SKOOR Risk Money movement. Skoored by AI.

Alert · reviewed · open

The entity's first transfer, $598.19, above the program median, came 0.0 hours after verification.

Detector
rapid_onboarding
Severity
medium
Program
Harbor Marketplace Payouts (simulated)
Subject
transfer acht_sim_harb_71odv4fo42b
Transfer
acht_sim_harb_71odv4fo42b · $598.19 · ach outgoing
Skoor at alert
null unscored
Hard signal
no
Policy
policy-v1
Opened
2026-09-17 19:30Z
Closed
Decision clock
none · due — no clock
Escalated

Draft narrative

What happened. An alert fired for rapid onboarding on entity Larch Studio 123 (enti_sim_harb_3fas9a73wv) under the Harbor Marketplace Payouts program. The alert cites the entity's first transfer, an outgoing ACH credit of $598.19 (acht_sim_harb_71odv4fo42b), occurring 0.0 hours after verification, above the program median of $463.32. What the evidence shows. The transfer is an outgoing ACH credit for $598.19, status SETTLED, with no return code. The entity is a verified US business, not flagged high risk, not PEP, with no review reasons on file, last screened 2026-06-28. The transfer skoor is null/unscored with n=4 and confidence null, meaning there is insufficient volume to generate a model score. The routeReason field states the alert was routed for review only because the detector is not auto-closable, not because of an elevated score. There are no prior dispositions on this entity. What was checked. Reviewed the transfer status, return code, and settlement outcome. Reviewed entity verification status, risk flags, PEP status, and screening history. Reviewed the scoring evidence block for skoor, band, and confidence. Confirmed no prior alerts or dispositions exist for this entity. What is recommended. The transfer has already settled with no return code and no indication of dispute or reversal. The entity is verified, not high risk, not PEP, and has no open review reasons. The scoring model has insufficient data (n=4, unscored) to support any risk determination beyond the raw timing observation, which by itself is a common pattern for marketplace payout onboarding. No evidence in this alert requires a person to intervene before funds move, since funds have already moved and settled without issue. Recommend closing the alert.
Recommendation
close
Confidence
0.62
Model
claude-sonnet-5
Drafted
2026-09-17 19:30Z
Rationale
  • Transfer status is SETTLED with no return code, indicating no failure or reversal occurred.
  • Entity is VERIFIED, not high risk, not PEP, with no review reasons and recent screening.
  • Transfer skoor is null/unscored with n=4 and confidence null; the evidence base is too thin to support an escalation decision on score alone.
  • routeReason indicates the alert was routed for review due to detector configuration (not auto-closable), not due to elevated risk signal (hard signal is false, band unscored).
  • No prior dispositions exist to suggest a repeating or escalating pattern for this entity.
  • Recommendation to close reflects the absence of any evidence requiring further human action before funds move, since funds already settled.

Evidence

{
  "n": 4,
  "band": "unscored",
  "skoor": null,
  "typology": "rapid_onboarding",
  "confidence": null,
  "thresholds": {
    "hours": 24
  },
  "medianCents": "46332",
  "routeReason": "detector not auto-closable",
  "hoursSinceVerification": 0
}

Decision

Sign in as an operator to decide. Operator sign-in →

Dispositions

No disposition yet.

Actions

Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.

No actions requested.