Alert · reviewed · open
Entity velocity spiked: 1 transfers and $857.09 in 24 hours.
- Detector
- velocity_spike
- Severity
- medium
- Program
- Harbor Marketplace Payouts (simulated)
- Subject
- entity enti_sim_harb_5segmmcp3wf
- Transfer
- acht_sim_harb_cmyprlso3xm · $629.38 · ach outgoing
- Skoor at alert
- null unscored
- Hard signal
- no
- Policy
- policy-v1
- Opened
- 2026-09-17 19:30Z
- Closed
- —
- Decision clock
- none · due — no clock
- Escalated
- —
Draft narrative
What happened. Velocity detector enti_sim_harb_5segmmcp3wf flagged a 24-hour velocity spike, citing 1 transfer totaling $857.09 against the program's daily average. Severity was set to medium and the alert was routed to review because the detector is not auto-closable.
What the evidence shows. The only transfer supplied in evidence is acht_sim_harb_cmyprlso3xm, an ACH outgoing CREDIT of $629.38 USD, status SETTLED, created 2026-07-10T02:58:44.000Z. This amount does not match the $857.09 cited in the alert summary, and the transfer date is roughly ten weeks before the alert open time of 2026-09-17T19:30:07.115Z, so it does not fall within the 24-hour window the detector references. The single signal present is velocity.sum_24h_gt_2x_daily_avg (weight 10), with n=4 and skoor null (band unscored), meaning no composite risk score was generated. Hard signal is false. The subject entity is a verified PERSON, not flagged high risk, not PEP, with no review reasons and a screening date of 2026-07-07T17:46:21.000Z. There are no prior dispositions on this entity.
What was checked. Reviewed the alert summary against the single transfer provided and found the amount and timing do not reconcile with the stated 24-hour, $857.09 velocity spike. Checked entity verification status, PEP status, high-risk flag, and review reasons, all clear. Checked scoring fields: skoor null, band unscored, hard signal false. Checked transfer status: SETTLED, so no funds are currently held. Checked prior dispositions: none on file.
What is recommended. Recommend closing the alert. The entity is verified with no risk flags, the detector produced no scored band or hard signal, and the only transfer of record is already settled with no return code. The mismatch between the alert's stated amount/window and the single transfer provided is a data quality gap that should be noted in the closure record, but it does not on its own indicate a pattern needing escalation given the otherwise clean entity profile and lack of prior alerts. A person should confirm the underlying velocity calculation input before this disposition is finalized, since the evidence supplied does not fully support the stated spike.
- Recommendation
- close
- Confidence
- 0.55
- Model
- claude-sonnet-5
- Drafted
- 2026-09-17 19:30Z
- Rationale
- Entity is VERIFIED, not high risk, not PEP, with no review reasons.
- Detector produced no scored band (skoor null, band unscored) and hard_signal is false.
- The single transfer in evidence ($629.38, settled 2026-07-10) does not match the alert's stated $857.09 and falls outside the described 24-hour window, indicating incomplete or inconsistent evidence rather than a confirmed spike.
- Transfer status is SETTLED, so there are no funds to hold or release.
- No prior dispositions exist for this entity, so no pattern of repeated alerts is evident.
- Confidence is moderate rather than high because the evidence contains an unresolved discrepancy that a person should verify before final closure.
Evidence
{
"n": 4,
"band": "unscored",
"skoor": null,
"signals": [
{
"code": "velocity.sum_24h_gt_2x_daily_avg",
"detail": "24h sum above 2× the program daily average",
"weight": 10
}
],
"routeReason": "detector not auto-closable"
}
Skoor signals
| Signal | Weight | Hard | Detail |
|---|---|---|---|
| velocity.sum_24h_gt_2x_daily_avg | +10 | 24h sum above 2× the program daily average |
Decision
Sign in as an operator to decide. Operator sign-in →
Dispositions
No disposition yet.
Actions
Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.
No actions requested.