Alert · reviewed · open
The entity made 5 transfers on 2026-08-04 and has been silent for 44 days since.
- Detector
- burst_then_dormant
- Severity
- medium
- Program
- Harbor Marketplace Payouts (simulated)
- Subject
- entity enti_sim_harb_b4xqtgv3vw
- Transfer
- —
- Skoor at alert
- null unscored
- Hard signal
- no
- Policy
- policy-v1
- Opened
- 2026-09-17 19:31Z
- Closed
- —
- Decision clock
- none · due — no clock
- Escalated
- —
Draft narrative
What happened. A burst_then_dormant detector fired on entity enti_sim_harb_b4xqtgv3vw (business "Cedar Services 114") under the Harbor Marketplace Payouts program. The entity made 5 transfers on 2026-08-04, meeting the burst threshold (burstMin=5), and has had no activity for 44 days since, exceeding the silence threshold (silenceDays=14). Severity is medium, hard_signal is false, and the alert carries no risk score (band unscored).
What the evidence shows. The entity is a verified business, not flagged high risk, not PEP, with no listed review reasons, and was last screened 2026-06-23, about six weeks before the burst. There are no prior dispositions on this entity. The routeReason field states the alert was routed for review only because the detector is not auto-closable, not because a risk indicator was breached at the entity level. Program-level KRIs show two items in breach status (manual_review_aging_hours and ach_unauthorized_return_rate) and several in watch status (hold_aging_hours, pep_flagged_entities, high_risk_entity_share), but none of these are tied in the evidence to this specific entity or to the 2026-08-04 transfers.
What was checked. Detector thresholds and counts (burstCount 5 vs burstMin 5, silentDays 44 vs silenceDays 14), entity verification and risk status, screening recency, PEP and review-reason fields, prior dispositions, and program KRI panel for related signals such as sanctioned_country_transfers, counterparty_concentration_top1, and verification_denial_rate, all of which are in the ok range.
What is recommended. No transfer is currently held and no evidence ties this entity to the program's breached KRIs. The burst-then-dormant pattern alone, on a verified, non-high-risk, non-PEP entity with recent screening and no prior alerts, does not present a signal that requires funds to be stopped or a broader pattern investigation. Recommend closing this alert. The manual_review_aging_hours and ach_unauthorized_return_rate breaches at the program level are noted for separate monitoring but are not evidenced against this entity and should not delay closure of this specific alert.
- Recommendation
- close
- Confidence
- 0.62
- Model
- claude-sonnet-5
- Drafted
- 2026-09-17 19:31Z
- Rationale
- Detector thresholds were met exactly at the minimum (burstCount 5 = burstMin 5), which is a low-margin trigger rather than a pronounced anomaly.
- Entity is VERIFIED, high_risk false, pep no, with no review reasons and screening within the last two months relative to the burst date.
- No hard signal, no score, and no prior dispositions exist for this entity, indicating this is a first-time, unscored alert.
- routeReason explicitly attributes routing to the detector's auto-close policy, not to any elevated risk finding.
- Program KRI breaches (manual_review_aging_hours, ach_unauthorized_return_rate) are program-wide aggregates with no field linking them to this entity or transaction set, so they cannot support escalation on this alert alone.
- No transfer-hold status is referenced in the alert, so 'release' does not apply and 'hold' is not warranted absent a specific held transaction.
Evidence
{
"burstDay": "2026-08-04",
"typology": "burst_then_dormant",
"programId": "898ba6ad-5b42-42fd-be7b-2afc9d52af5b",
"burstCount": 5,
"silentDays": 44,
"thresholds": {
"burstMin": 5,
"silenceDays": 14
},
"routeReason": "detector not auto-closable"
}
Decision
Sign in as an operator to decide. Operator sign-in →
Dispositions
No disposition yet.
Actions
Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.
No actions requested.