Alert · reviewed · open
Transaction Risk Skoor 40 (review band) on a $702.25 ach transfer: returns.counterparty_prior_unauthorized.
- Detector
- skoor_review
- Severity
- medium
- Program
- Harbor Marketplace Payouts (simulated)
- Subject
- transfer acht_sim_harb_b13qgy5w8f0
- Transfer
- acht_sim_harb_b13qgy5w8f0 · $702.25 · ach outgoing
- Skoor at alert
- 40 review
- Hard signal
- no
- Policy
- policy-v1
- Opened
- 2026-09-17 19:31Z
- Closed
- —
- Decision clock
- none · due — no clock
- Escalated
- —
Draft narrative
What happened. Alert e2f7c761-295d-4aaa-a641-555e2ea35912 fired from the skoor_review detector on ACH outgoing credit transfer acht_sim_harb_b13qgy5w8f0 for $702.25, opened 2026-09-17. The transaction risk skoor is 40, placing it in the review band, driven entirely by one signal: returns.counterparty_prior_unauthorized, weighted 40, noting 3 prior unauthorized returns for this counterparty. The transfer itself is already SETTLED with no return code on this specific transaction.
What the evidence shows. The transfer settled cleanly; there is no return coded against it. The flagged risk is historical: the counterparty cpty_sim_harb_gzii64r41f has 3 prior unauthorized returns on record, though its country is unknown. The originating entity, Payout Agent (Harbor), is VERIFIED, not high risk, not PEP, with no review reasons and screening current as of 2026-09-02. At the program level (Harbor Marketplace Payouts), most KRIs are in the ok or watch range, but two are in breach: manual_review_aging_hours (1438.04h, n=10) and ach_unauthorized_return_rate (0.00885, n=678). Hold_aging_hours (1023.97h, n=9) and high_risk_entity_share (0.0667, n=30) are at watch. No prior dispositions exist for this alert.
What was checked. Reviewed the transfer record (status, amount, rails, return code), the entity verification and screening status, the program's declared volume and KRI dashboard, and prior disposition history. Confirmed the alert's sole driver is the counterparty's return history rather than any defect in this settled transaction.
What is recommended. This specific transfer is settled with no return, so there are no funds to hold and nothing to release. However, the counterparty's 3 prior unauthorized returns, combined with the program's concurrent breach-level ach_unauthorized_return_rate and manual_review_aging_hours, indicate a pattern that extends beyond this single alert. This warrants escalation for a person to assess whether the counterparty or program-level return handling needs broader review, rather than a routine close.
- Recommendation
- escalate
- Confidence
- 0.62
- Model
- claude-sonnet-5
- Drafted
- 2026-09-17 19:32Z
- Rationale
- Transfer is SETTLED with no return code; no action is possible on this specific transaction, ruling out hold or release.
- The single driving signal (counterparty_prior_unauthorized, 3 priors) concerns counterparty history, not this transaction's outcome, so it does not by itself justify closing without human review.
- Program KRIs show two concurrent breaches (ach_unauthorized_return_rate and manual_review_aging_hours), suggesting the individual alert may be part of a broader pattern rather than an isolated event.
- Entity-level checks (verification, PEP, high-risk, screening recency) are all clean, so the concern is isolated to counterparty history and program-level return metrics, not the originating entity.
- No prior dispositions exist to indicate this pattern has already been reviewed or resolved.
Evidence
{
"n": 1746,
"band": "review",
"skoor": 40,
"signals": [
{
"code": "returns.counterparty_prior_unauthorized",
"detail": "3 prior unauthorized return(s)",
"weight": 40
}
],
"confidence": 1,
"routeReason": "detector not auto-closable"
}
Skoor signals
| Signal | Weight | Hard | Detail |
|---|---|---|---|
| returns.counterparty_prior_unauthorized | +40 | 5 prior unauthorized return(s) |
Decision
Sign in as an operator to decide. Operator sign-in →
Dispositions
No disposition yet.
Actions
Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.
No actions requested.