Alert · reviewed · open
Transaction Risk Skoor 40 (review band) on a $247.11 ach transfer: returns.counterparty_prior_unauthorized.
- Detector
- skoor_review
- Severity
- medium
- Program
- Harbor Marketplace Payouts (simulated)
- Subject
- transfer acht_sim_harb_4uqp7nrc8vp
- Transfer
- acht_sim_harb_4uqp7nrc8vp · $247.11 · ach outgoing
- Skoor at alert
- 40 review
- Hard signal
- no
- Policy
- policy-v1
- Opened
- 2026-09-17 19:31Z
- Closed
- —
- Decision clock
- none · due — no clock
- Escalated
- —
Draft narrative
What happened. Alert e7e8a299-241e-4620-8f4c-af84ae9a044c fired on ACH outgoing transfer acht_sim_harb_4uqp7nrc8vp for $247.11, flagged by the skoor_review detector at skoor 40 (review band) due to one prior unauthorized return associated with the counterparty. Hard signal is false. The transfer itself settled with return code none.
What the evidence shows. The only signal driving the score is returns.counterparty_prior_unauthorized, weighted 40, based on one historical unauthorized return for counterparty cpty_sim_harb_362c8piz3xi. This transfer, created 2026-09-09 and settled, carries no return code, indicating it processed without incident. The subject entity, Heath Holdings 119, is VERIFIED, not high risk, not PEP, with no open review reasons and screening current as of 2026-09-01. Program-level KRIs show ach_unauthorized_return_rate at 0.0076 (flagged breach) and manual_review_aging_hours at 1438 hours (flagged breach), but these are aggregate program metrics (n=793 and n=15 respectively) and are not specific to this counterparty or this transfer. No prior dispositions exist for this alert.
What was checked. Reviewed the transfer record (status, amount, rail, return code), the entity verification and risk flags, the program KRI panel for related patterns, and prior disposition history. Confirmed the transfer is settled, not pending or held, so there are no funds in a holdable state.
What is recommended. Close this alert. The transfer settled cleanly with no return, the entity is verified and low risk, and the triggering signal is a single historical unauthorized return rather than a recurring pattern tied to this counterparty. The program-level KRI breaches (ach_unauthorized_return_rate, manual_review_aging_hours) are aggregate signals that may warrant separate program-level review, but they do not point specifically to this transfer or this counterparty and should not block closure of this individual alert.
- Recommendation
- close
- Confidence
- 0.68
- Model
- claude-sonnet-5
- Drafted
- 2026-09-17 19:32Z
- Rationale
- Transfer status is SETTLED with return code none, indicating no operational issue with this specific transaction.
- Hard signal is false and the score of 40 rests on a single historical flag (one prior unauthorized return), not a recurring or escalating pattern for this counterparty.
- Entity is VERIFIED, not high risk, not PEP, with no open review reasons and screening current within the last three weeks.
- No prior dispositions exist on this subject, so there is no compounding history to escalate.
- Program KRI breaches on ach_unauthorized_return_rate and manual_review_aging_hours are aggregate, not specific to this alert's counterparty or transfer, so they support a separate program-level review rather than action on this alert.
- Transfer already settled, so hold or release are not applicable; no funds are pending movement.
Evidence
{
"n": 1988,
"band": "review",
"skoor": 40,
"signals": [
{
"code": "returns.counterparty_prior_unauthorized",
"detail": "1 prior unauthorized return(s)",
"weight": 40
}
],
"confidence": 1,
"routeReason": "detector not auto-closable"
}
Skoor signals
| Signal | Weight | Hard | Detail |
|---|---|---|---|
| returns.counterparty_prior_unauthorized | +40 | 1 prior unauthorized return(s) |
Decision
Sign in as an operator to decide. Operator sign-in →
Dispositions
No disposition yet.
Actions
Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.
No actions requested.