Alert · reviewed · open
Transaction Risk Skoor 40 (review band) on a $536.68 ach transfer: returns.counterparty_prior_unauthorized.
- Detector
- skoor_review
- Severity
- medium
- Program
- Harbor Marketplace Payouts (simulated)
- Subject
- transfer acht_sim_harb_8nspqxza9hm
- Transfer
- acht_sim_harb_8nspqxza9hm · $536.68 · ach outgoing
- Skoor at alert
- 40 review
- Hard signal
- no
- Policy
- policy-v1
- Opened
- 2026-09-17 19:32Z
- Closed
- —
- Decision clock
- none · due — no clock
- Escalated
- —
Draft narrative
What happened. Alert ecc59556-936a-4d78-bca9-6b1b2e5ac0f5 fired on outgoing ACH transfer acht_sim_harb_8nspqxza9hm for $536.68, flagged by the skoor_review detector at Skoor 40 (review band) due to one prior unauthorized return associated with the counterparty. The transfer has already settled with no return code recorded.
What the evidence shows. The single contributing signal is returns.counterparty_prior_unauthorized, weighted 40, based on one prior unauthorized return for counterparty cpty_sim_harb_bmqeuc7o3xi. The transfer itself settled cleanly with return code none. The originating entity, Birch Holdings 11, is VERIFIED, not high risk, not PEP, with no open review reasons and screening current as of 2026-08-31. Program-level KRIs show ach_unauthorized_return_rate at 0.00912 (n=877) in breach status, and manual_review_aging_hours at 1438.05 (n=16) also in breach. Other KRIs (frozen_accounts, overdraft_events, card_fraud_declines, pep_flagged_entities, high_risk_entity_share) sit in watch status but are not directly tied to this alert's signal.
What was checked. Reviewed the transfer status (SETTLED, no return code), the entity's verification and screening status, the program's declared volume and KRI panel, and prior dispositions (none on record). Confirmed the alert's hard_signal flag is false and route reason is 'detector not auto-closable,' meaning it requires manual disposition rather than automatic closure.
What is recommended. The transfer has already settled, so there are no funds to hold or release. However, the alert's basis (prior unauthorized return for this counterparty) aligns with a program-level KRI breach on ach_unauthorized_return_rate, suggesting this may not be an isolated case. A person should review whether this counterparty or a related pattern is contributing to the program-wide unauthorized return rate breach before closing this alert.
- Recommendation
- escalate
- Confidence
- 0.55
- Model
- claude-sonnet-5
- Drafted
- 2026-09-17 19:32Z
- Rationale
- Transfer status is SETTLED with return code none, so hold/release actions do not apply to this specific alert.
- The sole signal (prior unauthorized return, weight 40) is counterparty-specific and unresolved as to whether it reflects an isolated incident or a broader pattern.
- Program KRI ach_unauthorized_return_rate is in breach status (0.00912, n=877), which is consistent with the type of signal that triggered this alert and warrants pattern-level review.
- Originating entity Birch Holdings 11 shows no independent risk indicators (verified, not high risk, not PEP, no review reasons), so entity-level risk is not the concern.
- Evidence on the counterparty's return history is limited to a single data point (1 prior unauthorized return); no further counterparty-level detail is provided, which limits confidence.
- manual_review_aging_hours is also in breach (1438.05 hours, n=16), indicating review backlog risk that a person should factor into prioritization.
Evidence
{
"n": 2220,
"band": "review",
"skoor": 40,
"signals": [
{
"code": "returns.counterparty_prior_unauthorized",
"detail": "1 prior unauthorized return(s)",
"weight": 40
}
],
"confidence": 1,
"routeReason": "detector not auto-closable"
}
Skoor signals
| Signal | Weight | Hard | Detail |
|---|---|---|---|
| returns.counterparty_prior_unauthorized | +40 | 1 prior unauthorized return(s) |
Decision
Sign in as an operator to decide. Operator sign-in →
Dispositions
No disposition yet.
Actions
Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.
No actions requested.