Alert · reviewed · open
Activity on an entity flagged by screening (PEP status no, high risk).
- Detector
- sanctions_or_pep
- Severity
- high
- Program
- Harbor Marketplace Payouts (simulated)
- Subject
- entity enti_sim_harb_skonrvy3x6
- Transfer
- acht_sim_harb_b77zwczf81n · $204.13 · ach outgoing
- Skoor at alert
- 20 clear
- Hard signal
- no
- Policy
- policy-v1
- Opened
- 2026-09-17 19:31Z
- Closed
- —
- Decision clock
- none · due — no clock
- Escalated
- —
Draft narrative
What happened. Alert 313fe2c8-c5d5-4a2b-a7cc-d43990c77fa7 fired on entity enti_sim_harb_skonrvy3x6 under the sanctions_or_pep detector after a settled ACH outgoing debit of $204.13 on transfer acht_sim_harb_b77zwczf81n. The route reason states this detector is always sent to review, independent of score.
What the evidence shows. The entity is a verified US business marked high risk by screening, with PEP status no and no review reasons listed. Last screening was 2026-08-27, three weeks before the alert opened. The transfer-level skoor is 20 in the clear band with n=1619 and confidence 1, and hard_signal is false. The only contributing signal is entity.high_risk at weight 20. The transfer settled with no return code, indicating no rail-level rejection or dispute. Counterparty country is unknown but this is not one of the signals driving the alert.
What was checked. Reviewed the entity record for PEP status, verification state, and review reasons: all clear except the high-risk flag itself. Reviewed the transfer for status, return code, and amount relative to declared program volume: settled, no return, and $204.13 is immaterial against a $4,000,000.00 declared monthly volume. Reviewed program KRIs for related patterns: pep_flagged_entities and high_risk_entity_share are at watch, and manual_review_aging_hours and ach_unauthorized_return_rate are at breach, but none of these are specific to this entity or this transfer, and no prior dispositions exist on this entity to indicate a repeat pattern.
What is recommended. Close the alert. The evidence shows a routine review triggered by the detector's standing rule to always review high-risk entities, not by an elevated score or a hard signal. The entity is verified, not PEP, and has no other review reasons. The transfer settled cleanly with no return. A person should still be aware of the program-level KRI breaches (manual_review_aging_hours, ach_unauthorized_return_rate) but those are program-wide conditions, not specific to this alert, and do not change the disposition of this individual alert.
- Recommendation
- close
- Confidence
- 0.78
- Model
- claude-sonnet-5
- Drafted
- 2026-09-17 19:31Z
- Rationale
- Transfer skoor is 20, band clear, n=1619, confidence 1, hard_signal false.
- Only contributing signal is entity.high_risk at weight 20; no PEP, no other review reasons.
- Entity is VERIFIED, last screened 2026-08-27, 21 days before alert open, no stale screening flag at program level (stale_screening_share=0).
- Transfer status is SETTLED with return code none; amount $204.13 is small relative to declared $4,000,000.00 monthly volume.
- Route reason is 'detector always reviewed', meaning this alert would fire regardless of risk level given the entity's high-risk flag alone.
- Program KRIs show watch/breach items (pep_flagged_entities, high_risk_entity_share, manual_review_aging_hours, ach_unauthorized_return_rate) but these are aggregate measures, not tied to this specific entity or transfer, and no prior dispositions exist to suggest a pattern for this entity.
Evidence
{
"n": 1619,
"band": "clear",
"skoor": 20,
"signals": [
{
"code": "entity.high_risk",
"detail": "entity marked high risk by screening",
"weight": 20
}
],
"routeReason": "detector always reviewed"
}
Skoor signals
| Signal | Weight | Hard | Detail |
|---|---|---|---|
| entity.high_risk | +20 | entity marked high risk by screening |
Decision
Sign in as an operator to decide. Operator sign-in →
Dispositions
No disposition yet.
Actions
Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.
No actions requested.