Alert · reviewed · open
Transaction Risk Skoor 55 (review band) on a $620.16 ach transfer: returns.counterparty_prior_unauthorized, returns.entity_rate_gt_threshold.
- Detector
- skoor_review
- Severity
- medium
- Program
- Harbor Marketplace Payouts (simulated)
- Subject
- transfer acht_sim_harb_1n73ur078t0
- Transfer
- acht_sim_harb_1n73ur078t0 · $620.16 · ach outgoing
- Skoor at alert
- 55 review
- Hard signal
- no
- Policy
- policy-v1
- Opened
- 2026-09-17 19:31Z
- Closed
- —
- Decision clock
- none · due — no clock
- Escalated
- —
Draft narrative
What happened. A ach outgoing credit transfer of $620.16 (acht_sim_harb_1n73ur078t0) on program Harbor Marketplace Payouts (simulated) was flagged by detector skoor_review: Transaction Risk Skoor 55 (review band) on a $620.16 ach transfer: returns.counterparty_prior_unauthorized, returns.entity_rate_gt_threshold..
What the evidence shows. Transaction Risk Skoor 55 (band review). Signals: returns.counterparty_prior_unauthorized (+40), returns.entity_rate_gt_threshold (+15). Entity Larch Studio 111: verification VERIFIED, PEP no, high risk no.
What was checked. Program KRIs as of the latest snapshot: frozen_accounts ok, hold_aging_hours watch, overdraft_events ok, manual_review_rate ok, card_fraud_declines unmeasured, pep_flagged_entities watch, velocity_vs_declared ok, stale_screening_share ok, high_risk_entity_share watch, reserve_coverage_ratio ok, ach_overall_return_rate ok, verification_denial_rate ok, manual_review_aging_hours breach, ach_unauthorized_return_rate breach, sanctioned_country_transfers ok, ach_administrative_return_rate ok, counterparty_concentration_top1 ok. No prior dispositions on this entity or counterparty.
What is recommended. Recommended: escalate. A person decides; this draft was assembled from the evidence without a model (model call failed).
- Recommendation
- escalate
- Confidence
- null (template, no model)
- Model
- none (template)
- Drafted
- 2026-09-17 19:32Z
- Rationale
- Template draft: recommendation follows the band and the hard-signal rule only.
Evidence
{
"n": 1915,
"band": "review",
"skoor": 55,
"signals": [
{
"code": "returns.counterparty_prior_unauthorized",
"detail": "2 prior unauthorized return(s)",
"weight": 40
},
{
"code": "returns.entity_rate_gt_threshold",
"detail": "entity unauthorized return rate 1/28 originated ACH debits in 60d",
"weight": 15
}
],
"confidence": 1,
"routeReason": "detector not auto-closable"
}
Skoor signals
| Signal | Weight | Hard | Detail |
|---|---|---|---|
| returns.counterparty_prior_unauthorized | +40 | 2 prior unauthorized return(s) | |
| returns.entity_rate_gt_threshold | +15 | entity unauthorized return rate 1/28 originated ACH debits in 60d |
Decision
Sign in as an operator to decide. Operator sign-in →
Dispositions
No disposition yet.
Actions
Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.
No actions requested.