Alert · reviewed · open
13 transfer(s) have sat in manual review for up to 1439 hours.
- Detector
- manual_review_aging
- Severity
- medium
- Program
- Northwind Payroll (simulated)
- Subject
- program 030a8115-8109-4bdc-8e82-65ec40280d47
- Transfer
- —
- Skoor at alert
- null unscored
- Hard signal
- no
- Policy
- policy-v1
- Opened
- 2026-09-18 00:14Z
- Closed
- —
- Decision clock
- appeal · due 2026-09-25 00:14Z due 2026-09-25 00:14Z
- Escalated
- —
Draft narrative
What happened. Detector manual_review_aging raised an alert on program 030a8115-8109-4bdc-8e82-65ec40280d47 for program Northwind Payroll (simulated): 13 transfer(s) have sat in manual review for up to 1439 hours..
What the evidence shows. The transaction was unscored: too little history for a Skoor.
What was checked. Program KRIs as of the latest snapshot: frozen_accounts ok, hold_aging_hours watch, overdraft_events ok, manual_review_rate ok, card_fraud_declines unmeasured, pep_flagged_entities watch, velocity_vs_declared ok, stale_screening_share ok, high_risk_entity_share watch, reserve_coverage_ratio ok, ach_overall_return_rate ok, verification_denial_rate ok, manual_review_aging_hours breach, ach_unauthorized_return_rate ok, sanctioned_country_transfers ok, ach_administrative_return_rate ok, counterparty_concentration_top1 ok. No prior dispositions on this entity or counterparty.
What is recommended. Recommended: escalate. A person decides; this draft was assembled from the evidence without a model (model output did not match the schema).
- Recommendation
- escalate
- Confidence
- null (template, no model)
- Model
- none (template)
- Drafted
- 2026-09-18 00:15Z
- Rationale
- Template draft: recommendation follows the band and the hard-signal rule only.
Evidence
{
"n": 13,
"kri": "manual_review_aging_hours",
"unit": "hours",
"value": 1439.40326,
"status": "breach",
"threshold": 48,
"routeReason": "detector not auto-closable"
}
Decision
Sign in as an operator to decide. Operator sign-in →
Dispositions
No disposition yet.
Actions
Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.
No actions requested.