Alert · reviewed · open
Entity velocity spiked: 1 transfers and $2,112.96 in 24 hours.
- Detector
- velocity_spike
- Severity
- medium
- Program
- Lantern Lending (simulated)
- Subject
- entity enti_sim_lant_5oo9e1t4cj6
- Transfer
- acht_sim_lant_9x1wwiarckt · $940.47 · ach outgoing
- Skoor at alert
- null unscored
- Hard signal
- no
- Policy
- policy-v1
- Opened
- 2026-09-17 19:30Z
- Closed
- —
- Decision clock
- none · due — no clock
- Escalated
- —
Draft narrative
What happened. A ach outgoing credit transfer of $940.47 (acht_sim_lant_9x1wwiarckt) on program Lantern Lending (simulated) was flagged by detector velocity_spike: Entity velocity spiked: 1 transfers and $2,112.96 in 24 hours..
What the evidence shows. The transaction was unscored: too little history for a Skoor. Signals: counterparty.first_time (+10), velocity.sum_24h_gt_2x_daily_avg (+10). Entity Dune LLC 327: verification VERIFIED, PEP no, high risk no.
What was checked. No program KRI snapshot was available. No prior dispositions on this entity or counterparty.
What is recommended. Recommended: escalate. A person decides; this draft was assembled from the evidence without a model (model call failed).
- Recommendation
- escalate
- Confidence
- null (template, no model)
- Model
- none (template)
- Drafted
- 2026-09-17 19:30Z
- Rationale
- Template draft: recommendation follows the band and the hard-signal rule only.
Evidence
{
"n": 4,
"band": "unscored",
"skoor": null,
"signals": [
{
"code": "velocity.sum_24h_gt_2x_daily_avg",
"detail": "24h sum above 2× the program daily average",
"weight": 10
}
],
"routeReason": "detector not auto-closable"
}
Skoor signals
| Signal | Weight | Hard | Detail |
|---|---|---|---|
| counterparty.first_time | +10 | first transfer with this counterparty | |
| velocity.sum_24h_gt_2x_daily_avg | +10 | 24h sum above 2× the program daily average |
Decision
Sign in as an operator to decide. Operator sign-in →
Dispositions
No disposition yet.
Actions
Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.
No actions requested.