Alert · reviewed · open
Transaction Risk Skoor 40 (review band) on a $229.42 ach transfer: returns.counterparty_prior_unauthorized.
- Detector
- skoor_review
- Severity
- medium
- Program
- Harbor Marketplace Payouts (simulated)
- Subject
- transfer acht_sim_harb_5e7ozfuc4r0
- Transfer
- acht_sim_harb_5e7ozfuc4r0 · $229.42 · ach outgoing
- Skoor at alert
- 40 review
- Hard signal
- no
- Policy
- policy-v1
- Opened
- 2026-09-17 19:30Z
- Closed
- —
- Decision clock
- none · due — no clock
- Escalated
- —
Draft narrative
What happened. Alert ed9319ad-109d-42bc-b4f0-f19b49c8b7e1 was opened on 2026-09-17T19:30:20.139Z by the skoor_review detector for ACH transfer acht_sim_harb_5e7ozfuc4r0, a $229.42 outgoing credit under the Harbor Marketplace Payouts program. The transfer risk score is 40, placing it in the review band, driven by a single signal: one prior unauthorized return associated with the counterparty.
What the evidence shows. The transfer itself settled with return code none, so no unauthorized return occurred on this transaction. The score of 40 comes entirely from the counterparty's history of one prior unauthorized return (weight 40), with confidence 1 on a sample of 233. The receiving entity, Alder Co 10, is VERIFIED, not high risk, not PEP, with no open review reasons and screening current as of 2026-07-04. Program KRIs show no frozen accounts, no overdraft events, a low verification denial rate (3.3%), and a high-risk entity share of 6.7% (watch level but based on n=30). Fields for ACH unauthorized return rate, hold aging, and manual review rate are unmeasured (null), so no program-wide return pattern can be confirmed from this data.
What was checked. Transfer status and return code (SETTLED, no return), transfer-level skoor signal detail, entity verification status and screening date, and program KRI panel for related risk indicators (frozen accounts, overdraft, high-risk share, verification denial rate, unauthorized return rate). Prior dispositions on this alert: none.
What is recommended. The transfer already settled with no return, and the flagged signal reflects a single historical unauthorized return by the counterparty rather than any issue with this transaction. The receiving entity is verified with no other risk flags. There is no evidence in the KRI panel of a broader unauthorized-return pattern (the relevant rate is unmeasured, not elevated). No transfer is currently held, so release does not apply. Based on the evidence provided, this alert does not require further hold action; a person should confirm closure given the single-signal basis.
- Recommendation
- close
- Confidence
- 0.62
- Model
- claude-sonnet-5
- Drafted
- 2026-09-17 19:31Z
- Rationale
- Transfer acht_sim_harb_5e7ozfuc4r0 is SETTLED with return code none, indicating no unauthorized return occurred on this transaction itself.
- The review-band score of 40 rests on one signal: counterparty's prior unauthorized return (weight 40), not on current transaction behavior.
- Entity enti_sim_harb_3x8shd663uc is VERIFIED, not high risk, not PEP, with no open review reasons and screening current as of 2026-07-04.
- Program KRIs show no frozen accounts (0/2) and no overdraft events (0/2); ach_unauthorized_return_rate is unmeasured (null, n=0), so no confirmed pattern of repeat unauthorized returns exists at the program level.
- No transfer is currently on hold, so 'release' is not applicable; the amount ($229.42) and single-signal basis do not indicate a need to hold future movement.
- Confidence is moderated because several program KRIs (velocity_vs_declared, reserve_coverage_ratio, manual_review_rate) are unmeasured, limiting full context on program-wide risk.
Evidence
{
"n": 233,
"band": "review",
"skoor": 40,
"signals": [
{
"code": "returns.counterparty_prior_unauthorized",
"detail": "1 prior unauthorized return(s)",
"weight": 40
}
],
"confidence": 1,
"routeReason": "detector not auto-closable"
}
Skoor signals
| Signal | Weight | Hard | Detail |
|---|---|---|---|
| returns.counterparty_prior_unauthorized | +40 | 1 prior unauthorized return(s) |
Decision
Sign in as an operator to decide. Operator sign-in →
Dispositions
No disposition yet.
Actions
Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.
No actions requested.