cd /news/ai-agents/building-zyg0s-an-autonomous-explain… Β· home β€Ί topics β€Ί ai-agents β€Ί article
[ARTICLE Β· art-139371] src=dev.to β†— pub= topic=ai-agents verified=true sentiment=↑ positive

Building Zyg0s: An Autonomous, Explainable Fraud Investigation Agent Powered by TigerGraph Savanna Cloud & MCP

Vansh Deo and team QueryCrew built Zyg0s, an autonomous, explainable fraud investigation agent that fuses seven neuro-symbolic agents with TigerGraph Savanna Cloud, Model Context Protocol, and Groq to traverse entity networks across 590,000+ IEEE-CIS transactions. The system grades evidence on a four-tier defensibility framework, quantifies epistemic uncertainty, enforces Bank Fraud Policy Rules R1–R10 with two-stage actions, and drafts FinCEN BSA/AML Suspicious Activity Reports while writing closed cases back into graph memory.

by read8 min views1 publishedSep 25, 2026

TigerGraph Agentic Fraud Investigation Hackathon (Hacker House Goa / HHGOA Track)

Author: Vansh Deo Team Name: QueryCrew GitHub Repository: https://github.com/VanshDeo/Zyg0s Video Demo (3–5 min): Watch Live Walkthrough Live Application: Launch Zyg0s Workbench

Zyg0s is an autonomous, explainable cyber-investigation platform engineered to resolve the hardest bottleneck in modern banking: investigating complex financial crime and recommending defensible next-best actions when available signals are noisy and uncertain.

Powered by TigerGraph Savanna Cloud, Model Context Protocol (MCP), and Groq, Zyg0s fuses 7 specialized neuro-symbolic agents to traverse deep entity networks across 590,000+ IEEE-CIS transactions. It mathematically grades evidence across a 4-tier defensibility framework, quantifies epistemic uncertainty ($U$), enforces Bank Fraud Policy Rules (R1–R10) with dynamic two-stage actions, synthesizes regulator-grade FinCEN BSA/AML Suspicious Activity Reports (SARs), and updates graph-native case memory.

Every financial institution in the world faces an acute operational bottleneck: fraud investigation is manual, slow, and fragmented.

When an upstream machine learning model flags a suspicious credit card transaction, the money is often already in flight. Human fraud analysts are forced to swivel between five disjointed screens: looking up transaction logs, examining device fingerprints, querying customer historical baselines, checking core banking policies, and cross-referencing past fraud cases. By the time a case is manually triaged and reviewed, the fraud ring has moved on to siphon funds from dozens of other accounts.

Compounding this crisis are three structural traps:

We built Zyg0s (named after the ancient Greek zygos, the forensic scale of balance and evidence weighting).

   β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
   β”‚                  WHAT IS ZYG0S?                        β”‚
   β”‚  An Autonomous, Explainable Fraud Investigation Agent  β”‚
   β”‚  fusing TigerGraph Savanna Cloud, Model Context        β”‚
   β”‚  Protocol (MCP), and 7 Neuro-Symbolic Agents.          β”‚
   β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜

Rather than treating fraud as a simple black-box binary classification problem, Zyg0s models fraud investigation as an adaptive, 8-stage evidentiary legal trial. It gathers multi-hop graph signals from TigerGraph Savanna Cloud, grades evidence across a 4-tier defensibility framework, quantifies epistemic uncertainty ($U$), recommends policy-governed two-stage actions, drafts regulatory FinCEN BSA/AML Suspicious Activity Reports (SARs), and writes closed cases back into graph memory.

Fraud is fundamentally relationalβ€”it lives in the connections between cards, devices, IP subnets, billing regions, and email domains. Relational databases choke on the recursive joins required to unmask synthetic identities and collusion rings.

TigerGraph Savanna Cloud provided the foundational backbone for Zyg0s:

Trident/7.0 | Windows 10 | IE 11.0) is isolated to one customer or acting as a shared gateway across 15+ compromised cards.ClosedCase), linked via semantic and topological edges, enabling zero-latency precedent retrieval. Zyg0s resolves the AI compliance paradox by implementing a strict Neuro-Symbolic Division of Labor:

