SKOOR Risk Money movement. Skoored by AI.

Alert · reviewed · open

Transaction Risk Skoor 40 (review band) on a $230.57 ach transfer: returns.counterparty_prior_unauthorized.

Detector
skoor_review
Severity
medium
Program
Harbor Marketplace Payouts (simulated)
Subject
transfer acht_sim_harb_4x373e5n8nd
Transfer
acht_sim_harb_4x373e5n8nd · $230.57 · ach outgoing
Skoor at alert
40 review
Hard signal
no
Policy
policy-v1
Opened
2026-09-17 19:31Z
Closed
Decision clock
none · due — no clock
Escalated

Draft narrative

What happened. Alert bc2711c3-e671-437c-b584-36e45aa42463 was generated by the skoor_review detector on an outgoing ACH transfer (acht_sim_harb_4x373e5n8nd) of $230.57 from the Harbor Marketplace Payouts program. The transfer risk score was 40, placing it in the review band, driven entirely by one signal: the counterparty has one prior unauthorized ACH return. What the evidence shows. The transfer is outgoing, has settled, and carries no return code, meaning no funds are in a held or reversible state. The subject entity, Heath Holdings 119, is verified, not flagged high risk, not a PEP, has no open review reasons, and was screened on 2026-09-01. The single signal contributing to the score is one prior unauthorized return on the counterparty, weighted at 40 out of a possible higher band; there is no additional signal stacking. Program-level KRIs show ach_unauthorized_return_rate and manual_review_aging_hours in breach status, and pep_flagged_entities, high_risk_entity_share, hold_aging_hours in watch status, but none of these are tied to this specific transfer or entity beyond the single counterparty return already reflected in the score. There are no prior dispositions on this alert. What was checked. Transfer status and return code, entity verification and risk flags, screening recency, signal composition and weighting, program KRI panel for corroborating pattern, and prior disposition history. What is recommended. Close the alert. The transfer has already settled with no return code, so there is no fund-holding decision to make. The only driver of the score is one historical unauthorized return on the counterparty, and the subject entity is verified with no other risk indicators. The program-level KRI breaches (ach_unauthorized_return_rate, manual_review_aging_hours) are noted for portfolio monitoring but are not evidenced as connected to this specific transfer or entity, so they do not support escalation on this alert alone.
Recommendation
close
Confidence
0.72
Model
claude-sonnet-5
Drafted
2026-09-17 19:32Z
Rationale
  • Transfer status is SETTLED with return code none; there is no held transfer to act on, so release does not apply.
  • Entity is VERIFIED, not high risk, not PEP, with no open review reasons and recent screening (2026-09-01).
  • Score is driven by a single signal (one prior unauthorized return, weight 40) with no signal stacking evidenced.
  • Program KRI breaches on ach_unauthorized_return_rate and manual_review_aging_hours are portfolio-level and not directly tied to this transfer or counterparty in the evidence provided, so they support monitoring rather than escalation of this specific alert.
  • No prior dispositions exist to indicate a recurring or worsening pattern for this entity or counterparty.

Evidence

{
  "n": 1848,
  "band": "review",
  "skoor": 40,
  "signals": [
    {
      "code": "returns.counterparty_prior_unauthorized",
      "detail": "1 prior unauthorized return(s)",
      "weight": 40
    }
  ],
  "confidence": 1,
  "routeReason": "detector not auto-closable"
}

Skoor signals

SignalWeightHardDetail
returns.counterparty_prior_unauthorized+403 prior unauthorized return(s)

Decision

Sign in as an operator to decide. Operator sign-in →

Dispositions

No disposition yet.

Actions

Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.

No actions requested.