Alert · reviewed · open
Transaction Risk Skoor 30 (review band) on a $454.12 ach transfer: returns.counterparty_prior_any, returns.entity_rate_gt_threshold.
- Detector
- skoor_review
- Severity
- medium
- Program
- Harbor Marketplace Payouts (simulated)
- Subject
- transfer acht_sim_harb_ivz1fjx7cx
- Transfer
- acht_sim_harb_ivz1fjx7cx · $454.12 · ach outgoing
- Skoor at alert
- 30 review
- Hard signal
- no
- Policy
- policy-v1
- Opened
- 2026-09-17 19:31Z
- Closed
- —
- Decision clock
- none · due — no clock
- Escalated
- —
Draft narrative
What happened. A $454.12 outgoing ACH credit transfer (acht_sim_harb_ivz1fjx7cx) under the Harbor Marketplace Payouts program was flagged by the skoor_review detector at a risk score of 30 (review band, hard_signal false). Two signals fired: one prior non-NSF return on the counterparty, and an elevated entity-level unauthorized ACH return rate (1 of 29 originated debits in 60 days).
What the evidence shows. The transfer itself settled on 2026-08-21 with no return code recorded, so no funds are currently at risk of movement from this specific transaction. The originating entity, Juniper LLC 19, is VERIFIED, not flagged high risk, not PEP, has no open review reasons, and was screened as recently as 2026-07-06. The two triggering signals (counterparty_prior_any, entity_rate_gt_threshold) each carry a 15-point weight and together produced a review-band score, below any auto-escalation threshold. At the program level, however, the KRI panel shows ach_unauthorized_return_rate in breach (0.0118 over n=507) and manual_review_aging_hours in breach (1438 hours over n=9), alongside watch-level readings for hold_aging_hours, pep_flagged_entities, and high_risk_entity_share. These program-wide figures are broader than this single alert and are not explained by this transfer alone.
What was checked. Transfer status and return code, entity verification and screening status, program KRI panel, and prior dispositions (none found for this alert or entity).
What is recommended. The transfer is settled and not held, so no release action applies. The entity-level evidence here does not on its own show fraud or sanctions concern sufficient to hold or close-with-action. However, the program-level breach in unauthorized ACH return rate and manual review aging, combined with this alert's own entity-rate signal, suggest a pattern extending beyond this single transaction that a person should review at the program level rather than close silently.
- Recommendation
- escalate
- Confidence
- 0.52
- Model
- claude-sonnet-5
- Drafted
- 2026-09-17 19:31Z
- Rationale
- Transfer already settled with no return code; hold/release actions do not apply to this alert.
- Entity is verified, not high-risk, not PEP, with no open review reasons — no direct evidence of wrongdoing at the entity level.
- Score (30) and hard_signal false place this at the lower end of review-band alerts, arguing against automatic escalation on this alert's evidence alone.
- Program KRIs show a hard breach in ach_unauthorized_return_rate (0.0118, n=507) and manual_review_aging_hours (1438h, n=9), which corroborate the entity_rate_gt_threshold signal and point to a broader pattern than one transfer.
- Multiple watch-level KRIs (hold_aging_hours, pep_flagged_entities, high_risk_entity_share) further support review at the program level rather than a routine close.
- No prior dispositions exist to indicate this pattern has already been reviewed.
Evidence
{
"n": 1336,
"band": "review",
"skoor": 30,
"signals": [
{
"code": "returns.counterparty_prior_any",
"detail": "1 prior return(s) other than NSF",
"weight": 15
},
{
"code": "returns.entity_rate_gt_threshold",
"detail": "entity unauthorized return rate 1/29 originated ACH debits in 60d",
"weight": 15
}
],
"confidence": 1,
"routeReason": "detector not auto-closable"
}
Skoor signals
| Signal | Weight | Hard | Detail |
|---|---|---|---|
| returns.counterparty_prior_any | +15 | 1 prior return(s) other than NSF | |
| returns.entity_rate_gt_threshold | +15 | entity unauthorized return rate 1/29 originated ACH debits in 60d |
Decision
Sign in as an operator to decide. Operator sign-in →
Dispositions
No disposition yet.
Actions
Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.
No actions requested.