Alert · reviewed · open
First transfer to a new counterparty, $777.33, above the program's 95th percentile.
- Detector
- first_time_counterparty_large
- Severity
- medium
- Program
- Harbor Marketplace Payouts (simulated)
- Subject
- transfer acht_sim_harb_9xfxgwmw3yn
- Transfer
- acht_sim_harb_9xfxgwmw3yn · $777.33 · ach outgoing
- Skoor at alert
- null unscored
- Hard signal
- no
- Policy
- policy-v1
- Opened
- 2026-09-17 19:31Z
- Closed
- —
- Decision clock
- none · due — no clock
- Escalated
- —
Draft narrative
What happened. A first-time transfer of $777.33 to a new counterparty was flagged because it exceeded the program's 95th percentile threshold ($756.67). The detector fired due to two signals: counterparty.first_time and counterparty.first_time_and_large.
What the evidence shows. The transfer is an outgoing ACH credit with status COMPLETED and no return code, indicating no failure or rejection occurred. The subject entity, Juniper LLC 19, is VERIFIED, not flagged as high risk, not a PEP, and has no open review reasons. Its last screening was 2026-09-03, within the program's stale_screening_share=0 metric. The transfer and entity skoor are both null/unscored due to low sample size (n=4), meaning the model has insufficient history on this counterparty to produce a risk score. The counterparty's country is listed as unknown, which is a gap but not itself an evidenced risk signal. Program KRIs show two items in breach (ach_unauthorized_return_rate, manual_review_aging_hours) and three in watch status, but none of these are tied specifically to this transfer, counterparty, or entity.
What was checked. Reviewed alert evidence, transfer details, entity verification status, program KRIs, and prior dispositions. No prior dispositions exist for this alert or subject. No sanctioned-country transfers are recorded at the program level (0 of n=1783), and this transfer's country is not flagged as sanctioned.
What is recommended. No signal in the evidence indicates unauthorized activity, entity risk, or fund-movement failure. The transfer has already completed with no return code, so there is no pending transfer to hold or release. The alert reflects a first-time large payment that is consistent with a normal, verified business counterparty relationship. Recommend closing the alert. Confidence is limited by the unscored band (n=4) and unknown counterparty country, which should be noted for future monitoring but do not independently justify escalation or hold.
- Recommendation
- close
- Confidence
- 0.62
- Model
- claude-sonnet-5
- Drafted
- 2026-09-17 19:32Z
- Rationale
- Transfer status is COMPLETED with return code none, indicating no execution failure.
- Subject entity is VERIFIED, not high risk, not PEP, with no open review reasons and recent screening.
- Skoor is null due to low sample size (n=4), not due to any adverse score.
- Program-level KRI breaches (ach_unauthorized_return_rate, manual_review_aging_hours) are not linked to this specific transfer or entity in the evidence provided.
- No prior dispositions or pattern evidence link this alert to a broader concern warranting escalation.
- Counterparty country is unknown, which is a data gap but not a documented risk signal; this lowers confidence slightly rather than changing the recommendation.
Evidence
{
"n": 4,
"band": "unscored",
"skoor": null,
"signals": [
{
"code": "counterparty.first_time",
"detail": "first transfer with this counterparty",
"weight": 10
},
{
"code": "counterparty.first_time_and_large",
"detail": "amount above the program p95 (75667)",
"weight": 15
}
],
"routeReason": "detector always reviewed"
}
Skoor signals
| Signal | Weight | Hard | Detail |
|---|---|---|---|
| counterparty.first_time | +10 | first transfer with this counterparty | |
| counterparty.first_time_and_large | +15 | amount above the program p95 (75667) |
Decision
Sign in as an operator to decide. Operator sign-in →
Dispositions
No disposition yet.
Actions
Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.
No actions requested.