SKOOR Risk Money movement. Skoored by AI.

Alert · reviewed · held

Entity Denied Origin 1 entered the hold band (Skoor 80, n=0): entity.denied, entity.high_risk.

Detector
entity_hold
Severity
high
Program
Harbor Marketplace Payouts (simulated)
Subject
entity enti_sim_harb_130qwgg53wz
Transfer
Skoor at alert
80 hold
Hard signal
yes
Policy
policy-v1
Opened
2026-09-17 19:30Z
Closed
Decision clock
none · due — no clock
Escalated

Draft narrative

What happened. An entity hold alert fired for entity enti_sim_harb_130qwgg53wz ("Denied Origin 1") under the Harbor Marketplace Payouts program. The entity entered the hold band with a Skoor of 80 on n=0 prior activity, driven by two signals: entity.denied (weight 60, hard signal) and entity.high_risk (weight 20). Route was 'reviewed' with autoHold true, opened 2026-09-17T19:30:02.777Z. What the evidence shows. The entity record shows verification status DENIED, high_risk flag true, and review reasons listing sanctions_match. Last screened 2026-06-24T12:01:30.000Z, roughly three months before this alert. Country is US, entity type PERSON, PEP no. The alert's hard signal (entity.denied) is confirmed by the entity record's own verification field, so the two data points corroborate each other. Evidence confidence field on the alert itself is listed as 0.4, and n=0 means no transaction history has accrued under this entity. Prior dispositions: none, so this is the first review of this entity. What was checked. Confirmed the alert's signal codes against the entity record: verification DENIED matches entity.denied, high_risk true matches entity.high_risk. Checked review reasons field, which shows sanctions_match, a reason not itself scored as a separate signal in this alert but present on the entity. Checked last screened date for staleness (over 90 days old at alert open). Checked prior dispositions, none exist. Checked program context: Harbor Marketplace Payouts, declared monthly volume $4,000,000.00, rails ach/realtime, countries US; no program-level notes bearing on this entity. What is recommended. Hold. A denied verification status combined with a sanctions_match review reason on a hard signal is not something a system should resolve on its own. A person should review the sanctions_match reason directly, confirm current screening status given the last screen is three months old, and determine whether this entity should be permitted to transact at all under this program before any funds move.
Recommendation
hold
Confidence
0.55
Model
claude-sonnet-5
Drafted
2026-09-17 19:30Z
Rationale
  • Hard signal entity.denied is corroborated by the entity record's own verification=DENIED field.
  • review reasons field shows sanctions_match, which raises the stakes of the denial beyond a routine verification failure and warrants human confirmation.
  • last screened date is roughly three months old relative to alert open, so screening currency should be reverified by a person.
  • n=0 and alert confidence 0.4 indicate thin transactional evidence; this is a case with no track record to weigh against the denial, and no prior dispositions exist to inform pattern context.
  • escalate is not chosen because there is no evidence in this single-entity alert of a broader multi-entity or multi-program pattern; that would require additional alerts or entities to point to.
  • release is not applicable; this alert does not concern a transfer already held.

Evidence

{
  "n": 0,
  "band": "hold",
  "skoor": 80,
  "signals": [
    {
      "code": "entity.denied",
      "hard": true,
      "detail": "verification DENIED",
      "weight": 60
    },
    {
      "code": "entity.high_risk",
      "detail": "marked high risk by screening",
      "weight": 20
    }
  ],
  "version": "ers-v1",
  "autoHold": true,
  "confidence": 0.4,
  "routeReason": "hard signal"
}

Decision

Sign in as an operator to decide. Operator sign-in →

Dispositions

No disposition yet.

Actions

Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.

No actions requested.