# Building Zyg0s: An Autonomous, Explainable Fraud Investigation Agent Powered by TigerGraph Savanna Cloud & MCP

> Source: <https://dev.to/vanshdeo/building-zyg0s-an-autonomous-explainable-fraud-investigation-agent-powered-by-tigergraph-savanna-34ki>
> Published: 2026-09-25 01:03:35+00:00

**TigerGraph Agentic Fraud Investigation Hackathon (Hacker House Goa / HHGOA Track)**

**Author:** Vansh Deo
**Team Name:** QueryCrew
**GitHub Repository:** [https://github.com/VanshDeo/Zyg0s](https://github.com/VanshDeo/Zyg0s)
**Video Demo (3–5 min):** [Watch Live Walkthrough](https://your-video-link-here)
**Live Application:** [Launch Zyg0s Workbench](https://your-live-app-link-here)

**Zyg0s** is an autonomous, explainable cyber-investigation platform engineered to resolve the hardest bottleneck in modern banking: **investigating complex financial crime and recommending defensible next-best actions when available signals are noisy and uncertain**.

Powered by **TigerGraph Savanna Cloud**, **Model Context Protocol (MCP)**, and **Groq**, Zyg0s fuses 7 specialized neuro-symbolic agents to traverse deep entity networks across 590,000+ IEEE-CIS transactions. It mathematically grades evidence across a 4-tier defensibility framework, quantifies **epistemic uncertainty ($U$)**, enforces Bank Fraud Policy Rules (R1–R10) with dynamic two-stage actions, synthesizes regulator-grade **FinCEN BSA/AML Suspicious Activity Reports (SARs)**, and updates graph-native case memory.

Every financial institution in the world faces an acute operational bottleneck: **fraud investigation is manual, slow, and fragmented**. 

When an upstream machine learning model flags a suspicious credit card transaction, the money is often already in flight. Human fraud analysts are forced to swivel between five disjointed screens: looking up transaction logs, examining device fingerprints, querying customer historical baselines, checking core banking policies, and cross-referencing past fraud cases. By the time a case is manually triaged and reviewed, the fraud ring has moved on to siphon funds from dozens of other accounts.

Compounding this crisis are three structural traps:

We built **Zyg0s** (named after the ancient Greek *zygos*, the forensic scale of balance and evidence weighting).

```
   ┌────────────────────────────────────────────────────────┐
   │                  WHAT IS ZYG0S?                        │
   │  An Autonomous, Explainable Fraud Investigation Agent  │
   │  fusing TigerGraph Savanna Cloud, Model Context        │
   │  Protocol (MCP), and 7 Neuro-Symbolic Agents.          │
   └────────────────────────────────────────────────────────┘
```

Rather than treating fraud as a simple black-box binary classification problem, Zyg0s models fraud investigation as an **adaptive, 8-stage evidentiary legal trial**. It gathers multi-hop graph signals from **TigerGraph Savanna Cloud**, grades evidence across a 4-tier defensibility framework, quantifies **epistemic uncertainty ($U$)**, recommends policy-governed two-stage actions, drafts regulatory **FinCEN BSA/AML Suspicious Activity Reports (SARs)**, and writes closed cases back into graph memory.

Fraud is fundamentally relational—it lives in the connections between cards, devices, IP subnets, billing regions, and email domains. Relational databases choke on the recursive joins required to unmask synthetic identities and collusion rings.

