Alert · reviewed · open
The program's ach unauthorized return rate is 0.79% over 883 originated debits, above the 0.5% network threshold.
- Detector
- return_rate_breach
- Severity
- high
- Program
- Harbor Marketplace Payouts (simulated)
- Subject
- program 898ba6ad-5b42-42fd-be7b-2afc9d52af5b
- Transfer
- —
- Skoor at alert
- null unscored
- Hard signal
- no
- Policy
- policy-v1
- Opened
- 2026-09-18 00:15Z
- Closed
- —
- Decision clock
- appeal · due 2026-09-25 00:15Z due 2026-09-25 00:15Z
- Escalated
- —
Draft narrative
What happened. The return_rate_breach detector fired for program 898ba6ad-5b42-42fd-be7b-2afc9d52af5b (Harbor Marketplace Payouts) on 2026-09-18. The program's ACH unauthorized return rate over 883 originated debits is 0.79%, which exceeds the 0.5% network threshold. Route is 'reviewed' per the detector's always-review policy; severity is high.
What the evidence shows. The evidence field confirms n=883, ach_unauthorized_return_rate=0.007927519818799546 (0.79%), status breach, threshold 0.005 (0.5%). The program KRI panel shows the same metric in breach and also shows manual_review_aging_hours=1387.15 hours (n=17) in breach, well above what the ok/watch bands imply. Related watch-level KRIs include hold_aging_hours=1028.7 hours (n=11), overdraft_events=1 (n=3), card_fraud_declines=1 (n=1), pep_flagged_entities=1 (n=30), and high_risk_entity_share=6.67% (n=30). ach_overall_return_rate is 2.60%, higher than the unauthorized-only figure, which is expected since unauthorized returns are a subset. Reserve coverage (1.11), verification denial rate (3.33%), sanctioned_country_transfers (0), and counterparty concentration (7.19%) are within ok range. There is no prior disposition on this program to indicate the breach has already been reviewed or explained.
What was checked. Reviewed the alert evidence block, the full program KRI set, declared program volume and rails, and prior dispositions. Confirmed the unauthorized return rate breach is corroborated by a separate breach in manual_review_aging_hours and by several watch-level indicators (hold aging, overdraft events, card fraud declines, PEP-flagged entities, high-risk entity share). Confirmed the alert score is null (unscored) and hard_signal is false, meaning no automated high-confidence signal has already validated this as escalation-worthy. Confirmed this alert concerns a program-level rate metric, not a specific held transfer, so no funds are currently on hold for this alert.
What is recommended. A person should review the program's ACH return activity and the aging manual-review queue before this reaches the next reporting cycle, given the network threshold breach is paired with a second breach (manual_review_aging_hours) and multiple watch-level indicators on the same program. This combination suggests a pattern across program controls rather than an isolated metric spike, warranting escalation beyond a routine single-alert review.
- Recommendation
- escalate
- Confidence
- 0.62
- Model
- claude-sonnet-5
- Drafted
- 2026-09-18 00:15Z
- Rationale
- ach_unauthorized_return_rate is confirmed in breach at 0.79% against a 0.5% network threshold over a sufficient sample (n=883).
- A second KRI, manual_review_aging_hours, is independently in breach (1387.15 hours, n=17), indicating a possible backlog alongside the return-rate issue.
- Multiple other program KRIs sit at watch level (hold_aging_hours, overdraft_events, card_fraud_declines, pep_flagged_entities, high_risk_entity_share), suggesting broader program-level strain rather than a single isolated metric.
- No prior dispositions exist for this program, so the pattern has not yet been reviewed by a person.
- The alert concerns a program-level rate, not a specific held transfer, so 'release' does not apply; and the presence of a second breach plus several watch flags argues for escalation over a routine hold or close.
- Confidence is moderate rather than high because the alert score is null (unscored) and hard_signal is false, meaning no independent high-confidence signal corroborates this beyond the KRI data itself.
Evidence
{
"n": 883,
"kri": "ach_unauthorized_return_rate",
"unit": "ratio",
"value": 0.007927519818799546,
"status": "breach",
"threshold": 0.005,
"routeReason": "detector always reviewed"
}
Decision
Sign in as an operator to decide. Operator sign-in →
Dispositions
No disposition yet.
Actions
Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.
No actions requested.