Alert · reviewed · open
Activity on an entity flagged by screening (PEP status no, high risk).
- Detector
- sanctions_or_pep
- Severity
- high
- Program
- Harbor Marketplace Payouts (simulated)
- Subject
- entity enti_sim_harb_skonrvy3x6
- Transfer
- acht_sim_harb_ay5c05sd3zz · $445.70 · ach outgoing
- Skoor at alert
- null unscored
- Hard signal
- no
- Policy
- policy-v1
- Opened
- 2026-09-17 19:30Z
- Closed
- —
- Decision clock
- none · due — no clock
- Escalated
- —
Draft narrative
What happened. Alert ade6051d-ce5c-4d84-9cef-81dff5c02007 was opened by the sanctions_or_pep detector on 2026-09-17 for entity enti_sim_harb_skonrvy3x6, part of the Harbor Marketplace Payouts program. The detector routes to review on every hit by design (routeReason: 'detector always reviewed'), and the entity was flagged as high risk by screening.
What the evidence shows. The entity record shows PEP status 'no', verification status VERIFIED, and review reasons 'none'. The only signal present is entity.high_risk (weight 20), with no sanctions list match, no adverse media hit, and no other corroborating signal despite n=4. The associated transfer, acht_sim_harb_ay5c05sd3zz, is a single outgoing ACH credit for $445.70 USD, already SETTLED, with no return code. The transfer itself carries an unscored, unconfident risk band (skoor null, n=4, confidence null) and hard_signal is false. The entity was last screened 2026-06-26, about three months before this alert opened, with no new reason cited for re-flagging. There are no prior dispositions on this entity or transfer.
What was checked. Reviewed the alert evidence block, the entity screening record, the transfer record, and program declared volume/rails. Checked for a specific sanctions or PEP match, adverse media reason, or return code on the transfer. None found. Checked whether the transfer is still pending or held; it is already settled, so a hold or release recommendation would not apply to it.
What is recommended. Close the alert. The evidence consists of a single generic high-risk flag from screening with no PEP status, no sanctions match, no adverse review reason, and a verified entity identity. The linked transfer is a small, already-settled ACH credit ($445.70) with no return code, well within the program's declared $4,000,000 monthly volume. There is no basis in the evidence for holding funds (already settled) or for escalating (no pattern across multiple transfers or entities is shown; n=4 signals but only one signal is populated). If future screening produces a specific sanctions or PEP match, or if the entity's high-risk flag is later paired with adverse detail, the alert should be reopened for review.
- Recommendation
- close
- Confidence
- 0.62
- Model
- claude-sonnet-5
- Drafted
- 2026-09-17 19:30Z
- Rationale
- Detector routes to review automatically regardless of substance, so the routing itself is not evidence of risk.
- PEP is 'no' and review reasons are 'none'; the only populated signal is a generic entity.high_risk flag with no specific detail.
- Entity verification status is VERIFIED, reducing identity risk concern.
- Transfer is already SETTLED with no return code, so 'hold' or 'release' does not apply.
- Only one transfer is evidenced; no pattern across multiple transfers or entities supports escalation.
- Score band is unscored with confidence null, indicating thin scoring data; confidence in this disposition is held below 0.7 for that reason.
Evidence
{
"n": 4,
"band": "unscored",
"skoor": null,
"signals": [
{
"code": "entity.high_risk",
"detail": "entity marked high risk by screening",
"weight": 20
}
],
"routeReason": "detector always reviewed"
}
Skoor signals
| Signal | Weight | Hard | Detail |
|---|---|---|---|
| entity.high_risk | +20 | entity marked high risk by screening |
Decision
Sign in as an operator to decide. Operator sign-in →
Dispositions
No disposition yet.
Actions
Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.
No actions requested.