SKOOR Risk Money movement. Skoored by AI.

Alert · reviewed · held

Counterparty Receiver 21 entered the hold band (Skoor 80, n=15): counterparty.unauthorized_returns, counterparty.unauthorized_rate, counterparty.return_rate, counterparty.new.

Detector
counterparty_hold
Severity
high
Program
Harbor Marketplace Payouts (simulated)
Subject
counterparty cpty_sim_harb_b3trqxlu3zb
Transfer
Skoor at alert
80 hold
Hard signal
no
Policy
policy-v1
Opened
2026-09-17 19:31Z
Closed
Decision clock
none · due — no clock
Escalated

Draft narrative

What happened. A high-severity counterparty_hold alert fired for counterparty cpty_sim_harb_b3trqxlu3zb on 2026-09-17. The counterparty entered the hold band with a skoor of 80 based on 15 observed transactions (n=15). What the evidence shows. The counterparty drew 1 unauthorized return out of 15 transactions, producing an unauthorized rate of 1/15 (6.7%), which the system flags as above the network threshold (weight 40 for the unauthorized return itself, weight 15 for the rate signal). The overall return rate is also 1/15 (weight 15). The counterparty is new, first seen 0 days ago (weight 10). The detector marks hard_signal as false and reports a confidence of 0.308, indicating the underlying signal strength is modest. autoHold is true, meaning the system has already placed this counterparty on hold pending review; routeReason confirms the detector is not auto-closable. What was checked. Program-level KRIs for Harbor Marketplace Payouts were reviewed for corroborating context. ach_unauthorized_return_rate is in breach (0.0097, n=411) and manual_review_aging_hours is in breach (1438 hours, n=7), both at the program level rather than tied specifically to this counterparty. pep_flagged_entities (1/30), high_risk_entity_share (0.067), and hold_aging_hours (1023.96 hours, n=5) are all in watch status. frozen_accounts, overdraft_events, manual_review_rate, stale_screening_share, reserve_coverage_ratio, sanctioned_country_transfers, and ach_administrative_return_rate are all ok. No prior dispositions exist for this counterparty. The sample size behind the alert itself (n=15) is small, and the single unauthorized return drives most of the skoor weight. What is recommended. Given the counterparty is new with a thin transaction history (n=15) and a single unauthorized return is the primary driver of the hold, a person should review the underlying return before any further activity with this counterparty is cleared. The program-level breach metrics (ach_unauthorized_return_rate, manual_review_aging_hours) provide context but are not specific to this counterparty and do not by themselves establish a broader pattern tied to this alert. Hold is recommended pending manual review; escalation is not supported by the evidence available here since the pattern has not been shown to extend beyond this single counterparty.
Recommendation
hold
Confidence
0.55
Model
claude-sonnet-5
Drafted
2026-09-17 19:31Z
Rationale
  • Detector placed the counterparty in the hold band (skoor 80) with autoHold true, and routeReason states the detector is not auto-closable.
  • The alert rests on a small sample (n=15) with a single unauthorized return driving 40 of the 80 skoor points.
  • hard_signal is false and detector confidence is low (0.308), indicating the signal is suggestive but not conclusive.
  • Counterparty is newly seen (0 days), so there is no transaction history to independently corroborate or rule out the unauthorized return.
  • Program KRIs show related metrics (ach_unauthorized_return_rate, manual_review_aging_hours) in breach, but these are program-wide and not directly linked to this specific counterparty, so escalation to a broader pattern is not supported by the evidence in this alert.
  • No prior dispositions exist to inform whether this counterparty has a history of similar issues.

Evidence

{
  "n": 15,
  "band": "hold",
  "skoor": 80,
  "signals": [
    {
      "code": "counterparty.unauthorized_returns",
      "detail": "drew 1 unauthorized return(s)",
      "weight": 40
    },
    {
      "code": "counterparty.unauthorized_rate",
      "detail": "unauthorized rate 1/15 above the network threshold",
      "weight": 15
    },
    {
      "code": "counterparty.return_rate",
      "detail": "return rate 1/15",
      "weight": 15
    },
    {
      "code": "counterparty.new",
      "detail": "first seen 0d ago",
      "weight": 10
    }
  ],
  "version": "crs-v1",
  "autoHold": true,
  "confidence": 0.308,
  "routeReason": "detector not auto-closable"
}

Decision

Sign in as an operator to decide. Operator sign-in →

Dispositions

No disposition yet.

Actions

Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.

No actions requested.