**TigerGraph Savanna Cloud** provided the foundational backbone for Zyg0s:

`Trident/7.0 | Windows 10 | IE 11.0`) is isolated to one customer or acting as a shared gateway across 15+ compromised cards.`ClosedCase`), linked via semantic and topological edges, enabling zero-latency precedent retrieval.
Zyg0s resolves the AI compliance paradox by implementing a strict **Neuro-Symbolic Division of Labor**:

```
┌──────────────────────────────────────────────────────────────────────────────────┐
│                         NEURO-SYMBOLIC DIVISION OF LABOR                         │
├────────────────────────────────────────┬─────────────────────────────────────────┤
│ 🛡️ DETERMINISTIC GOVERNOR (Symbolic)   │ 🧠 LLM COGNITIVE LAYER (Neural)        │
│ "Absolute Truth, Math, & Compliance"   │ "Fluid Reasoning, Synthesis, & Copilot" │
├────────────────────────────────────────┼─────────────────────────────────────────┤
│ • GSQL multi-hop graph traversals      │ • Novel pattern discovery & naming (R9) │
│ • Entity resolution & device clusters  │ • Legal-grade FinCEN BSA/AML SAR draft  │
│ • Immutable numerical fact anchoring   │ • Natural language "What Changed" logs  │
│ • 4-Tier evidence defensibility math   │ • Interactive Investigator Copilot Q&A  │
│ • Uncertainty score formula (U = 1-C)  │ • Explaining edge cases to analysts     │
│ • Bank Fraud Policy v1.0 (R1–R10) gate │ • Zero-hallucination factual grounding  │
│ • Tiered permissions (auto, L1, L2)    │ • Graceful offline fallback             │
│ • Graph writeback to Savanna Cloud     │                                         │
└────────────────────────────────────────┴─────────────────────────────────────────┘
[ Multi-Modal Ingestion ]
          ┌───────────────────────┬───────────────────────┐
     Risk Score            Customer Report          Analyst Request
     (0.00 - 1.00)        (Disputed Amount)       (Graph Cluster Traversal)
          └───────────────────────┬───────────────────────┘
                                  │
                                  ▼
                     [ 7-Agent Pipeline Engine ]
    ┌─────────────────────────────────────────────────────────────┐
    │ 1. Alert Sentinel      ──► Ingests alert, computes Z-scores │
    │ 2. Graph Scout         ──► TigerGraph Savanna Cloud (MCP)   │
    │ 3. Evidence Assessor   ──► 4-Tier Defensibility & U index   │
    │ 4. Pattern Strategist  ──► Typology match & novel patterns  │
    │ 5. Policy Governor     ──► Bank Policy v1.0 (R1-R10) & NBA  │
    │ 6. Compliance Officer  ──► FinCEN BSA/AML SAR (5 W's)       │
    │ 7. Memory Weaver       ──► TigerGraph Graph Memory Commit   │
    └─────────────────────────────┬───────────────────────────────┘
                                  │
                                  ▼
                   [ Interactive Workbench UI ]
     Case Queue   •   Live Progression   •   Graph & SAR Workspace
```

Zyg0s executes an 8-stage state machine that mirrors how elite forensic investigators work:

```
  [1. Trigger] Ingest alert via risk score, dispute, or analyst request.
       │
  [2. Investigate] Open case, retrieve historical baselines & card history.
       │
  [3. Gather Evidence] Traverse TigerGraph 2-hop ego network & shared devices.
       │
  [4. Assess Uncertainty] Compute Epistemic Uncertainty U. If U > 0.40, stop destructive actions!
       │
  [5. Gather More Evidence] Issue non-destructive Step-Up Challenge (SMS OTP / Biometric).
       │
  [6. Take Next Actions] Evaluate Bank Policy R1-R10; evolve Stage 1 NBA into Stage 2 Final NBA.
       │
  [7. Explain Decision] Synthesize 5 W's rationale citing policy rules & evidence grades.
       │
  [8. Update Case Memory] Persist case vertex to TigerGraph Cloud via Hybrid RRF Index.
```

A central innovation of Zyg0s is our **strict containment of Large Language Models (Groq / Qwen 2.5)**:

`L2` Manager approval).
In Zyg0s, recommendations are not static—they dynamically evolve across a **Two-Stage Next-Best Action (NBA)** lifecycle:

$$ \text{Confidence} = \left| \frac{\sum w_i}{\sum |w_i| + \epsilon} \right| \times \min\left(1.0, \frac{N}{N_{\text{min}}}\right) $$

$$ U = 1.0 - \text{Confidence} $$

`VERIFY_WITH_CUSTOMER` and `MONITOR_CARD`.` CLOSE_NO_FRAUD` (Card remains active).`BLOCK_ALL_CARDS`, `CREATE_CASE`, and `FILE_REPORT` under Zyg0s was rigorously evaluated against all 20 official benchmark exam cases from the final two months of the IEEE-CIS / Vesta dataset:

| Case ID | Trigger Channel | Typology Pattern | Final Verdict | Risk Score | Epistemic Uncertainty ($U$) | Final Confidence | SAR Filed? | Next Best Action | Approval Route |

| :---: | :---: | :---: | :---: | :---: | :---: | :---: | :---: | :---: | :---: |

| **HHG-001** | Risk Score (0.61) | `none` | **CLEARED** | 5 / 100 | 0.330 | **67%** | No | `CLOSE_NO_FRAUD` | `auto` |

| **HHG-002** | Risk Score (0.79) | `card_not_present_fraud` | **CLEARED** | 5 / 100 | 0.000 | **100%** | No | `CLOSE_NO_FRAUD` | `auto` |

