SKOOR Risk Money movement. Skoored by AI.

Alert · reviewed · open

The entity made 5 transfers on 2026-07-15 and has been silent for 63 days since.

Detector
burst_then_dormant
Severity
medium
Program
Harbor Marketplace Payouts (simulated)
Subject
entity enti_sim_harb_yhmcztb3vc
Transfer
Skoor at alert
null unscored
Hard signal
no
Policy
policy-v1
Opened
2026-09-17 19:30Z
Closed
Decision clock
none · due — no clock
Escalated

Draft narrative

What happened. On 2026-07-15 entity enti_sim_harb_yhmcztb3vc (Juniper LLC 19) made 5 transfers under program Harbor Marketplace Payouts, then had no activity for the following 63 days. The burst_then_dormant detector fired because the transfer count met the burstMin threshold of 5 and the silence period exceeded the silenceDays threshold of 14. The alert was routed to review rather than auto-closed. What the evidence shows. The alert record contains no transaction amounts, only counts and dates. The entity is a VERIFIED business, not flagged high risk, not PEP, with no review reasons listed, and was last screened 2026-07-06, nine days before the burst. The alert carries no score (skoor null, band unscored) and hard_signal is false. Program-level KRIs show frozen_accounts, overdraft_events, stale_screening_share, and verification_denial_rate all in the ok range. Two KRIs sit at watch: pep_flagged_entities (1 of 30) and high_risk_entity_share (0.067 of 30), but neither is tied to this specific entity in the evidence provided. Several KRIs (hold_aging_hours, manual_review_rate, velocity_vs_declared, reserve_coverage_ratio, ach return rates) are unmeasured (n=0), so no conclusion can be drawn from them. There are no prior dispositions for this entity. What was checked. Detector thresholds against reported burst count and silent days, entity verification and risk status, entity screening recency, program-level KRI panel, and prior disposition history. No transfer amounts, counterparty details, or rail-level data were present in the evidence to assess dollar volume against the program's declared $4,000,000.00 monthly volume. What is recommended. Close the alert. The pattern matches the detector's definition, but the entity is verified, not high risk, not PEP, has no open review reasons, and no hard signal or score elevates the case. Nothing in the current evidence points to a specific concern requiring a hold on funds or a broader pattern review. The two watch-level program KRIs (pep_flagged_entities, high_risk_entity_share) are not linked to this entity in the record and do not by themselves warrant escalation of this alert.
Recommendation
close
Confidence
0.58
Model
claude-sonnet-5
Drafted
2026-09-17 19:30Z
Rationale
  • Detector thresholds (burstMin=5, silenceDays=14) were met exactly as designed; the alert reflects the detector working as intended, not an anomaly beyond its definition.
  • hard_signal is false and skoor is null/unscored, indicating no elevated risk scoring attached to this alert.
  • Entity is VERIFIED, not high risk, not PEP, with review reasons listed as none, and was screened just before the burst date.
  • No transaction amounts, counterparties, or rail data are present in the evidence, which limits confidence and is noted explicitly rather than inferred.
  • Program KRIs relevant to hold risk (frozen_accounts, overdraft_events) are in the ok range; KRIs at watch (pep_flagged_entities, high_risk_entity_share) are program-wide and not attributed to this specific entity in the record.
  • No prior dispositions exist for this entity, so there is no pattern of repeat alerts to support escalation.

Evidence

{
  "burstDay": "2026-07-15",
  "typology": "burst_then_dormant",
  "programId": "898ba6ad-5b42-42fd-be7b-2afc9d52af5b",
  "burstCount": 5,
  "silentDays": 63,
  "thresholds": {
    "burstMin": 5,
    "silenceDays": 14
  },
  "routeReason": "detector not auto-closable"
}

Decision

Sign in as an operator to decide. Operator sign-in →

Dispositions

No disposition yet.

Actions

Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.

No actions requested.