SKOOR Risk Money movement. Skoored by AI.

Alert · reviewed · open

Entity velocity spiked: 2 transfers and $832.91 in 24 hours.

Detector
velocity_spike
Severity
medium
Program
Harbor Marketplace Payouts (simulated)
Subject
entity enti_sim_harb_5ogb4mu73vg
Transfer
acht_sim_harb_cbpryauy3zr · $770.28 · ach outgoing
Skoor at alert
null unscored
Hard signal
no
Policy
policy-v1
Opened
2026-09-17 19:30Z
Closed
Decision clock
none · due — no clock
Escalated

Draft narrative

What happened. A velocity-spike detector fired on entity enti_sim_harb_5ogb4mu73vg (Kestrel Partners 110) after the system observed 2 transfers totaling $832.91 within 24 hours, which exceeded 2x the program's daily average. Severity is medium, the alert is unscored (skoor null, band unscored), and hard_signal is false. What the evidence shows. The single supporting transfer on record (acht_sim_harb_cbpryauy3zr) is an ACH outgoing CREDIT of $770.28, status SETTLED, with no return code. That transfer's own signal set includes counterparty.first_time and counterparty.first_time_and_large in addition to the velocity flag, but the alert-level evidence array lists only the velocity signal (weight 10), so the alert itself is not scored as a first-time-counterparty case. The counterparty's country is unknown. The entity is a verified US person, not high risk, not PEP, with review reasons none and a screening date of 2026-07-05, well before this alert opened. The transfer is already settled, so there is no held transfer to release. What was checked. Program context: Harbor Marketplace Payouts has declared monthly volume of $4,000,000.00; the $832.91 in this alert is a small fraction of that. Program KRIs show ach_overall_return_rate 0, ach_unauthorized_return_rate 0, sanctioned_country_transfers 0, and reserve_coverage_ratio 75.02 (n=14, ok) — no funding or return-rate stress. Several KRIs sit at watch level (manual_review_rate 0.032, pep_flagged_entities 1/30, high_risk_entity_share 0.067), and manual_review_aging_hours shows a breach at 1438 hours, but that metric has n=1 and is not tied to this entity or transfer in the evidence provided. Prior dispositions: none on file for this entity. What is recommended. Close this alert as reviewed with no further action on the transfer itself, since it settled cleanly with no return code and the entity is verified with no risk flags. A person should still glance at the counterparty.first_time_and_large signal on the underlying transfer record before final sign-off, since that detail is not reflected in the alert's own evidence array.
Recommendation
close
Confidence
0.62
Model
claude-sonnet-5
Drafted
2026-09-17 19:30Z
Rationale
  • Alert is unscored (skoor null, band unscored) and hard_signal is false, indicating thin, low-confidence detector output.
  • Only one supporting transfer is documented; it is SETTLED with no return code, so there is nothing pending to hold or release.
  • Entity is VERIFIED, not high risk, not PEP, with no review reasons and recent screening (2026-07-05).
  • The $832.91 velocity spike is immaterial against the program's $4,000,000.00 declared monthly volume.
  • Program-level KRIs relevant to fraud/returns (ach_overall_return_rate, ach_unauthorized_return_rate, sanctioned_country_transfers) are all at 0/ok; watch-level KRIs (manual_review_rate, pep_flagged_entities, high_risk_entity_share) are not specifically linked to this entity or alert in the evidence.
  • The transfer-level evidence includes counterparty.first_time and counterparty.first_time_and_large signals that are not carried into the alert-level evidence array, which limits full confidence in a clean close and warrants a brief human glance rather than fully automated closure.

Evidence

{
  "n": 4,
  "band": "unscored",
  "skoor": null,
  "signals": [
    {
      "code": "velocity.sum_24h_gt_2x_daily_avg",
      "detail": "24h sum above 2× the program daily average",
      "weight": 10
    }
  ],
  "routeReason": "detector not auto-closable"
}

Skoor signals

SignalWeightHardDetail
counterparty.first_time+10first transfer with this counterparty
velocity.sum_24h_gt_2x_daily_avg+1024h sum above 2× the program daily average

Decision

Sign in as an operator to decide. Operator sign-in →

Dispositions

No disposition yet.

Actions

Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.

No actions requested.