SKOOR Risk Money movement. Skoored by AI.

Alert · reviewed · open

Transaction Risk Skoor 30 (review band) on a $707.38 ach transfer: returns.counterparty_prior_any, returns.entity_rate_gt_threshold.

Detector
skoor_review
Severity
medium
Program
Harbor Marketplace Payouts (simulated)
Subject
transfer acht_sim_harb_b75kejly988
Transfer
acht_sim_harb_b75kejly988 · $707.38 · ach outgoing
Skoor at alert
30 review
Hard signal
no
Policy
policy-v1
Opened
2026-09-17 19:32Z
Closed
Decision clock
none · due — no clock
Escalated

Draft narrative

What happened. Alert 31dacb4c-c1b9-41fb-8bb3-4dbc415e63f5 fired on outgoing ACH credit acht_sim_harb_b75kejly988 for $707.38, opened 2026-09-17T19:32:10.402Z under detector skoor_review. The transfer settled on 2026-09-12T22:42:51.000Z with no return code recorded. What the evidence shows. The transfer scored Skoor 30 (review band, n=2085, confidence 1) on two signals: returns.counterparty_prior_any (1 prior return other than NSF, weight 15) and returns.entity_rate_gt_threshold (entity unauthorized return rate 1/26 = 3.85% of originated ACH debits in 60 days, weight 15). The entity, Kestrel Partners 122 (enti_sim_harb_2pfeu42a3wr), is a US business, verification VERIFIED, not flagged high risk, not PEP, with no open review reasons and screening current as of 2026-08-19. Program KRIs show ach_unauthorized_return_rate at 0.845% (n=828) in breach status and manual_review_aging_hours at 1438 hours (n=15) in breach status; other return-rate and volume KRIs (ach_overall_return_rate, ach_administrative_return_rate, velocity_vs_declared, counterparty_concentration_top1) are within ok/watch ranges. No prior dispositions exist for this alert. What was checked. Transfer status and return code, entity verification and screening status and risk flags, program-level KRI panel for related return-rate and aging metrics, and prior disposition history. What is recommended. The transfer is already settled, so no funds are available to hold or release. The entity-level unauthorized return signal is corroborated by a program-wide breach on the same ach_unauthorized_return_rate KRI and a breach on manual_review_aging_hours, which together suggest this entity's return pattern may be part of a broader program-level trend rather than an isolated event. This warrants a person reviewing the entity's return history across the program before closing, rather than an automatic close.
Recommendation
escalate
Confidence
0.55
Model
claude-sonnet-5
Drafted
2026-09-17 19:32Z
Rationale
  • Transfer status is SETTLED with no return code, so hold/release actions do not apply.
  • Entity has one prior non-NSF return and a 3.85% unauthorized return rate (1/26), both used as scoring signals at weight 15 each, pushing the transfer into the review band.
  • Program KRI ach_unauthorized_return_rate is in breach status (0.845%, n=828), and manual_review_aging_hours is also in breach (1438 hours, n=15), indicating this alert may not be isolated.
  • Entity itself is VERIFIED, not high risk, not PEP, with no open review reasons, which limits the severity of this single alert on its own.
  • No prior dispositions exist to indicate this entity or pattern has already been reviewed.

Evidence

{
  "n": 2085,
  "band": "review",
  "skoor": 30,
  "signals": [
    {
      "code": "returns.counterparty_prior_any",
      "detail": "1 prior return(s) other than NSF",
      "weight": 15
    },
    {
      "code": "returns.entity_rate_gt_threshold",
      "detail": "entity unauthorized return rate 1/26 originated ACH debits in 60d",
      "weight": 15
    }
  ],
  "confidence": 1,
  "routeReason": "detector not auto-closable"
}

Skoor signals

SignalWeightHardDetail
returns.counterparty_prior_any+151 prior return(s) other than NSF
returns.entity_rate_gt_threshold+15entity unauthorized return rate 1/26 originated ACH debits in 60d

Decision

Sign in as an operator to decide. Operator sign-in →

Dispositions

No disposition yet.

Actions

Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.

No actions requested.