entity ACH unauthorized-return rate above threshold (1 of 41 originated debits in 60 days). The transfer has already settled with no return code recorded.
What the evidence shows. The transfer settled without a return; the risk score is driven by a single prior counterparty return and one prior unauthorized-type return out of 41 originated ACH debits (2.4%) for this entity in the trailing 60 days. Hard_signal is false and the alert routed to review only because the detector is not auto-closable, not because of an independent stop condition. The entity (Juniper LLC 121) is VERIFIED, not high risk, not PEP, has no open review reasons, and was screened as recently as 2026-09-01. Program-level KRIs show ach_unauthorized_return_rate at 0.85% (breach status) and manual_review_aging_hours in breach, but these are program-wide metrics with much larger denominators (n=709, n=11) and are not tied specifically to this entity or transfer.
What was checked. Transfer status and return code, entity verification and screening status, program KRI panel for corroborating patterns (frozen accounts, sanctioned-country transfers, verification denial rate, counterparty concentration), and prior dispositions on this alert (none found).
What is recommended. Close the alert. The transfer has already settled with no return, the entity is verified with no other risk flags, and the triggering signals rest on a single prior return event against a small sample (1/41). There is no pending transfer to hold or release, and no evidence here indicates a broader pattern warranting escalation. If the entity's unauthorized-return count increases in subsequent 60-day windows, a person should revisit.
- Recommendation
- close
- Confidence
- 0.62
- Model
- claude-sonnet-5
- Drafted
- 2026-09-17 19:32Z
- Rationale
- Transfer status is SETTLED with no return code; there is no fund movement to hold or release.
- Skoor is 30 (review band, not high) and hard_signal is false, indicating no independent stop condition was triggered.
- Entity is VERIFIED, not high risk, not PEP, with no open review reasons and recent screening (2026-09-01).
- Triggering signals are based on one prior non-NSF return and a 1/41 (2.4%) entity unauthorized-return rate, a thin sample.
- Program KRI breaches (ach_unauthorized_return_rate, manual_review_aging_hours) are portfolio-wide metrics, not specific evidence of an issue with this entity or transfer.
- No prior dispositions exist on this alert, and no other program signals (sanctioned-country transfers, frozen accounts, concentration) indicate a broader pattern.
Evidence
{
"n": 1818,
"band": "review",
"skoor": 30,
"signals": [
{
"code": "returns.counterparty_prior_any",
"detail": "1 prior return(s) other than NSF",
"weight": 15
},
{
"code": "returns.entity_rate_gt_threshold",
"detail": "entity unauthorized return rate 1/41 originated ACH debits in 60d",
"weight": 15
}
],
"confidence": 1,
"routeReason": "detector not auto-closable"
}
Skoor signals
| Signal | Weight | Hard | Detail |
|---|---|---|---|
| returns.counterparty_prior_any | +15 | 1 prior return(s) other than NSF | |
| returns.entity_rate_gt_threshold | +15 | entity unauthorized return rate 2/41 originated ACH debits in 60d |
Decision
Sign in as an operator to decide. Operator sign-in →
Dispositions
No disposition yet.
Actions
Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.
No actions requested.