Alert · reviewed · held
Entity Denied Origin 2 entered the hold band (Skoor 85, n=1): entity.denied, entity.hold_share.
- Detector
- entity_hold
- Severity
- high
- Program
- Meridian Remit (simulated)
- Subject
- entity enti_sim_meri_3qusu9s29pg
- Transfer
- —
- Skoor at alert
- 85 hold
- Hard signal
- yes
- Policy
- policy-v1
- Opened
- 2026-09-17 19:31Z
- Closed
- —
- Decision clock
- none · due — no clock
- Escalated
- —
Draft narrative
What happened. Entity enti_sim_meri_3qusu9s29pg ("Denied Origin 2") in program Meridian Remit (simulated) triggered an entity_hold alert. Skoor reached 85, placing it in the hold band, driven by an entity.denied signal (weight 60, hard signal true) and an entity.hold_share signal (weight 25) showing 100% of the entity's scored transfers (n=1) fall in the hold band.
What the evidence shows. The entity record shows verification status DENIED with review reasons listed as sanctions_match, last screened 2026-06-24. High risk flag is false and pep flag is no, but the denied verification combined with a sanctions_match reason is the basis for the hard signal. The hold_share signal is based on only one scored transfer (n=1), so the 100% figure reflects a single observation rather than a pattern across multiple transfers. Alert-level confidence is reported as 0.412, which is low, though the hard signal (entity.denied) is what drove the autoHold and the routeReason "hard signal."
What was checked. Reviewed the alert evidence block, the entity record, the program declaration (volume, rails, countries), and program KRIs. No prior dispositions exist for this entity. Program KRIs show several items in breach (reserve_coverage_ratio, manual_review_aging_hours, ach_unauthorized_return_rate) and two in watch (hold_aging_hours, pep_flagged_entities), but none of these KRIs are entity-specific to enti_sim_meri_3qusu9s29pg, and the alert itself is based on a single scored transfer (n=1), so there is no evidence here of a multi-entity pattern tied to this specific alert.
What is recommended. Hold. Verification DENIED with a sanctions_match review reason and a hard signal is sufficient basis to keep this entity's transfers from moving until a person confirms the sanctions screening result and verification denial are correctly recorded and resolved. This is not a release scenario since no specific transfer is described as already held pending release, and it is not an escalation absent evidence of a broader pattern beyond this single entity (n=1).
- Recommendation
- hold
- Confidence
- 0.62
- Model
- claude-sonnet-5
- Drafted
- 2026-09-17 19:31Z
- Rationale
- entity.denied is a hard signal (weight 60) tied to verification DENIED and review reason sanctions_match
- Skoor 85 places the entity in the hold band with autoHold true and routeReason "hard signal"
- entity.hold_share signal is based on n=1 scored transfer, so it reflects a single data point, not a confirmed pattern
- Alert-level confidence field is only 0.412, indicating the scoring model itself has limited certainty despite the hard signal
- Program KRIs show unrelated breaches (reserve_coverage_ratio, manual_review_aging_hours, ach_unauthorized_return_rate) that are not directly tied to this entity and do not by themselves support escalation of this specific alert
- No prior dispositions exist for this entity, so there is no history to indicate this is part of a larger recurring issue
Evidence
{
"n": 1,
"band": "hold",
"skoor": 85,
"signals": [
{
"code": "entity.denied",
"hard": true,
"detail": "verification DENIED",
"weight": 60
},
{
"code": "entity.hold_share",
"detail": "100% of scored transfers in the hold band",
"weight": 25
}
],
"version": "ers-v1",
"autoHold": true,
"confidence": 0.412,
"routeReason": "hard signal"
}
Decision
Sign in as an operator to decide. Operator sign-in →
Dispositions
No disposition yet.
Actions
Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.
No actions requested.