SKOOR Risk Money movement. Skoored by AI.

Alert · reviewed · held

Entity High Risk Trading 1 entered the hold band (Skoor 75, n=38): entity.high_risk, entity.unauthorized_returns, entity.return_rate, entity.velocity.

Detector
entity_hold
Severity
high
Program
Harbor Marketplace Payouts (simulated)
Subject
entity enti_sim_harb_skonrvy3x6
Transfer
Skoor at alert
75 hold
Hard signal
no
Policy
policy-v1
Opened
2026-09-17 19:32Z
Closed
Decision clock
none · due — no clock
Escalated

Draft narrative

What happened. Alert 7352a2b8-f617-4760-bf10-792c19275d3b fired on entity_hold detector for entity enti_sim_harb_skonrvy3x6 ("High Risk Trading 1"), a verified business under Harbor Marketplace Payouts. The entity's Skoor reached 75, placing it in the hold band, based on 38 observed transactions. autoHold is true and the alert was routed for review because the detector is not auto-closable. What the evidence shows. Four signals drove the score: the entity is flagged high risk by screening (weight 20); it has 1 unauthorized return against it (weight 30); its return rate is 3 of 38 transactions, or 7.9% (weight 15), well above the program-wide ach_overall_return_rate of 2.78%; and its last-30-day volume is 2.1x its prior monthly volume (weight 10). The entity itself shows verification VERIFIED, high_risk true, pep no, no review reasons, last screened 2026-08-27. Confidence on the alert is 0.856 and hard_signal is false, meaning no single deterministic trigger, but a combination of moderate-weight factors. What was checked. I reviewed the alert evidence block, the entity record, the program declared volume and rails, and program-level KRIs. Program KRIs show ach_unauthorized_return_rate at 0.845% is flagged as a breach (n=828), and manual_review_aging_hours at 1438 hours is also a breach (n=15). high_risk_entity_share (6.67%) and pep_flagged_entities are at watch level. There are no prior dispositions on this entity to inform a repeat-offender or false-positive baseline. What is recommended. Hold. The entity has an unauthorized return, an elevated return rate against the program baseline, and a velocity spike, combined with an existing high-risk flag. autoHold is already true and there is no prior disposition history to support closing without review. A person should confirm whether the unauthorized return and velocity increase reflect a legitimate business change or a risk pattern before any funds tied to this entity move further. The program-level breach in ach_unauthorized_return_rate is noted as context but is not, on this evidence alone, shown to be driven by this entity beyond its single contributing return, so escalation to a program-wide pattern is not established by the data in hand.
Recommendation
hold
Confidence
0.72
Model
claude-sonnet-5
Drafted
2026-09-17 19:32Z
Rationale
  • Skoor 75 places entity in hold band with autoHold true; detector explicitly marked not auto-closable.
  • Unauthorized return (1 of 38) and return rate 7.9% exceed program ach_overall_return_rate of 2.78%, per program KRIs.
  • Velocity 2.1x prior monthly volume is an unexplained increase with no corroborating context in the record.
  • No prior dispositions exist for this entity, so there is no basis to treat this as a known, cleared pattern.
  • Entity verification status is VERIFIED and pep is no, which weighs against escalation but does not offset the unauthorized-return and velocity signals.
  • Program-level ach_unauthorized_return_rate is flagged as a breach, but the evidence does not link this entity's single return to a broader multi-entity pattern, so escalate is not supported yet.

Evidence

{
  "n": 38,
  "band": "hold",
  "skoor": 75,
  "signals": [
    {
      "code": "entity.high_risk",
      "detail": "marked high risk by screening",
      "weight": 20
    },
    {
      "code": "entity.unauthorized_returns",
      "detail": "1 unauthorized return(s) against it",
      "weight": 30
    },
    {
      "code": "entity.return_rate",
      "detail": "return rate 3/38",
      "weight": 15
    },
    {
      "code": "entity.velocity",
      "detail": "last 30 days 2.1× its prior monthly volume",
      "weight": 10
    }
  ],
  "version": "ers-v1",
  "autoHold": true,
  "confidence": 0.856,
  "routeReason": "detector not auto-closable"
}

Decision

Sign in as an operator to decide. Operator sign-in →

Dispositions

No disposition yet.

Actions

Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.

No actions requested.