β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚                         NEURO-SYMBOLIC DIVISION OF LABOR                         β”‚
β”œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€
β”‚ πŸ›‘οΈ DETERMINISTIC GOVERNOR (Symbolic)   β”‚ 🧠 LLM COGNITIVE LAYER (Neural)        β”‚
β”‚ "Absolute Truth, Math, & Compliance"   β”‚ "Fluid Reasoning, Synthesis, & Copilot" β”‚
β”œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”Όβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€
β”‚ β€’ GSQL multi-hop graph traversals      β”‚ β€’ Novel pattern discovery & naming (R9) β”‚
β”‚ β€’ Entity resolution & device clusters  β”‚ β€’ Legal-grade FinCEN BSA/AML SAR draft  β”‚
β”‚ β€’ Immutable numerical fact anchoring   β”‚ β€’ Natural language "What Changed" logs  β”‚
β”‚ β€’ 4-Tier evidence defensibility math   β”‚ β€’ Interactive Investigator Copilot Q&A  β”‚
β”‚ β€’ Uncertainty score formula (U = 1-C)  β”‚ β€’ Explaining edge cases to analysts     β”‚
β”‚ β€’ Bank Fraud Policy v1.0 (R1–R10) gate β”‚ β€’ Zero-hallucination factual grounding  β”‚
β”‚ β€’ Tiered permissions (auto, L1, L2)    β”‚ β€’ Graceful offline fallback             β”‚
β”‚ β€’ Graph writeback to Savanna Cloud     β”‚                                         β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”΄β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
[ Multi-Modal Ingestion ]
          β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
     Risk Score            Customer Report          Analyst Request
     (0.00 - 1.00)        (Disputed Amount)       (Graph Cluster Traversal)
          β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
                                  β”‚
                                  β–Ό
                     [ 7-Agent Pipeline Engine ]
    β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
    β”‚ 1. Alert Sentinel      ──► Ingests alert, computes Z-scores β”‚
    β”‚ 2. Graph Scout         ──► TigerGraph Savanna Cloud (MCP)   β”‚
    β”‚ 3. Evidence Assessor   ──► 4-Tier Defensibility & U index   β”‚
    β”‚ 4. Pattern Strategist  ──► Typology match & novel patterns  β”‚
    β”‚ 5. Policy Governor     ──► Bank Policy v1.0 (R1-R10) & NBA  β”‚
    β”‚ 6. Compliance Officer  ──► FinCEN BSA/AML SAR (5 W's)       β”‚
    β”‚ 7. Memory Weaver       ──► TigerGraph Graph Memory Commit   β”‚
    β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
                                  β”‚
                                  β–Ό
                   [ Interactive Workbench UI ]
     Case Queue   β€’   Live Progression   β€’   Graph & SAR Workspace

Zyg0s executes an 8-stage state machine that mirrors how elite forensic investigators work:

  [1. Trigger] Ingest alert via risk score, dispute, or analyst request.
       β”‚
  [2. Investigate] Open case, retrieve historical baselines & card history.
       β”‚
  [3. Gather Evidence] Traverse TigerGraph 2-hop ego network & shared devices.
       β”‚
  [4. Assess Uncertainty] Compute Epistemic Uncertainty U. If U > 0.40, stop destructive actions!
       β”‚
  [5. Gather More Evidence] Issue non-destructive Step-Up Challenge (SMS OTP / Biometric).
       β”‚
  [6. Take Next Actions] Evaluate Bank Policy R1-R10; evolve Stage 1 NBA into Stage 2 Final NBA.
       β”‚
  [7. Explain Decision] Synthesize 5 W's rationale citing policy rules & evidence grades.
       β”‚
  [8. Update Case Memory] Persist case vertex to TigerGraph Cloud via Hybrid RRF Index.

A central innovation of Zyg0s is our strict containment of Large Language Models (Groq / Qwen 2.5):

L2 Manager approval). In Zyg0s, recommendations are not staticβ€”they dynamically evolve across a Two-Stage Next-Best Action (NBA) lifecycle:

$$ \text{Confidence} = \left| \frac{\sum w_i}{\sum |w_i| + \epsilon} \right| \times \min\left(1.0, \frac{N}{N_{\text{min}}}\right) $$

$$ U = 1.0 - \text{Confidence} $$

VERIFY_WITH_CUSTOMER and MONITOR_CARD. CLOSE_NO_FRAUD (Card remains active).BLOCK_ALL_CARDS, CREATE_CASE, and FILE_REPORT under Zyg0s was rigorously evaluated against all 20 official benchmark exam cases from the final two months of the IEEE-CIS / Vesta dataset:

| Case ID | Trigger Channel | Typology Pattern | Final Verdict | Risk Score | Epistemic Uncertainty ($U$) | Final Confidence | SAR Filed? | Next Best Action | Approval Route |

| :---: | :---: | :---: | :---: | :---: | :---: | :---: | :---: | :---: | :---: |

| HHG-001 | Risk Score (0.61) | none | CLEARED | 5 / 100 | 0.330 | 67% | No | CLOSE_NO_FRAUD | auto |

