Alert · reviewed · open
Transaction Risk Skoor 30 (review band) on a $707.38 ach transfer: returns.counterparty_prior_any, returns.entity_rate_gt_threshold.
- Detector
- skoor_review
- Severity
- medium
- Program
- Harbor Marketplace Payouts (simulated)
- Subject
- transfer acht_sim_harb_b75kejly988
- Transfer
- acht_sim_harb_b75kejly988 · $707.38 · ach outgoing
- Skoor at alert
- 30 review
- Hard signal
- no
- Policy
- policy-v1
- Opened
- 2026-09-17 19:32Z
- Closed
- —
- Decision clock
- none · due — no clock
- Escalated
- —
Draft narrative
What happened. Alert 31dacb4c-c1b9-41fb-8bb3-4dbc415e63f5 fired on outgoing ACH credit acht_sim_harb_b75kejly988 for $707.38, opened 2026-09-17T19:32:10.402Z under detector skoor_review. The transfer settled on 2026-09-12T22:42:51.000Z with no return code recorded.
What the evidence shows. The transfer scored Skoor 30 (review band, n=2085, confidence 1) on two signals: returns.counterparty_prior_any (1 prior return other than NSF, weight 15) and returns.entity_rate_gt_threshold (entity unauthorized return rate 1/26 = 3.85% of originated ACH debits in 60 days, weight 15). The entity, Kestrel Partners 122 (enti_sim_harb_2pfeu42a3wr), is a US business, verification VERIFIED, not flagged high risk, not PEP, with no open review reasons and screening current as of 2026-08-19. Program KRIs show ach_unauthorized_return_rate at 0.845% (n=828) in breach status and manual_review_aging_hours at 1438 hours (n=15) in breach status; other return-rate and volume KRIs (ach_overall_return_rate, ach_administrative_return_rate, velocity_vs_declared, counterparty_concentration_top1) are within ok/watch ranges. No prior dispositions exist for this alert.
What was checked. Transfer status and return code, entity verification and screening status and risk flags, program-level KRI panel for related return-rate and aging metrics, and prior disposition history.
What is recommended. The transfer is already settled, so no funds are available to hold or release. The entity-level unauthorized return signal is corroborated by a program-wide breach on the same ach_unauthorized_return_rate KRI and a breach on manual_review_aging_hours, which together suggest this entity's return pattern may be part of a broader program-level trend rather than an isolated event. This warrants a person reviewing the entity's return history across the program before closing, rather than an automatic close.
- Recommendation
- escalate
- Confidence
- 0.55
- Model
- claude-sonnet-5
- Drafted
- 2026-09-17 19:32Z
- Rationale
- Transfer status is SETTLED with no return code, so hold/release actions do not apply.
- Entity has one prior non-NSF return and a 3.85% unauthorized return rate (1/26), both used as scoring signals at weight 15 each, pushing the transfer into the review band.
- Program KRI ach_unauthorized_return_rate is in breach status (0.845%, n=828), and manual_review_aging_hours is also in breach (1438 hours, n=15), indicating this alert may not be isolated.
- Entity itself is VERIFIED, not high risk, not PEP, with no open review reasons, which limits the severity of this single alert on its own.
- No prior dispositions exist to indicate this entity or pattern has already been reviewed.
Evidence
{
"n": 2085,
"band": "review",
"skoor": 30,
"signals": [
{
"code": "returns.counterparty_prior_any",
"detail": "1 prior return(s) other than NSF",
"weight": 15
},
{
"code": "returns.entity_rate_gt_threshold",
"detail": "entity unauthorized return rate 1/26 originated ACH debits in 60d",
"weight": 15
}
],
"confidence": 1,
"routeReason": "detector not auto-closable"
}
Skoor signals
| Signal | Weight | Hard | Detail |
|---|---|---|---|
| returns.counterparty_prior_any | +15 | 1 prior return(s) other than NSF | |
| returns.entity_rate_gt_threshold | +15 | entity unauthorized return rate 1/26 originated ACH debits in 60d |
Decision
Sign in as an operator to decide. Operator sign-in →
Dispositions
No disposition yet.
Actions
Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.
No actions requested.