SKOOR Risk Money movement. Skoored by AI.

Alert · reviewed · held

Counterparty Receiver 85 entered the hold band (Skoor 90, n=3): counterparty.unauthorized_returns, counterparty.unauthorized_rate, counterparty.return_rate, counterparty.review_share, counterparty.new.

Detector
counterparty_hold
Severity
high
Program
Harbor Marketplace Payouts (simulated)
Subject
counterparty cpty_sim_harb_5p4yfvh5vq
Transfer
Skoor at alert
90 hold
Hard signal
no
Policy
policy-v1
Opened
2026-09-17 19:31Z
Closed
Decision clock
none · due — no clock
Escalated

Draft narrative

What happened. A counterparty_hold detector fired on counterparty cpty_sim_harb_5p4yfvh5vq, placing it in the hold band with a Skoor of 90 based on n=3 observed transactions. The alert was opened 2026-09-17T19:31:52.763Z and routed for review because the detector is not auto-closable. What the evidence shows. Of 3 transactions from this counterparty, 1 was an unauthorized return (33% unauthorized rate, 33% overall return rate), which exceeds the network threshold and drove the largest share of the score (weight 40 of 90). The counterparty is newly seen (0 days) and 67% of its activity sits in the review band. The detector's own confidence is low (0.142) and hard_signal is false, meaning no independent corroborating signal outside the model score. There are no prior dispositions for this counterparty. What was checked. Program-level KRIs were checked for context: ach_unauthorized_return_rate is flagged breach at 0.81% across n=742, and manual_review_aging_hours is flagged breach at 1438 hours across n=12, with hold_aging_hours also at watch (1024 hours, n=11). These are program-wide metrics, not counterparty-specific, so they do not confirm or rule out a pattern tied to this counterparty. Other KRIs (frozen_accounts, overdraft_events, sanctioned_country_transfers, velocity_vs_declared, reserve_coverage_ratio) are at ok or watch and show nothing specific to this counterparty. No prior alert history exists for this counterparty to compare against. What is recommended. Hold. The sample size (n=3) is too thin to draw a firm conclusion, but the one unauthorized return on a brand-new counterparty is a signal that should not be dismissed without a person reviewing the underlying transaction and counterparty details before any further funds move to or from this counterparty. The program-level breach on aging manual reviews (1438 hours) also suggests this alert should not sit in queue indefinitely.
Recommendation
hold
Confidence
0.45
Model
claude-sonnet-5
Drafted
2026-09-17 19:32Z
Rationale
  • n=3 is a thin sample; the 33% unauthorized rate is a single event, not a repeated pattern, so certainty about counterparty behavior is limited.
  • Detector confidence is explicitly low (0.142) and hard_signal is false, meaning the score reflects a model band rather than a confirmed hard fact.
  • The counterparty is new (0 days old), which typically warrants closer human review before closing an alert involving an unauthorized return.
  • routeReason states the detector is not auto-closable, indicating the system itself requires human disposition rather than automated close.
  • Program-wide manual_review_aging_hours and ach_unauthorized_return_rate are in breach, which does not implicate this specific counterparty but supports not deprioritizing the review.
  • No prior dispositions exist for this counterparty, so there is no track record to lean on for a close recommendation.

Evidence

{
  "n": 3,
  "band": "hold",
  "skoor": 90,
  "signals": [
    {
      "code": "counterparty.unauthorized_returns",
      "detail": "drew 1 unauthorized return(s)",
      "weight": 40
    },
    {
      "code": "counterparty.unauthorized_rate",
      "detail": "unauthorized rate 1/3 above the network threshold",
      "weight": 15
    },
    {
      "code": "counterparty.return_rate",
      "detail": "return rate 1/3",
      "weight": 15
    },
    {
      "code": "counterparty.review_share",
      "detail": "67% in the review band",
      "weight": 10
    },
    {
      "code": "counterparty.new",
      "detail": "first seen 0d ago",
      "weight": 10
    }
  ],
  "version": "crs-v1",
  "autoHold": true,
  "confidence": 0.142,
  "routeReason": "detector not auto-closable"
}

Decision

Sign in as an operator to decide. Operator sign-in →

Dispositions

No disposition yet.

Actions

Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.

No actions requested.