Alert · reviewed · open
Transaction Risk Skoor 40 (review band) on a $488.15 ach transfer: returns.counterparty_prior_unauthorized.
- Detector
- skoor_review
- Severity
- medium
- Program
- Harbor Marketplace Payouts (simulated)
- Subject
- transfer acht_sim_harb_x17u1xl900
- Transfer
- acht_sim_harb_x17u1xl900 · $488.15 · ach outgoing
- Skoor at alert
- 40 review
- Hard signal
- no
- Policy
- policy-v1
- Opened
- 2026-09-17 19:32Z
- Closed
- —
- Decision clock
- none · due — no clock
- Escalated
- —
Draft narrative
What happened. Alert c8ba602f-cc00-47a6-a815-b8eda344cbca fired on outgoing ACH transfer acht_sim_harb_x17u1xl900, a $488.15 debit under the Harbor Marketplace Payouts program. The skoor_review detector scored the transfer 40 (review band, hard_signal false) on the single signal returns.counterparty_prior_unauthorized, weight 40, citing 2 prior unauthorized returns for the counterparty. The transfer status is SETTLED with return code none; the alert was auto-routed to review because the detector is not auto-closable.
What the evidence shows. The counterparty cpty_sim_harb_27gwzr6k4hg has a documented history of 2 prior unauthorized returns, which is the sole driver of the score. The transfer itself settled cleanly with no return code, so no loss or reversal has occurred on this specific transaction. The originating entity, Payout Agent (Harbor), is VERIFIED, not high risk, not PEP, and was screened 2026-09-02 with no open review reasons. Program-level KRIs show ach_unauthorized_return_rate at 0.86% (n=812) flagged as a breach, and manual_review_aging_hours at 1438 hours (n=15) also flagged as breach. Other KRIs (overall return rate, administrative return rate, velocity vs declared, concentration) are within ok/watch ranges. No prior dispositions exist for this alert.
What was checked. Reviewed the alert evidence and signal detail, transfer record (status, amount, return code, counterparty), entity verification and screening status, and the program KRI panel for corroborating or contradicting signals. No hold is in place on this transfer (status SETTLED), so there is no fund-movement decision pending on this alert.
What is recommended. Because the transfer has already settled, there is no transfer to hold or release. The unauthorized-return history on this specific counterparty, combined with the program-wide breach on ach_unauthorized_return_rate, indicates this may not be an isolated counterparty issue but part of a broader pattern within the program. A person should review the counterparty's full transaction history across the program and the breach on manual_review_aging_hours to determine whether this counterparty or a related set of counterparties should be restricted from future payouts.
- Recommendation
- escalate
- Confidence
- 0.62
- Model
- claude-sonnet-5
- Drafted
- 2026-09-17 19:32Z
- Rationale
- Detector signal is a single factor (counterparty_prior_unauthorized) but reflects 2 confirmed prior unauthorized returns, not a one-off.
- Program KRI ach_unauthorized_return_rate is flagged 'breach', indicating the program-wide unauthorized return issue extends beyond this one alert.
- manual_review_aging_hours is also flagged 'breach' (1438 hours, n=15), suggesting reviews in this program are not being closed promptly, which supports escalation rather than a routine close.
- Transfer is already SETTLED with no return code, so 'hold' or 'release' do not apply; no funds are currently pending movement on this alert.
- Originating entity is verified, low risk, and has no open review reasons, which weighs against escalating the entity itself but does not offset the counterparty-level and program-level signals.
- Evidence is limited to counts and rates without transaction-level detail on the prior unauthorized returns (dates, amounts), so confidence is moderate, not high.
Evidence
{
"n": 2034,
"band": "review",
"skoor": 40,
"signals": [
{
"code": "returns.counterparty_prior_unauthorized",
"detail": "2 prior unauthorized return(s)",
"weight": 40
}
],
"confidence": 1,
"routeReason": "detector not auto-closable"
}
Skoor signals
| Signal | Weight | Hard | Detail |
|---|---|---|---|
| returns.counterparty_prior_unauthorized | +40 | 2 prior unauthorized return(s) |
Decision
Sign in as an operator to decide. Operator sign-in →
Dispositions
No disposition yet.
Actions
Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.
No actions requested.