| HHG-002 | Risk Score (0.79) | card_not_present_fraud | CLEARED | 5 / 100 | 0.000 | 100% | No | CLOSE_NO_FRAUD | auto |

| HHG-003 | Customer Dispute | none | FRAUD | 95 / 100 | 0.330 | 67% | No | BLOCK_CARD | L1 |

| HHG-004 | Customer Dispute | card_not_present_new_device | FRAUD | 99 / 100 | 0.150 | 85% | No | BLOCK_CARD | L1 |

| HHG-005 | Risk Score (0.54) | card_not_present_new_device | FRAUD | 85 / 100 | 0.150 | 85% | No | BLOCK_ALL_CARDS | L2 |

| HHG-006 | Customer Dispute | card_not_present_new_device | FRAUD | 99 / 100 | 0.150 | 85% | No | BLOCK_CARD | L1 |

| HHG-007 | Risk Score (0.87) | account_takeover | FRAUD | 85 / 100 | 0.150 | 85% | No | BLOCK_CARD | L1 |

| HHG-008 | Customer Dispute | none | CLEARED | 5 / 100 | 0.330 | 67% | No | CLOSE_NO_FRAUD | auto |

| HHG-009 | Customer Dispute | none | CLEARED | 5 / 100 | 0.330 | 67% | No | CLOSE_NO_FRAUD | auto |

| HHG-010 | Risk Score (0.90) | card_not_present_new_device | FRAUD | 85 / 100 | 0.150 | 85% | No | BLOCK_ALL_CARDS | L2 |

| HHG-011 | Customer Dispute | none | CLEARED | 5 / 100 | 0.550 | 45% | No | CLOSE_NO_FRAUD | auto |

| HHG-012 | Risk Score (0.55) | none | CLEARED | 5 / 100 | 0.330 | 67% | No | CLOSE_NO_FRAUD | auto |

| HHG-013 | Risk Score (0.76) | card_not_present_new_device | FRAUD | 92 / 100 | 0.000 | 100% | Yes | BLOCK_ALL_CARDS | L2 |

| HHG-014 | Analyst Request | card_not_present_new_device | FRAUD | 99 / 100 | 0.150 | 85% | Yes | BLOCK_ALL_CARDS | L2 |

| HHG-015 | Risk Score (0.77) | card_not_present_new_device | FRAUD | 92 / 100 | 0.000 | 100% | Yes | BLOCK_ALL_CARDS | L2 |

| HHG-016 | Customer Dispute | card_not_present_new_device | FRAUD | 99 / 100 | 0.000 | 100% | Yes | BLOCK_ALL_CARDS | L2 |

| HHG-017 | Risk Score (0.57) | card_not_present_fraud | FRAUD | 85 / 100 | 0.150 | 85% | No | BLOCK_ALL_CARDS | L2 |

| HHG-018 | Customer Dispute | none | CLEARED | 5 / 100 | 0.330 | 67% | No | CLOSE_NO_FRAUD | auto |

| HHG-019 | Risk Score (0.90) | card_not_present_new_device | FRAUD | 85 / 100 | 0.150 | 85% | Yes | BLOCK_ALL_CARDS | L2 |

| HHG-020 | Risk Score (0.52) | card_not_present_new_device | FRAUD | 85 / 100 | 0.150 | 85% | Yes | BLOCK_ALL_CARDS | L2 |

Building an autonomous agent for production fintech required overcoming several non-trivial engineering hurdles:

closed_cases_history.csv) and built a bottleneck, numexpr). sys.modules.setdefault("bottleneck", None)) to ensure crash-proof operation across local environments and cloud deployments.tigergraph__get_neighbors, tigergraph__get_node) to restrict traversal expansions to relevant 2-hop neighborhoods, completing graph evaluations in under 1.5 seconds. Deterministic policy rules and graph structure do not restrict AI agentsβ€”they make them usable in high-liability industries. By decoupling mathematical computation and statutory policy from fluid natural language synthesis, we achieved 100% regulatory compliance, zero arithmetic hallucinations, and defensible audit trails.

Codebase & Benchmarks: GitHub Repository

Submission Track: TigerGraph Agentic Fraud Investigation (Hacker House Goa)

── more in #ai-agents 4 stories Β· sorted by recency
── more on @vansh deo 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain β€” perfect for shipping the agent you just read about.

$git push zahid main
β†’ Live at https://your-agent.zahid.host βœ“
Get free account β†’ Pricing
from €0/mo Β· no card required
LIVE [news/building-zyg0s-an-au…] indexed:0 read:8min 2026-09-25 Β· β€”