Alert · reviewed · held
Counterparty Receiver 40 entered the hold band (Skoor 80, n=12): counterparty.unauthorized_returns, counterparty.unauthorized_rate, counterparty.return_rate, counterparty.new.
- Detector
- counterparty_hold
- Severity
- high
- Program
- Northwind Payroll (simulated)
- Subject
- counterparty cpty_sim_nort_32oue95lqr
- Transfer
- —
- Skoor at alert
- 80 hold
- Hard signal
- no
- Policy
- policy-v1
- Opened
- 2026-09-17 19:31Z
- Closed
- —
- Decision clock
- none · due — no clock
- Escalated
- —
Draft narrative
What happened. Counterparty cpty_sim_nort_32oue95lqr was flagged by the counterparty_hold detector and entered the hold band on 2026-09-17. The alert is routed as reviewed because the detector is not auto-closable, and an auto-hold was applied per policy.
What the evidence shows. Across 12 observed transactions (n=12), the counterparty drew 1 unauthorized return, giving an unauthorized rate of 1/12 that exceeds the network threshold (weight 40 and weight 15 signals). The same single event also drives a return rate of 1/12 (weight 15). The counterparty is new, first seen 0 days ago (weight 10). Combined these signals produced a skoor of 80, landing in the hold band. The detector's own confidence in this score is low (0.268) and hard_signal is false, meaning the score rests on a small sample rather than a confirmed high-certainty signal.
What was checked. The alert evidence block (signals, weights, n, skoor, confidence) was reviewed. Program-level KRIs for Northwind Payroll (ACH, US, declared volume $2,500,000.00/month) were checked for context: ach_unauthorized_return_rate is 0 across 417 transactions and ach_overall_return_rate is 0.96% (n=417), both in the ok range, indicating this single unauthorized return is not part of a broader program-wide unauthorized-return pattern. Two program KRIs are flagged watch (pep_flagged_entities=1/33, high_risk_entity_share=6.1%) and one is in breach (manual_review_aging_hours=1434.7h, n=8), but none of these link specifically to this counterparty in the evidence provided. No prior dispositions exist for this counterparty.
What is recommended. Hold this counterparty's activity pending a person's review. The sample size (n=12) is small and the detector's own confidence is low, so a reviewer should confirm whether the single unauthorized return reflects payer error, a disputed authorization, or a genuine risk pattern before any further transactions with this counterparty are released. This is not a transfer-hold alert, so no release action applies here.
- Recommendation
- hold
- Confidence
- 0.55
- Model
- claude-sonnet-5
- Drafted
- 2026-09-17 19:31Z
- Rationale
- Skoor 80 places the counterparty in the hold band per policy, and autoHold=true was applied.
- The unauthorized return signal (weight 40) is the dominant driver and stems from a single event out of 12 transactions, a small sample.
- Detector confidence is low (0.268) and hard_signal is false, indicating the evidence is suggestive but not conclusive.
- Program-wide ACH unauthorized and overall return rates are both within ok ranges (0% and 0.96% respectively over 417 transactions), so there is no evidence in this alert of a program-wide pattern tying back to this specific counterparty.
- Route is 'reviewed' and detector is marked not auto-closable, meaning policy requires human judgment rather than automatic closure.
- No prior dispositions exist to inform whether this is a repeat pattern for this counterparty.
Evidence
{
"n": 12,
"band": "hold",
"skoor": 80,
"signals": [
{
"code": "counterparty.unauthorized_returns",
"detail": "drew 1 unauthorized return(s)",
"weight": 40
},
{
"code": "counterparty.unauthorized_rate",
"detail": "unauthorized rate 1/12 above the network threshold",
"weight": 15
},
{
"code": "counterparty.return_rate",
"detail": "return rate 1/12",
"weight": 15
},
{
"code": "counterparty.new",
"detail": "first seen 0d ago",
"weight": 10
}
],
"version": "crs-v1",
"autoHold": true,
"confidence": 0.268,
"routeReason": "detector not auto-closable"
}
Decision
Sign in as an operator to decide. Operator sign-in →
Dispositions
No disposition yet.
Actions
Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.
No actions requested.