Alert · reviewed · held
Counterparty Receiver 23 entered the hold band (Skoor 90, n=15): counterparty.unauthorized_returns, counterparty.unauthorized_rate, counterparty.return_rate, counterparty.review_share, counterparty.new.
- Detector
- counterparty_hold
- Severity
- high
- Program
- Harbor Marketplace Payouts (simulated)
- Subject
- counterparty cpty_sim_harb_gzii64r41f
- Transfer
- —
- Skoor at alert
- 90 hold
- Hard signal
- no
- Policy
- policy-v1
- Opened
- 2026-09-17 19:31Z
- Closed
- —
- Decision clock
- none · due — no clock
- Escalated
- —
Draft narrative
What happened. Detector counterparty_hold raised an alert on counterparty cpty_sim_harb_gzii64r41f for program Harbor Marketplace Payouts (simulated): Counterparty Receiver 23 entered the hold band (Skoor 90, n=15): counterparty.unauthorized_returns, counterparty.unauthorized_rate, counterparty.return_rate, counterparty.review_share, counterparty.new..
What the evidence shows. Transaction Risk Skoor 90 (band hold).
What was checked. Program KRIs as of the latest snapshot: frozen_accounts ok, hold_aging_hours watch, overdraft_events ok, manual_review_rate ok, card_fraud_declines unmeasured, pep_flagged_entities watch, velocity_vs_declared unmeasured, stale_screening_share ok, high_risk_entity_share watch, reserve_coverage_ratio ok, ach_overall_return_rate ok, verification_denial_rate ok, manual_review_aging_hours breach, ach_unauthorized_return_rate breach, sanctioned_country_transfers ok, ach_administrative_return_rate ok, counterparty_concentration_top1 ok. No prior dispositions on this entity or counterparty.
What is recommended. Recommended: hold. A person decides; this draft was assembled from the evidence without a model (model output did not match the schema).
- Recommendation
- hold
- Confidence
- null (template, no model)
- Model
- none (template)
- Drafted
- 2026-09-17 19:31Z
- Rationale
- Template draft: recommendation follows the band and the hard-signal rule only.
Evidence
{
"n": 15,
"band": "hold",
"skoor": 90,
"signals": [
{
"code": "counterparty.unauthorized_returns",
"detail": "drew 2 unauthorized return(s)",
"weight": 40
},
{
"code": "counterparty.unauthorized_rate",
"detail": "unauthorized rate 2/15 above the network threshold",
"weight": 15
},
{
"code": "counterparty.return_rate",
"detail": "return rate 2/15",
"weight": 15
},
{
"code": "counterparty.review_share",
"detail": "93% in the review band",
"weight": 10
},
{
"code": "counterparty.new",
"detail": "first seen 0d ago",
"weight": 10
}
],
"version": "crs-v1",
"autoHold": true,
"confidence": 0.305,
"routeReason": "detector not auto-closable"
}
Decision
Sign in as an operator to decide. Operator sign-in →
Dispositions
No disposition yet.
Actions
Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.
No actions requested.