| **HHG-003** | Customer Dispute | `none` | **FRAUD** | 95 / 100 | 0.330 | **67%** | No | `BLOCK_CARD` | `L1` |

| **HHG-004** | Customer Dispute | `card_not_present_new_device` | **FRAUD** | 99 / 100 | 0.150 | **85%** | No | `BLOCK_CARD` | `L1` |

| **HHG-005** | Risk Score (0.54) | `card_not_present_new_device` | **FRAUD** | 85 / 100 | 0.150 | **85%** | No | `BLOCK_ALL_CARDS` | `L2` |

| **HHG-006** | Customer Dispute | `card_not_present_new_device` | **FRAUD** | 99 / 100 | 0.150 | **85%** | No | `BLOCK_CARD` | `L1` |

| **HHG-007** | Risk Score (0.87) | `account_takeover` | **FRAUD** | 85 / 100 | 0.150 | **85%** | No | `BLOCK_CARD` | `L1` |

| **HHG-008** | Customer Dispute | `none` | **CLEARED** | 5 / 100 | 0.330 | **67%** | No | `CLOSE_NO_FRAUD` | `auto` |

| **HHG-009** | Customer Dispute | `none` | **CLEARED** | 5 / 100 | 0.330 | **67%** | No | `CLOSE_NO_FRAUD` | `auto` |

| **HHG-010** | Risk Score (0.90) | `card_not_present_new_device` | **FRAUD** | 85 / 100 | 0.150 | **85%** | No | `BLOCK_ALL_CARDS` | `L2` |

| **HHG-011** | Customer Dispute | `none` | **CLEARED** | 5 / 100 | 0.550 | **45%** | No | `CLOSE_NO_FRAUD` | `auto` |

| **HHG-012** | Risk Score (0.55) | `none` | **CLEARED** | 5 / 100 | 0.330 | **67%** | No | `CLOSE_NO_FRAUD` | `auto` |

| **HHG-013** | Risk Score (0.76) | `card_not_present_new_device` | **FRAUD** | 92 / 100 | 0.000 | **100%** | Yes | `BLOCK_ALL_CARDS` | `L2` |

| **HHG-014** | Analyst Request | `card_not_present_new_device` | **FRAUD** | 99 / 100 | 0.150 | **85%** | Yes | `BLOCK_ALL_CARDS` | `L2` |

| **HHG-015** | Risk Score (0.77) | `card_not_present_new_device` | **FRAUD** | 92 / 100 | 0.000 | **100%** | Yes | `BLOCK_ALL_CARDS` | `L2` |

| **HHG-016** | Customer Dispute | `card_not_present_new_device` | **FRAUD** | 99 / 100 | 0.000 | **100%** | Yes | `BLOCK_ALL_CARDS` | `L2` |

| **HHG-017** | Risk Score (0.57) | `card_not_present_fraud` | **FRAUD** | 85 / 100 | 0.150 | **85%** | No | `BLOCK_ALL_CARDS` | `L2` |

| **HHG-018** | Customer Dispute | `none` | **CLEARED** | 5 / 100 | 0.330 | **67%** | No | `CLOSE_NO_FRAUD` | `auto` |

| **HHG-019** | Risk Score (0.90) | `card_not_present_new_device` | **FRAUD** | 85 / 100 | 0.150 | **85%** | Yes | `BLOCK_ALL_CARDS` | `L2` |

| **HHG-020** | Risk Score (0.52) | `card_not_present_new_device` | **FRAUD** | 85 / 100 | 0.150 | **85%** | Yes | `BLOCK_ALL_CARDS` | `L2` |

Building an autonomous agent for production fintech required overcoming several non-trivial engineering hurdles:

`closed_cases_history.csv`) and built a `bottleneck`, `numexpr`).` sys.modules.setdefault("bottleneck", None)`) to ensure crash-proof operation across local environments and cloud deployments.`tigergraph__get_neighbors`, `tigergraph__get_node`) to restrict traversal expansions to relevant 2-hop neighborhoods, completing graph evaluations in under 1.5 seconds.
Deterministic policy rules and graph structure do not restrict AI agents—**they make them usable in high-liability industries**. By decoupling mathematical computation and statutory policy from fluid natural language synthesis, we achieved 100% regulatory compliance, zero arithmetic hallucinations, and defensible audit trails.

**Codebase & Benchmarks**: [GitHub Repository](https://github.com/VanshDeo/Zyg0s)

**Submission Track**: TigerGraph Agentic Fraud Investigation (Hacker House Goa)
