Alert · reviewed · open
1 overdraft event(s) and 0 frozen account(s) on the program in the window.
- Detector
- overdraft_or_frozen
- Severity
- medium
- Program
- Harbor Marketplace Payouts (simulated)
- Subject
- account 898ba6ad-5b42-42fd-be7b-2afc9d52af5b
- Transfer
- —
- Skoor at alert
- null unscored
- Hard signal
- no
- Policy
- policy-v1
- Opened
- 2026-09-17 19:31Z
- Closed
- —
- Decision clock
- none · due — no clock
- Escalated
- —
Draft narrative
What happened. Alert 6feafa0a-815f-4735-9572-481a31f1d1d5 fired on the overdraft_or_frozen detector for account 898ba6ad-5b42-42fd-be7b-2afc9d52af5b. The summary reports 1 overdraft event and 0 frozen accounts on the program during the window.
What the evidence shows. frozen_accounts is 0 of 3 measured, status ok, threshold 0. overdraft_events is 1 of 3 measured, status watch, threshold 0 (any nonzero value trips watch at this threshold). The alert carries no hard signal and is unscored (skoor null, band unscored). At the program level, KRIs show two breaches unrelated to this account's overdraft flag: manual_review_aging_hours (1438.05 hours, n=15, breach) and ach_unauthorized_return_rate (0.00757, n=793, breach). Other program KRIs (hold_aging_hours, pep_flagged_entities, high_risk_entity_share) sit at watch. frozen_accounts, verification_denial_rate, reserve_coverage_ratio, ach_overall_return_rate, sanctioned_country_transfers, counterparty_concentration_top1, and velocity_vs_declared are all ok.
What was checked. Reviewed the alert evidence block for the named account (overdraft and frozen counts), the routeReason field, prior dispositions (none on file), and the program KRI panel for context on whether the single overdraft event fits a broader pattern. No transfer-hold reference exists in this alert, so no funds are described as held.
What is recommended. Close this alert. The evidence is a single overdraft event with no frozen accounts, no hard signal, and no scored risk band. Nothing in the account-level evidence indicates funds movement requiring a hold. The two program-level KRI breaches (manual_review_aging_hours, ach_unauthorized_return_rate) are not tied to this subject account in the evidence provided and should be tracked as separate program-level items rather than folded into this account alert.
- Recommendation
- close
- Confidence
- 0.62
- Model
- claude-sonnet-5
- Drafted
- 2026-09-17 19:32Z
- Rationale
- overdraft_events watch status is driven by a threshold of 0, so any single event trips watch; the count here is 1 out of 3 measured, a thin sample.
- frozen_accounts is 0, status ok, removing the more severe half of this detector's basis.
- hard_signal is false and skoor is null/unscored, indicating no elevated automated risk assessment for this alert.
- No prior dispositions exist for this account, so there is no pattern history to weigh.
- Program-level breaches (manual_review_aging_hours, ach_unauthorized_return_rate) are reported at the program level, not attributed to this specific account in the evidence, so they do not by themselves justify escalating this account-level alert.
- This alert does not reference a held transfer, so 'release' does not apply.
Evidence
{
"routeReason": "detector not auto-closable",
"frozen_accounts": {
"n": 3,
"unit": "count",
"value": 0,
"status": "ok",
"threshold": 0
},
"overdraft_events": {
"n": 3,
"unit": "count",
"value": 1,
"status": "watch",
"threshold": 0
}
}
Decision
Sign in as an operator to decide. Operator sign-in →
Dispositions
No disposition yet.
Actions
Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.
No actions requested.