Alert · reviewed · open
Transaction Risk Skoor 40 (review band) on a $336.92 ach transfer: returns.counterparty_prior_unauthorized.
- Detector
- skoor_review
- Severity
- medium
- Program
- Harbor Marketplace Payouts (simulated)
- Subject
- transfer acht_sim_harb_8ielm6ju9g7
- Transfer
- acht_sim_harb_8ielm6ju9g7 · $336.92 · ach outgoing
- Skoor at alert
- 40 review
- Hard signal
- no
- Policy
- policy-v1
- Opened
- 2026-09-17 19:32Z
- Closed
- —
- Decision clock
- none · due — no clock
- Escalated
- —
Draft narrative
What happened. Alert 843f6c72-1308-4705-83ec-f759a21ecfb9 was opened on 2026-09-17T19:32:19.176Z by the skoor_review detector for an outgoing ACH transfer of $336.92 (acht_sim_harb_8ielm6ju9g7) under the Harbor Marketplace Payouts program. The transfer scored 40 (review band, hard_signal false) driven entirely by one signal: three prior unauthorized returns tied to the counterparty (weight 40).
What the evidence shows. The transfer itself settled on 2026-09-16 with no return code recorded, so this specific transfer has not been returned or reversed. The risk signal is about the counterparty's history (cpty_sim_harb_39i9ftby3xi, country unknown), which has three prior unauthorized returns. The paying entity, Birch Holdings 113 (enti_sim_harb_2ag6spru3vs), is VERIFIED, not high risk, not PEP, with no open review reasons and a screening date of 2026-08-19. At the program level, ach_unauthorized_return_rate (0.0091, n=877) is flagged as a breach against its threshold, and manual_review_aging_hours (1438h, n=16) is also in breach. Other KRIs (hold_aging_hours, overdraft_events, card_fraud_declines, pep_flagged_entities, high_risk_entity_share) sit in watch status. No prior dispositions exist for this alert.
What was checked. Reviewed the transfer record (status, amount, return code, creation date), the entity verification status and screening recency, the program's declared volume and rails, and the full KRI panel supplied with the alert. Confirmed there is no linked hold on this transfer (status SETTLED) and no prior disposition history to reference.
What is recommended. The transfer has already settled with no return code, so there is no held transfer to release or hold. The unauthorized-return history on the counterparty, combined with the program-level ach_unauthorized_return_rate breach, indicates a pattern that extends beyond this single alert and warrants review of the counterparty relationship and related transfers across the program rather than disposition of this alert alone.
- Recommendation
- escalate
- Confidence
- 0.55
- Model
- claude-sonnet-5
- Drafted
- 2026-09-17 19:32Z
- Rationale
- Transfer status is SETTLED with no return code, ruling out hold/release since there is no held transfer to act on.
- The alert's sole driver is counterparty history (3 prior unauthorized returns), which is an entity/counterparty-level pattern signal, not isolated to this transaction.
- Program KRI ach_unauthorized_return_rate is in breach status (0.0091, n=877), corroborating that unauthorized returns are an elevated program-wide concern, not a one-off.
- manual_review_aging_hours is also in breach (1438h), suggesting review capacity strain that supports routing this to a person rather than closing.
- Paying entity is verified, low risk, not PEP, and recently screened, which limits concern about the paying side but does not address the counterparty risk driving the alert.
- Confidence is moderate rather than high because the counterparty's country is unknown and no detail on the three prior unauthorized returns (dates, amounts, other transfers) is provided in this context.
Evidence
{
"n": 2220,
"band": "review",
"skoor": 40,
"signals": [
{
"code": "returns.counterparty_prior_unauthorized",
"detail": "3 prior unauthorized return(s)",
"weight": 40
}
],
"confidence": 1,
"routeReason": "detector not auto-closable"
}
Skoor signals
| Signal | Weight | Hard | Detail |
|---|---|---|---|
| returns.counterparty_prior_unauthorized | +40 | 3 prior unauthorized return(s) |
Decision
Sign in as an operator to decide. Operator sign-in →
Dispositions
No disposition yet.
Actions
Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.
No actions requested.