Alert · reviewed · held
Counterparty Receiver 21 entered the hold band (Skoor 80, n=15): counterparty.unauthorized_returns, counterparty.unauthorized_rate, counterparty.return_rate, counterparty.new.
- Detector
- counterparty_hold
- Severity
- high
- Program
- Harbor Marketplace Payouts (simulated)
- Subject
- counterparty cpty_sim_harb_b3trqxlu3zb
- Transfer
- —
- Skoor at alert
- 80 hold
- Hard signal
- no
- Policy
- policy-v1
- Opened
- 2026-09-17 19:31Z
- Closed
- —
- Decision clock
- none · due — no clock
- Escalated
- —
Draft narrative
What happened. A high-severity counterparty_hold alert fired for counterparty cpty_sim_harb_b3trqxlu3zb on 2026-09-17. The counterparty entered the hold band with a skoor of 80 based on 15 observed transactions (n=15).
What the evidence shows. The counterparty drew 1 unauthorized return out of 15 transactions, producing an unauthorized rate of 1/15 (6.7%), which the system flags as above the network threshold (weight 40 for the unauthorized return itself, weight 15 for the rate signal). The overall return rate is also 1/15 (weight 15). The counterparty is new, first seen 0 days ago (weight 10). The detector marks hard_signal as false and reports a confidence of 0.308, indicating the underlying signal strength is modest. autoHold is true, meaning the system has already placed this counterparty on hold pending review; routeReason confirms the detector is not auto-closable.
What was checked. Program-level KRIs for Harbor Marketplace Payouts were reviewed for corroborating context. ach_unauthorized_return_rate is in breach (0.0097, n=411) and manual_review_aging_hours is in breach (1438 hours, n=7), both at the program level rather than tied specifically to this counterparty. pep_flagged_entities (1/30), high_risk_entity_share (0.067), and hold_aging_hours (1023.96 hours, n=5) are all in watch status. frozen_accounts, overdraft_events, manual_review_rate, stale_screening_share, reserve_coverage_ratio, sanctioned_country_transfers, and ach_administrative_return_rate are all ok. No prior dispositions exist for this counterparty. The sample size behind the alert itself (n=15) is small, and the single unauthorized return drives most of the skoor weight.
What is recommended. Given the counterparty is new with a thin transaction history (n=15) and a single unauthorized return is the primary driver of the hold, a person should review the underlying return before any further activity with this counterparty is cleared. The program-level breach metrics (ach_unauthorized_return_rate, manual_review_aging_hours) provide context but are not specific to this counterparty and do not by themselves establish a broader pattern tied to this alert. Hold is recommended pending manual review; escalation is not supported by the evidence available here since the pattern has not been shown to extend beyond this single counterparty.
- Recommendation
- hold
- Confidence
- 0.55
- Model
- claude-sonnet-5
- Drafted
- 2026-09-17 19:31Z
- Rationale
- Detector placed the counterparty in the hold band (skoor 80) with autoHold true, and routeReason states the detector is not auto-closable.
- The alert rests on a small sample (n=15) with a single unauthorized return driving 40 of the 80 skoor points.
- hard_signal is false and detector confidence is low (0.308), indicating the signal is suggestive but not conclusive.
- Counterparty is newly seen (0 days), so there is no transaction history to independently corroborate or rule out the unauthorized return.
- Program KRIs show related metrics (ach_unauthorized_return_rate, manual_review_aging_hours) in breach, but these are program-wide and not directly linked to this specific counterparty, so escalation to a broader pattern is not supported by the evidence in this alert.
- No prior dispositions exist to inform whether this counterparty has a history of similar issues.
Evidence
{
"n": 15,
"band": "hold",
"skoor": 80,
"signals": [
{
"code": "counterparty.unauthorized_returns",
"detail": "drew 1 unauthorized return(s)",
"weight": 40
},
{
"code": "counterparty.unauthorized_rate",
"detail": "unauthorized rate 1/15 above the network threshold",
"weight": 15
},
{
"code": "counterparty.return_rate",
"detail": "return rate 1/15",
"weight": 15
},
{
"code": "counterparty.new",
"detail": "first seen 0d ago",
"weight": 10
}
],
"version": "crs-v1",
"autoHold": true,
"confidence": 0.308,
"routeReason": "detector not auto-closable"
}
Decision
Sign in as an operator to decide. Operator sign-in →
Dispositions
No disposition yet.
Actions
Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.
No actions requested.