SKOOR Risk Money movement. Skoored by AI.

Alert · reviewed · held

Counterparty Receiver 40 entered the hold band (Skoor 80, n=12): counterparty.unauthorized_returns, counterparty.unauthorized_rate, counterparty.return_rate, counterparty.new.

Detector
counterparty_hold
Severity
high
Program
Northwind Payroll (simulated)
Subject
counterparty cpty_sim_nort_32oue95lqr
Transfer
Skoor at alert
80 hold
Hard signal
no
Policy
policy-v1
Opened
2026-09-17 19:31Z
Closed
Decision clock
none · due — no clock
Escalated

Draft narrative

What happened. Counterparty cpty_sim_nort_32oue95lqr was flagged by the counterparty_hold detector and entered the hold band on 2026-09-17. The alert is routed as reviewed because the detector is not auto-closable, and an auto-hold was applied per policy. What the evidence shows. Across 12 observed transactions (n=12), the counterparty drew 1 unauthorized return, giving an unauthorized rate of 1/12 that exceeds the network threshold (weight 40 and weight 15 signals). The same single event also drives a return rate of 1/12 (weight 15). The counterparty is new, first seen 0 days ago (weight 10). Combined these signals produced a skoor of 80, landing in the hold band. The detector's own confidence in this score is low (0.268) and hard_signal is false, meaning the score rests on a small sample rather than a confirmed high-certainty signal. What was checked. The alert evidence block (signals, weights, n, skoor, confidence) was reviewed. Program-level KRIs for Northwind Payroll (ACH, US, declared volume $2,500,000.00/month) were checked for context: ach_unauthorized_return_rate is 0 across 417 transactions and ach_overall_return_rate is 0.96% (n=417), both in the ok range, indicating this single unauthorized return is not part of a broader program-wide unauthorized-return pattern. Two program KRIs are flagged watch (pep_flagged_entities=1/33, high_risk_entity_share=6.1%) and one is in breach (manual_review_aging_hours=1434.7h, n=8), but none of these link specifically to this counterparty in the evidence provided. No prior dispositions exist for this counterparty. What is recommended. Hold this counterparty's activity pending a person's review. The sample size (n=12) is small and the detector's own confidence is low, so a reviewer should confirm whether the single unauthorized return reflects payer error, a disputed authorization, or a genuine risk pattern before any further transactions with this counterparty are released. This is not a transfer-hold alert, so no release action applies here.
Recommendation
hold
Confidence
0.55
Model
claude-sonnet-5
Drafted
2026-09-17 19:31Z
Rationale
  • Skoor 80 places the counterparty in the hold band per policy, and autoHold=true was applied.
  • The unauthorized return signal (weight 40) is the dominant driver and stems from a single event out of 12 transactions, a small sample.
  • Detector confidence is low (0.268) and hard_signal is false, indicating the evidence is suggestive but not conclusive.
  • Program-wide ACH unauthorized and overall return rates are both within ok ranges (0% and 0.96% respectively over 417 transactions), so there is no evidence in this alert of a program-wide pattern tying back to this specific counterparty.
  • Route is 'reviewed' and detector is marked not auto-closable, meaning policy requires human judgment rather than automatic closure.
  • No prior dispositions exist to inform whether this is a repeat pattern for this counterparty.

Evidence

{
  "n": 12,
  "band": "hold",
  "skoor": 80,
  "signals": [
    {
      "code": "counterparty.unauthorized_returns",
      "detail": "drew 1 unauthorized return(s)",
      "weight": 40
    },
    {
      "code": "counterparty.unauthorized_rate",
      "detail": "unauthorized rate 1/12 above the network threshold",
      "weight": 15
    },
    {
      "code": "counterparty.return_rate",
      "detail": "return rate 1/12",
      "weight": 15
    },
    {
      "code": "counterparty.new",
      "detail": "first seen 0d ago",
      "weight": 10
    }
  ],
  "version": "crs-v1",
  "autoHold": true,
  "confidence": 0.268,
  "routeReason": "detector not auto-closable"
}

Decision

Sign in as an operator to decide. Operator sign-in →

Dispositions

No disposition yet.

Actions

Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.

No actions requested.