Alert · reviewed · held
Entity High Risk Trading 1 entered the hold band (Skoor 75, n=38): entity.high_risk, entity.unauthorized_returns, entity.return_rate, entity.velocity.
- Detector
- entity_hold
- Severity
- high
- Program
- Harbor Marketplace Payouts (simulated)
- Subject
- entity enti_sim_harb_skonrvy3x6
- Transfer
- —
- Skoor at alert
- 75 hold
- Hard signal
- no
- Policy
- policy-v1
- Opened
- 2026-09-17 19:32Z
- Closed
- —
- Decision clock
- none · due — no clock
- Escalated
- —
Draft narrative
What happened. Alert 7352a2b8-f617-4760-bf10-792c19275d3b fired on entity_hold detector for entity enti_sim_harb_skonrvy3x6 ("High Risk Trading 1"), a verified business under Harbor Marketplace Payouts. The entity's Skoor reached 75, placing it in the hold band, based on 38 observed transactions. autoHold is true and the alert was routed for review because the detector is not auto-closable.
What the evidence shows. Four signals drove the score: the entity is flagged high risk by screening (weight 20); it has 1 unauthorized return against it (weight 30); its return rate is 3 of 38 transactions, or 7.9% (weight 15), well above the program-wide ach_overall_return_rate of 2.78%; and its last-30-day volume is 2.1x its prior monthly volume (weight 10). The entity itself shows verification VERIFIED, high_risk true, pep no, no review reasons, last screened 2026-08-27. Confidence on the alert is 0.856 and hard_signal is false, meaning no single deterministic trigger, but a combination of moderate-weight factors.
What was checked. I reviewed the alert evidence block, the entity record, the program declared volume and rails, and program-level KRIs. Program KRIs show ach_unauthorized_return_rate at 0.845% is flagged as a breach (n=828), and manual_review_aging_hours at 1438 hours is also a breach (n=15). high_risk_entity_share (6.67%) and pep_flagged_entities are at watch level. There are no prior dispositions on this entity to inform a repeat-offender or false-positive baseline.
What is recommended. Hold. The entity has an unauthorized return, an elevated return rate against the program baseline, and a velocity spike, combined with an existing high-risk flag. autoHold is already true and there is no prior disposition history to support closing without review. A person should confirm whether the unauthorized return and velocity increase reflect a legitimate business change or a risk pattern before any funds tied to this entity move further. The program-level breach in ach_unauthorized_return_rate is noted as context but is not, on this evidence alone, shown to be driven by this entity beyond its single contributing return, so escalation to a program-wide pattern is not established by the data in hand.
- Recommendation
- hold
- Confidence
- 0.72
- Model
- claude-sonnet-5
- Drafted
- 2026-09-17 19:32Z
- Rationale
- Skoor 75 places entity in hold band with autoHold true; detector explicitly marked not auto-closable.
- Unauthorized return (1 of 38) and return rate 7.9% exceed program ach_overall_return_rate of 2.78%, per program KRIs.
- Velocity 2.1x prior monthly volume is an unexplained increase with no corroborating context in the record.
- No prior dispositions exist for this entity, so there is no basis to treat this as a known, cleared pattern.
- Entity verification status is VERIFIED and pep is no, which weighs against escalation but does not offset the unauthorized-return and velocity signals.
- Program-level ach_unauthorized_return_rate is flagged as a breach, but the evidence does not link this entity's single return to a broader multi-entity pattern, so escalate is not supported yet.
Evidence
{
"n": 38,
"band": "hold",
"skoor": 75,
"signals": [
{
"code": "entity.high_risk",
"detail": "marked high risk by screening",
"weight": 20
},
{
"code": "entity.unauthorized_returns",
"detail": "1 unauthorized return(s) against it",
"weight": 30
},
{
"code": "entity.return_rate",
"detail": "return rate 3/38",
"weight": 15
},
{
"code": "entity.velocity",
"detail": "last 30 days 2.1× its prior monthly volume",
"weight": 10
}
],
"version": "ers-v1",
"autoHold": true,
"confidence": 0.856,
"routeReason": "detector not auto-closable"
}
Decision
Sign in as an operator to decide. Operator sign-in →
Dispositions
No disposition yet.
Actions
Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.
No actions requested.