Alert · reviewed · held
Transaction Risk Skoor 90 (hold band) on a $2,400.00 ach transfer: entity.denied, entity.high_risk, amount.gt_3x_median.
- Detector
- skoor_hold
- Severity
- high
- Program
- Harbor Marketplace Payouts (simulated)
- Subject
- transfer acht_sim_harb_6mf9ak9b9ki
- Transfer
- acht_sim_harb_6mf9ak9b9ki · $2,400.00 · ach outgoing
- Skoor at alert
- 90 hold
- Hard signal
- yes
- Policy
- policy-v1
- Opened
- 2026-09-17 19:31Z
- Closed
- —
- Decision clock
- none · due — no clock
- Escalated
- —
Draft narrative
What happened. Alert b8ea9070-c416-4359-9bb0-c02e0841a514 fired on ACH outgoing transfer acht_sim_harb_6mf9ak9b9ki for $2,400.00 under program Harbor Marketplace Payouts. The skoor engine scored the transaction 90 (hold band, n=954, confidence 0.7) and set autoHold true based on a hard signal. Despite this, the transfer record shows status SETTLED, created 2026-08-09T20:25:42.000Z, with no return code.
What the evidence shows. Three signals drove the score: entity.denied (hard, weight 60) — the counterparty entity enti_sim_harb_130qwgg53wz, a person named 'Denied Origin 1', has verification status DENIED with review reason sanctions_match, last screened 2026-06-24. entity.high_risk (weight 20) confirms the entity is flagged high risk. amount.gt_3x_median (weight 10) shows the $2,400.00 amount exceeds 3x the program median of $425.39. The hard signal (entity.denied) alone should have forced a hold, per routeReason 'hard signal' and autoHold true, yet the transfer already settled. Program KRIs show pep_flagged_entities and high_risk_entity_share at 'watch', and manual_review_aging_hours plus ach_unauthorized_return_rate at 'breach', indicating broader review-timeliness and unauthorized-return issues in this program.
What was checked. Reviewed the alert signals, transfer status and timestamps, the linked entity's verification and screening record, and program-level KRIs. No prior dispositions exist for this alert. The transfer's counterparty country is unknown, and no return code is present, so no reversal or unauthorized-return action has been recorded against this settled transfer.
What is recommended. This transfer settled despite a hard-hold signal (denied entity verification with a sanctions_match reason) and autoHold true, which indicates a control gap between the skoor hold decision and payment execution rather than a single false positive. A person should review why the hold did not prevent settlement, confirm whether the entity's sanctions_match requires a filing or fund recovery action, and check whether other transfers tied to this entity or program window settled under the same gap. This is escalated rather than closed or held, since the transfer cannot be held post-settlement and the underlying issue (hard-hold bypass) may affect more than this one alert.
- Recommendation
- escalate
- Confidence
- 0.78
- Model
- claude-sonnet-5
- Drafted
- 2026-09-17 19:31Z
- Rationale
- Hard signal entity.denied (weight 60) with review reason sanctions_match on a verified-DENIED entity, per evidence.signals and ENTITY record.
- autoHold was true and routeReason was 'hard signal', yet TRANSFER status is SETTLED with no return code, indicating the hold did not stop fund movement.
- Because the transfer is already settled, 'hold' is not actionable (funds have moved) and 'release' does not apply (no active hold to release).
- Entity is also marked high_risk and amount exceeds 3x program median, reinforcing risk rather than mitigating it.
- Program KRIs show pep_flagged_entities and high_risk_entity_share at watch and manual_review_aging_hours and ach_unauthorized_return_rate at breach, consistent with a broader pattern of delayed or bypassed controls worth review beyond this single alert.
- No prior dispositions exist to indicate this gap has already been addressed.
Evidence
{
"n": 954,
"band": "hold",
"skoor": 90,
"signals": [
{
"code": "entity.denied",
"hard": true,
"detail": "entity verification DENIED",
"weight": 60
},
{
"code": "entity.high_risk",
"detail": "entity marked high risk by screening",
"weight": 20
},
{
"code": "amount.gt_3x_median",
"detail": "amount > 3× program median (42539)",
"weight": 10
}
],
"autoHold": true,
"confidence": 0.7,
"routeReason": "hard signal"
}
Skoor signals
| Signal | Weight | Hard | Detail |
|---|---|---|---|
| entity.denied | +60 | yes | entity verification DENIED |
| entity.high_risk | +20 | entity marked high risk by screening | |
| returns.counterparty_prior_any | +15 | 1 prior return(s) other than NSF | |
| amount.gt_3x_median | +10 | amount > 3× program median (42539) |
Decision
Sign in as an operator to decide. Operator sign-in →
Dispositions
No disposition yet.
Actions
Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.
No actions requested.