SKOOR Risk Money movement. Skoored by AI.

Alert · reviewed · open

Transaction Risk Skoor 55 (review band) on a $376.50 ach transfer: returns.counterparty_prior_unauthorized, returns.entity_rate_gt_threshold.

Detector
skoor_review
Severity
medium
Program
Harbor Marketplace Payouts (simulated)
Subject
transfer acht_sim_harb_90w3r1nj8tf
Transfer
acht_sim_harb_90w3r1nj8tf · $376.50 · ach outgoing
Skoor at alert
55 review
Hard signal
no
Policy
policy-v1
Opened
2026-09-17 19:31Z
Closed
Decision clock
none · due — no clock
Escalated

Draft narrative

What happened. Alert acb39615-246c-410b-9d79-4f17009d44b4 fired on outgoing ACH credit (payout) acht_sim_harb_90w3r1nj8tf for $376.50 from program Harbor Marketplace Payouts to counterparty cpty_sim_harb_362c8piz3xi. The transaction risk score was 55 (review band, hard signal false), driven by two signals: one prior unauthorized return for this counterparty (weight 40) and an entity-level unauthorized return rate of 1/42 originated ACH debits in 60 days exceeding threshold (weight 15). What the evidence shows. The transfer is a CREDIT, status SETTLED, with no return code recorded, so the funds have already moved and no return has occurred on this transfer itself. The entity (Juniper LLC 19) is VERIFIED, not flagged high risk, not PEP, with no open review reasons and a screening date of 2026-09-03, before the transfer's creation. The entity-level unauthorized return rate cited (1/42) reflects the entity's ACH debit activity, not this credit transfer, and is a single historical occurrence. Program KRIs show ach_unauthorized_return_rate and manual_review_aging_hours in breach status, but these are program-wide metrics (n=767 and n=14 respectively) not specific to this entity or counterparty, and no prior dispositions exist tying this alert to a broader pattern. What was checked. Transfer status and return code, entity verification and screening status, program KRI panel, and prior dispositions for this alert or related entity. No return has posted against this transfer, and no other alerts on this entity are on record. What is recommended. Close the alert. The transfer has settled with no return, the entity is verified with no open risk flags, and the underlying signals reference a single historical counterparty return and a low entity return rate that do not, on this evidence, indicate an active or escalating problem tied to this specific transfer. The program-level KRI breaches (ach_unauthorized_return_rate, manual_review_aging_hours) are noted for separate program-level monitoring but are not evidenced here as connected to this entity or transfer.
Recommendation
close
Confidence
0.68
Model
claude-sonnet-5
Drafted
2026-09-17 19:32Z
Rationale
  • Transfer is SETTLED with no return code; no funds are pending or held on this alert.
  • Entity is VERIFIED, not high risk, not PEP, with no open review reasons.
  • Signals reflect one historical counterparty unauthorized return and a modest entity debit return rate (1/42), not a hard signal.
  • Program KRI breaches (ach_unauthorized_return_rate, manual_review_aging_hours) are program-wide and not directly linked in the evidence to this entity or transfer.
  • No prior dispositions exist indicating a recurring pattern for this entity or counterparty.

Evidence

{
  "n": 1951,
  "band": "review",
  "skoor": 55,
  "signals": [
    {
      "code": "returns.counterparty_prior_unauthorized",
      "detail": "1 prior unauthorized return(s)",
      "weight": 40
    },
    {
      "code": "returns.entity_rate_gt_threshold",
      "detail": "entity unauthorized return rate 1/42 originated ACH debits in 60d",
      "weight": 15
    }
  ],
  "confidence": 1,
  "routeReason": "detector not auto-closable"
}

Skoor signals

SignalWeightHardDetail
returns.counterparty_prior_unauthorized+401 prior unauthorized return(s)
returns.entity_rate_gt_threshold+15entity unauthorized return rate 1/42 originated ACH debits in 60d

Decision

Sign in as an operator to decide. Operator sign-in →

Dispositions

No disposition yet.

Actions

Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.

No actions requested.