Alert · reviewed · open
Transaction Risk Skoor 55 (review band) on a $215.53 ach transfer: returns.counterparty_prior_unauthorized, returns.entity_rate_gt_threshold.
- Detector
- skoor_review
- Severity
- medium
- Program
- Harbor Marketplace Payouts (simulated)
- Subject
- transfer acht_sim_harb_3uaw3tq68zo
- Transfer
- acht_sim_harb_3uaw3tq68zo · $215.53 · ach outgoing
- Skoor at alert
- 55 review
- Hard signal
- no
- Policy
- policy-v1
- Opened
- 2026-09-17 19:32Z
- Closed
- —
- Decision clock
- none · due — no clock
- Escalated
- —
Draft narrative
What happened. An alert fired on outgoing ACH transfer acht_sim_harb_3uaw3tq68zo, a $215.53 credit under program Harbor Marketplace Payouts. The transfer skoor is 55 (review band, hard signal false), driven by two signals: a prior unauthorized return on the counterparty and an entity-level unauthorized return rate exceeding threshold (1 of 29 originated ACH debits in 60 days).
What the evidence shows. The transfer itself settled with no return code, meaning no unauthorized return occurred on this specific transaction. The unauthorized-return signal is a historical flag tied to the counterparty (1 prior unauthorized return, detail not itemized) and the entity's return rate is based on the entity's own ACH debits, a different transaction type than the outgoing credit under review. The entity, Larch Studio 111, is VERIFIED, not high risk, not PEP, with no open review reasons and screening current as of 2026-08-21. Program-level KRIs show ach_unauthorized_return_rate in breach (0.0086 vs prior period) and manual_review_aging_hours in breach (1438h), but these are program-wide metrics with no direct link established to this counterparty or entity beyond the single prior return already counted in the alert signal.
What was checked. Transfer status and return code, entity verification and risk flags, program declared volume and country scope, program KRI panel for corroborating patterns, and prior dispositions on this alert or subject (none found).
What is recommended. The transfer is already settled with no return code, so there are no funds to hold and 'release' does not apply. The entity is verified with no risk flags, and the signals trace to historical/statistical counterparty and entity data rather than evidence of a problem with this transaction. The program-level KRI breaches (unauthorized return rate, review aging) are not tied to this entity or counterparty in the evidence provided and would need separate review rather than action on this single alert. Close this alert; no person action is needed on this transfer.
- Recommendation
- close
- Confidence
- 0.62
- Model
- claude-sonnet-5
- Drafted
- 2026-09-17 19:32Z
- Rationale
- Transfer status is SETTLED with return code none, indicating no unauthorized return occurred on this transaction itself.
- Entity is VERIFIED, not high risk, not PEP, with no open review reasons and screening less than a month stale.
- The two signals driving skoor 55 are historical/statistical (one prior counterparty return, entity debit return rate) not evidence of fraud on this specific credit.
- Hold or release are not applicable since the transfer has already settled and there are no funds in a held state.
- Program KRI breaches (ach_unauthorized_return_rate, manual_review_aging_hours) are noted but the evidence does not connect them to this specific counterparty or entity, so escalation is not supported by what is in this alert.
- No prior dispositions exist on this subject, so there is no repeat-alert pattern to elevate this beyond a standard close.
Evidence
{
"n": 2040,
"band": "review",
"skoor": 55,
"signals": [
{
"code": "returns.counterparty_prior_unauthorized",
"detail": "1 prior unauthorized return(s)",
"weight": 40
},
{
"code": "returns.entity_rate_gt_threshold",
"detail": "entity unauthorized return rate 1/29 originated ACH debits in 60d",
"weight": 15
}
],
"confidence": 1,
"routeReason": "detector not auto-closable"
}
Skoor signals
| Signal | Weight | Hard | Detail |
|---|---|---|---|
| returns.counterparty_prior_unauthorized | +40 | 1 prior unauthorized return(s) | |
| returns.entity_rate_gt_threshold | +15 | entity unauthorized return rate 1/29 originated ACH debits in 60d |
Decision
Sign in as an operator to decide. Operator sign-in →
Dispositions
No disposition yet.
Actions
Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.
No actions requested.