SKOOR Risk Money movement. Skoored by AI.

Alert · reviewed · open

The entity made 5 transfers on 2026-07-29 and has been silent for 49 days since.

Detector
burst_then_dormant
Severity
medium
Program
Northwind Payroll (simulated)
Subject
entity enti_sim_nort_318e3k7b1i
Transfer
Skoor at alert
null unscored
Hard signal
no
Policy
policy-v1
Opened
2026-09-17 19:30Z
Closed
Decision clock
none · due — no clock
Escalated

Draft narrative

What happened. Entity enti_sim_nort_318e3k7b1i (business "Grove Co 06", Northwind Payroll program) generated 5 transfers on 2026-07-29 and has had no activity for 49 days since, exceeding the detector's burst threshold (5) and silence threshold (14 days). This triggered a medium-severity burst_then_dormant alert that routed to review because the detector is not auto-closable. What the evidence shows. The entity is a verified business, not flagged high risk, not PEP, with no review reasons on file, screened 2026-07-06 (44 days before the burst, within normal recency). The alert has no hard signal and is unscored (band unscored). The burst of 5 transfers in one day followed by dormancy is consistent with a single payroll disbursement event under a payroll program (declared monthly volume $2,500,000.00 via ACH, US only), which by nature clusters activity on set dates followed by quiet periods. Program-level KRIs are mostly ok: frozen_accounts, overdraft_events, sanctioned_country_transfers, ach return rates, stale_screening_share, verification_denial_rate, reserve_coverage_ratio all ok. Two KRIs sit at watch (pep_flagged_entities=1 of 33; high_risk_entity_share=0.061), and manual_review_aging_hours shows a breach (1434.67 hours, n=3), but none of these are tied to this specific entity or alert reasons, and the n=3 sample is small. What was checked. Entity verification status, risk flags, PEP status, review reasons, and screening recency; program declared volume and rails against the burst pattern; program KRI panel for corroborating signals; prior dispositions on this entity (none found). What is recommended. Close the alert. No transfer is on hold, so release does not apply. The entity shows no risk indicators, is recently verified, and the burst-then-dormant pattern is consistent with a routine payroll disbursement cycle. The unrelated manual_review_aging_hours breach and watch-level KRIs are program-wide observations with small sample sizes and do not point to this entity; they do not by themselves warrant escalation of this specific alert.
Recommendation
close
Confidence
0.62
Model
claude-sonnet-5
Drafted
2026-09-17 19:30Z
Rationale
  • Entity is VERIFIED, not high risk, not PEP, no review reasons, screening current as of 2026-07-06.
  • Alert has no hard signal and is unscored, and the burst/dormancy pattern matches expected payroll disbursement behavior for this program.
  • Program KRIs directly relevant to fraud/AML (ach_unauthorized_return_rate, sanctioned_country_transfers, verification_denial_rate) are all in normal range.
  • Watch-level KRIs (pep_flagged_entities, high_risk_entity_share) and the manual_review_aging_hours breach are program-wide with small samples and not linked to this entity, so they inform context but do not override the entity-level evidence.
  • No prior dispositions exist for this entity to indicate a repeated or worsening pattern.

Evidence

{
  "burstDay": "2026-07-29",
  "typology": "burst_then_dormant",
  "programId": "030a8115-8109-4bdc-8e82-65ec40280d47",
  "burstCount": 5,
  "silentDays": 49,
  "thresholds": {
    "burstMin": 5,
    "silenceDays": 14
  },
  "routeReason": "detector not auto-closable"
}

Decision

Sign in as an operator to decide. Operator sign-in →

Dispositions

No disposition yet.

Actions

Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.

No actions requested.