Alert · reviewed · open
First transfer to a new counterparty, $857.09, above the program's 95th percentile.
- Detector
- first_time_counterparty_large
- Severity
- medium
- Program
- Harbor Marketplace Payouts (simulated)
- Subject
- transfer acht_sim_harb_ar15193w3xz
- Transfer
- acht_sim_harb_ar15193w3xz · $857.09 · ach outgoing
- Skoor at alert
- null unscored
- Hard signal
- no
- Policy
- policy-v1
- Opened
- 2026-09-17 19:31Z
- Closed
- —
- Decision clock
- none · due — no clock
- Escalated
- —
Draft narrative
What happened. A detector flagged transfer acht_sim_harb_ar15193w3xz as a first-time payment to a new counterparty in an amount ($857.09) above the program's 95th percentile threshold ($784.96). The alert was auto-routed for review under the program's standing rule that this detector type always gets reviewed.
What the evidence shows. The transfer is an outgoing ACH credit of $857.09, status COMPLETED, with no return code recorded, created 2026-07-10. The two triggering signals are counterparty.first_time (+10) and counterparty.first_time_and_large (+15); the transfer itself carries no skoor (band unscored, n=14, confidence null), so no independent risk score corroborates the signals. The originating entity, Heath Holdings 119, is VERIFIED, not flagged high risk, not PEP, has no open review reasons, and was screened on 2026-09-01, after this transfer's creation date. The counterparty's country is unknown, but no sanctioned-country or geographic signal fired. Program-level KRIs show ach_unauthorized_return_rate and manual_review_aging_hours in breach and several others in watch status (hold_aging_hours, pep_flagged_entities, high_risk_entity_share), but none of these are tied to this specific transfer or entity in the evidence provided.
What was checked. Transfer status and return code, entity verification and risk/PEP flags, screening recency relative to transfer date, program KRIs for related patterns (sanctioned country transfers, ach return rates, high-risk entity share), and prior dispositions on this alert (none exist).
What is recommended. Close the alert. The transfer has already completed with no return or reversal, the entity is verified with no risk or PEP indicators, and the only evidence is a first-time/large-amount detector trigger with no corroborating skoor or KRI linkage. There is nothing in the evidence to hold on, since the funds have already settled, and no basis to escalate absent a broader pattern tied to this entity or counterparty.
- Recommendation
- close
- Confidence
- 0.62
- Model
- claude-sonnet-5
- Drafted
- 2026-09-17 19:32Z
- Rationale
- Transfer status is COMPLETED with no return code, so a hold/release recommendation does not apply.
- Entity is VERIFIED, not high risk, not PEP, with no open review reasons and screening postdating the transfer.
- Triggering signals (first_time, first_time_and_large) are the only evidence; transfer skoor is null/unscored (n=14), limiting confidence in the alert's own risk assessment.
- Program KRI breaches (ach_unauthorized_return_rate, manual_review_aging_hours) are program-wide metrics with no direct link shown to this transfer or entity, so they do not support escalation on this alert alone.
- No prior dispositions exist to indicate a repeated or worsening pattern for this entity or counterparty.
- Confidence is moderate rather than high because the counterparty's country is unknown and the transfer's own risk band is unscored, leaving some evidentiary thinness.
Evidence
{
"n": 14,
"band": "unscored",
"skoor": null,
"signals": [
{
"code": "counterparty.first_time",
"detail": "first transfer with this counterparty",
"weight": 10
},
{
"code": "counterparty.first_time_and_large",
"detail": "amount above the program p95 (78496)",
"weight": 15
}
],
"routeReason": "detector always reviewed"
}
Skoor signals
| Signal | Weight | Hard | Detail |
|---|---|---|---|
| counterparty.first_time | +10 | first transfer with this counterparty | |
| counterparty.first_time_and_large | +15 | amount above the program p95 (78496) |
Decision
Sign in as an operator to decide. Operator sign-in →
Dispositions
No disposition yet.
Actions
Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.
No actions requested.