SKOOR Risk Money movement. Skoored by AI.

Alert · reviewed · open

Entity velocity spiked: 1 transfers and $733.20 in 24 hours.

Detector
velocity_spike
Severity
medium
Program
Lantern Lending (simulated)
Subject
entity enti_sim_lant_5pyvo263cie
Transfer
acht_sim_lant_3yn8l12xcjt · $1,002.76 · ach outgoing
Skoor at alert
null unscored
Hard signal
no
Policy
policy-v1
Opened
2026-09-17 19:30Z
Closed
Decision clock
none · due — no clock
Escalated

Draft narrative

What happened. A velocity_spike alert fired for entity enti_sim_lant_5pyvo263cie (Iris Services 320), citing 1 transfer totaling $733.20 in 24 hours, which is above 2× the program's daily average for Lantern Lending. Severity is medium, route is 'reviewed' because the detector is not auto-closable, and there is no prior disposition history for this entity. What the evidence shows. The alert record shows n=1, band unscored, skoor null, with two signals: velocity.sum_24h_gt_2x_daily_avg (weight 10) and, at the transfer level, counterparty.first_time (weight 10). The transfer record attached (acht_sim_lant_3yn8l12xcjt) is an outgoing ACH credit of $1002.76, settled, created 2026-07-10, to a first-time counterparty with unknown country and no return code. This dollar amount and date do not match the alert summary's $733.20/24h figure, so the transfer provided may not be the same transaction underlying the velocity calculation. The entity is a verified business, not flagged high risk, not PEP, with no review reasons on file, last screened 2026-06-23. What was checked. Checked the alert evidence block, the linked transfer record, the program's declared monthly volume ($900,000.00, ACH, US), the entity's verification and risk status, and prior dispositions. Confirmed no hard signal is present and the score band is unscored (n=1, skoor null), meaning this is a low-volume, low-confidence statistical trigger rather than a scored risk finding. Noted the mismatch between the alert's stated 24h sum and the single transfer's amount, which cannot be resolved from the data given. What is recommended. Given a single transaction, a verified low-risk entity with no PEP or high-risk flags, no prior alert history, and no hard signal, there is nothing in the evidence that requires holding funds or escalating a pattern. The data mismatch between the alert summary and the transfer record is noted but does not itself indicate a risk concern requiring a person to act before this is closed; it is flagged for awareness. Recommend closing the alert.
Recommendation
close
Confidence
0.55
Model
claude-sonnet-5
Drafted
2026-09-17 19:30Z
Rationale
  • Alert is unscored (skoor null, band unscored, n=1), indicating low statistical confidence in the velocity trigger itself.
  • Entity is VERIFIED, not high risk, not PEP, with no review reasons and no prior dispositions.
  • Only one transfer is in evidence; no hard signal present; total alert weight (20) is low.
  • The transfer amount ($1002.76) and date (2026-07-10) do not match the alert's cited $733.20/24h figure, which weakens confidence that the evidence set fully represents the triggering activity, but nothing in either record points to elevated risk (settled, no return code, though counterparty is first-time with unknown country).
  • No transfer is described as held, so 'release' does not apply; no pattern across multiple entities or alerts is evidenced, so escalation is not supported.

Evidence

{
  "n": 1,
  "band": "unscored",
  "skoor": null,
  "signals": [
    {
      "code": "velocity.sum_24h_gt_2x_daily_avg",
      "detail": "24h sum above 2× the program daily average",
      "weight": 10
    }
  ],
  "routeReason": "detector not auto-closable"
}

Skoor signals

SignalWeightHardDetail
counterparty.first_time+10first transfer with this counterparty
velocity.sum_24h_gt_2x_daily_avg+1024h sum above 2× the program daily average

Decision

Sign in as an operator to decide. Operator sign-in →

Dispositions

No disposition yet.

Actions

Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.

No actions requested.