SKOOR Risk Money movement. Skoored by AI.

Alert · reviewed · open

First transfer to a new counterparty, $932.90, above the program's 95th percentile.

Detector
first_time_counterparty_large
Severity
medium
Program
Harbor Marketplace Payouts (simulated)
Subject
transfer acht_sim_harb_2jd51y517gv
Transfer
acht_sim_harb_2jd51y517gv · $932.90 · ach outgoing
Skoor at alert
40 review
Hard signal
no
Policy
policy-v1
Opened
2026-09-17 19:31Z
Closed
Decision clock
none · due — no clock
Escalated

Draft narrative

What happened. Alert fired on a first-time counterparty transfer of $932.90 via ACH credit, flagged because the amount exceeds the program's 95th percentile ($849.40) for new counterparties. The transfer has already settled. What the evidence shows. The alert evidence lists two signals totaling a score of 25 (counterparty.first_time +10, counterparty.first_time_and_large +15), but the transfer-level skoor record shows a third signal, returns.entity_rate_gt_threshold (+15), bringing the total to 40 and placing it in the review band. This third signal is not explained in the alert summary or entity record. The transfer itself settled cleanly with no return code. The entity, Juniper LLC 19, is verified, not high-risk, not PEP, screened as of 2026-07-06, with no review reasons on file. Program KRIs show ach_unauthorized_return_rate in breach status (0.0118, n=507) and manual_review_aging_hours in breach (1438 hours, n=9), both program-wide conditions rather than specific to this transfer or entity. What was checked. Transfer status and return code, entity verification and risk flags, program KRI panel, and prior dispositions (none on file). The counterparty's country is listed as unknown, which was noted but is not flagged as a program risk given rails are US-only ACH/realtime. What is recommended. The transfer has already settled with no return, and the entity carries no adverse flags. However, the unexplained returns.entity_rate_gt_threshold signal on the transfer skoor record, combined with the program's breach-level ach_unauthorized_return_rate KRI, means the entity's return history was not fully verifiable from the evidence provided. A person should confirm this entity's individual return rate before closing, since the alert evidence is incomplete on this point.
Recommendation
hold
Confidence
0.45
Model
claude-sonnet-5
Drafted
2026-09-17 19:31Z
Rationale
  • Transfer is already settled with no return code, so no funds-movement action is pending, but this does not resolve the unexplained third scoring signal.
  • The returns.entity_rate_gt_threshold signal appears on the transfer skoor record but is absent from the alert's own evidence summary, which is a gap a person should close before disposition.
  • Entity verification, PEP, and high-risk checks are all clean, which supports a lower-severity read, but does not address the return-rate signal directly.
  • Program KRIs show ach_unauthorized_return_rate and manual_review_aging_hours in breach status, indicating elevated return activity and review backlog at the program level, which raises the bar for closing an alert with an unexplained return-related signal.
  • Confidence is moderate rather than high because the alert evidence itself is incomplete relative to the underlying transfer scoring data.

Evidence

{
  "n": 1386,
  "band": "review",
  "skoor": 40,
  "signals": [
    {
      "code": "counterparty.first_time",
      "detail": "first transfer with this counterparty",
      "weight": 10
    },
    {
      "code": "counterparty.first_time_and_large",
      "detail": "amount above the program p95 (84940)",
      "weight": 15
    }
  ],
  "routeReason": "detector always reviewed"
}

Skoor signals

SignalWeightHardDetail
counterparty.first_time+10first transfer with this counterparty
counterparty.first_time_and_large+15amount above the program p95 (84929)
returns.entity_rate_gt_threshold+15entity unauthorized return rate 1/30 originated ACH debits in 60d

Decision

Sign in as an operator to decide. Operator sign-in →

Dispositions

No disposition yet.

Actions

Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.

No actions requested.