Alert · reviewed · open
Activity on an entity flagged by screening (PEP status no, high risk).
- Detector
- sanctions_or_pep
- Severity
- high
- Program
- Harbor Marketplace Payouts (simulated)
- Subject
- entity enti_sim_harb_skonrvy3x6
- Transfer
- acht_sim_harb_8yd1sg7h90f · $414.42 · ach outgoing
- Skoor at alert
- 20 clear
- Hard signal
- no
- Policy
- policy-v1
- Opened
- 2026-09-17 19:32Z
- Closed
- —
- Decision clock
- none · due — no clock
- Escalated
- —
Draft narrative
What happened. Alert 4f2ac0a8-c61a-4d7d-aa68-c5fa22f426a8 fired on entity enti_sim_harb_skonrvy3x6 under the sanctions_or_pep detector because the entity is marked high risk by screening. The detector routes for review on every high-risk flag regardless of score (routeReason: detector always reviewed). The alert score is 20, band clear, hard_signal false.
What the evidence shows. The entity is a BUSINESS, verification status VERIFIED, pep flag no, review reasons none, last screened 2026-08-27. The single signal driving the score is entity.high_risk (+20), which alone lands in the clear band. The associated transfer acht_sim_harb_8yd1sg7h90f is an outgoing ACH credit of $414.42 USD, status SETTLED, with no return code. The transfer-level skoor is also 20/clear with confidence 1.0 on n=2040. There are no other signals (no sanctioned-country match, no stale screening, no PEP hit). Program KRIs show two items outside normal range: manual_review_aging_hours at 1438.05 hours (breach) and ach_unauthorized_return_rate at 0.86% (breach), alongside several watch-level items (hold_aging_hours, overdraft_events, pep_flagged_entities, high_risk_entity_share). None of these KRI breaches are tied in the evidence to this specific entity or transfer.
What was checked. Reviewed the alert signals, transfer details, entity screening record, and program KRI panel. Confirmed no hard signal, no PEP match, no review reasons, verification status VERIFIED, and no return code on the settled transfer. Checked prior dispositions for this alert or entity: none exist. Noted the two program-level KRI breaches but found no linkage in the evidence connecting them to this alert's subject or transaction.
What is recommended. Close this alert. The evidence supports no immediate action on this entity or transfer: score is clear band, no hard signal, entity is verified and not PEP, and the transfer settled cleanly with no return. The program-level KRI breaches (manual_review_aging_hours, ach_unauthorized_return_rate) are noted but are not evidenced as connected to this specific alert and should be tracked separately at the program level rather than held against this transfer.
- Recommendation
- close
- Confidence
- 0.78
- Model
- claude-sonnet-5
- Drafted
- 2026-09-17 19:32Z
- Rationale
- Alert score 20 is in the clear band with hard_signal false, per the alert's own skoor and the transfer's skoor (both 20/clear, n=2040, confidence 1.0).
- Entity is VERIFIED, pep=no, review reasons none, and was screened within the last month (2026-08-27), showing no independent risk indicator beyond the single high_risk flag already scored.
- The routeReason indicates this alert type is always reviewed for high-risk entities, not that a specific elevated risk was detected here.
- The associated transfer settled with no return code, indicating no processing or compliance exception on the money movement itself.
- Program KRI breaches (manual_review_aging_hours, ach_unauthorized_return_rate) exist in the evidence but are not tied to this entity or transfer, so they do not by themselves justify holding funds already settled; they may warrant separate program-level review outside this alert.
- No prior dispositions exist for this entity, so there is no pattern of repeated flags to escalate on.
Evidence
{
"n": 2040,
"band": "clear",
"skoor": 20,
"signals": [
{
"code": "entity.high_risk",
"detail": "entity marked high risk by screening",
"weight": 20
}
],
"routeReason": "detector always reviewed"
}
Skoor signals
| Signal | Weight | Hard | Detail |
|---|---|---|---|
| entity.high_risk | +20 | entity marked high risk by screening |
Decision
Sign in as an operator to decide. Operator sign-in →
Dispositions
No disposition yet.
Actions
Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.
No actions requested.