Building Zyg0s: An Autonomous, Explainable Fraud Investigation Agent Powered by TigerGraph Savanna Cloud & MCP Vansh Deo and team QueryCrew built Zyg0s, an autonomous, explainable fraud investigation agent that fuses seven neuro-symbolic agents with TigerGraph Savanna Cloud, Model Context Protocol, and Groq to traverse entity networks across 590,000+ IEEE-CIS transactions. The system grades evidence on a four-tier defensibility framework, quantifies epistemic uncertainty, enforces Bank Fraud Policy Rules R1–R10 with two-stage actions, and drafts FinCEN BSA/AML Suspicious Activity Reports while writing closed cases back into graph memory. TigerGraph Agentic Fraud Investigation Hackathon Hacker House Goa / HHGOA Track Author: Vansh Deo Team Name: QueryCrew GitHub Repository: https://github.com/VanshDeo/Zyg0s https://github.com/VanshDeo/Zyg0s Video Demo 3–5 min : Watch Live Walkthrough https://your-video-link-here Live Application: Launch Zyg0s Workbench https://your-live-app-link-here Zyg0s is an autonomous, explainable cyber-investigation platform engineered to resolve the hardest bottleneck in modern banking: investigating complex financial crime and recommending defensible next-best actions when available signals are noisy and uncertain . Powered by TigerGraph Savanna Cloud , Model Context Protocol MCP , and Groq , Zyg0s fuses 7 specialized neuro-symbolic agents to traverse deep entity networks across 590,000+ IEEE-CIS transactions. It mathematically grades evidence across a 4-tier defensibility framework, quantifies epistemic uncertainty $U$ , enforces Bank Fraud Policy Rules R1–R10 with dynamic two-stage actions, synthesizes regulator-grade FinCEN BSA/AML Suspicious Activity Reports SARs , and updates graph-native case memory. Every financial institution in the world faces an acute operational bottleneck: fraud investigation is manual, slow, and fragmented . When an upstream machine learning model flags a suspicious credit card transaction, the money is often already in flight. Human fraud analysts are forced to swivel between five disjointed screens: looking up transaction logs, examining device fingerprints, querying customer historical baselines, checking core banking policies, and cross-referencing past fraud cases. By the time a case is manually triaged and reviewed, the fraud ring has moved on to siphon funds from dozens of other accounts. Compounding this crisis are three structural traps: We built Zyg0s named after the ancient Greek zygos , the forensic scale of balance and evidence weighting . ┌────────────────────────────────────────────────────────┐ │ WHAT IS ZYG0S? │ │ An Autonomous, Explainable Fraud Investigation Agent │ │ fusing TigerGraph Savanna Cloud, Model Context │ │ Protocol MCP , and 7 Neuro-Symbolic Agents. │ └────────────────────────────────────────────────────────┘ Rather than treating fraud as a simple black-box binary classification problem, Zyg0s models fraud investigation as an adaptive, 8-stage evidentiary legal trial . It gathers multi-hop graph signals from TigerGraph Savanna Cloud , grades evidence across a 4-tier defensibility framework, quantifies epistemic uncertainty $U$ , recommends policy-governed two-stage actions, drafts regulatory FinCEN BSA/AML Suspicious Activity Reports SARs , and writes closed cases back into graph memory. Fraud is fundamentally relational—it lives in the connections between cards, devices, IP subnets, billing regions, and email domains. Relational databases choke on the recursive joins required to unmask synthetic identities and collusion rings. TigerGraph Savanna Cloud provided the foundational backbone for Zyg0s: Trident/7.0 | Windows 10 | IE 11.0 is isolated to one customer or acting as a shared gateway across 15+ compromised cards. ClosedCase , linked via semantic and topological edges, enabling zero-latency precedent retrieval. Zyg0s resolves the AI compliance paradox by implementing a strict Neuro-Symbolic Division of Labor : ┌──────────────────────────────────────────────────────────────────────────────────┐ │ NEURO-SYMBOLIC DIVISION OF LABOR │ ├────────────────────────────────────────┬─────────────────────────────────────────┤ │ 🛡️ DETERMINISTIC GOVERNOR Symbolic │ 🧠 LLM COGNITIVE LAYER Neural │ │ "Absolute Truth, Math, & Compliance" │ "Fluid Reasoning, Synthesis, & Copilot" │ ├────────────────────────────────────────┼─────────────────────────────────────────┤ │ • GSQL multi-hop graph traversals │ • Novel pattern discovery & naming R9 │ │ • Entity resolution & device clusters │ • Legal-grade FinCEN BSA/AML SAR draft │ │ • Immutable numerical fact anchoring │ • Natural language "What Changed" logs │ │ • 4-Tier evidence defensibility math │ • Interactive Investigator Copilot Q&A │ │ • Uncertainty score formula U = 1-C │ • Explaining edge cases to analysts │ │ • Bank Fraud Policy v1.0 R1–R10 gate │ • Zero-hallucination factual grounding │ │ • Tiered permissions auto, L1, L2 │ • Graceful offline fallback │ │ • Graph writeback to Savanna Cloud │ │ └────────────────────────────────────────┴─────────────────────────────────────────┘ Multi-Modal Ingestion ┌───────────────────────┬───────────────────────┐ Risk Score Customer Report Analyst Request 0.00 - 1.00 Disputed Amount Graph Cluster Traversal └───────────────────────┬───────────────────────┘ │ ▼ 7-Agent Pipeline Engine ┌─────────────────────────────────────────────────────────────┐ │ 1. Alert Sentinel ──► Ingests alert, computes Z-scores │ │ 2. Graph Scout ──► TigerGraph Savanna Cloud MCP │ │ 3. Evidence Assessor ──► 4-Tier Defensibility & U index │ │ 4. Pattern Strategist ──► Typology match & novel patterns │ │ 5. Policy Governor ──► Bank Policy v1.0 R1-R10 & NBA │ │ 6. Compliance Officer ──► FinCEN BSA/AML SAR 5 W's │ │ 7. Memory Weaver ──► TigerGraph Graph Memory Commit │ └─────────────────────────────┬───────────────────────────────┘ │ ▼ Interactive Workbench UI Case Queue • Live Progression • Graph & SAR Workspace Zyg0s executes an 8-stage state machine that mirrors how elite forensic investigators work: 1. Trigger Ingest alert via risk score, dispute, or analyst request. │ 2. Investigate Open case, retrieve historical baselines & card history. │ 3. Gather Evidence Traverse TigerGraph 2-hop ego network & shared devices. │ 4. Assess Uncertainty Compute Epistemic Uncertainty U. If U 0.40, stop destructive actions │ 5. Gather More Evidence Issue non-destructive Step-Up Challenge SMS OTP / Biometric . │ 6. Take Next Actions Evaluate Bank Policy R1-R10; evolve Stage 1 NBA into Stage 2 Final NBA. │ 7. Explain Decision Synthesize 5 W's rationale citing policy rules & evidence grades. │ 8. Update Case Memory Persist case vertex to TigerGraph Cloud via Hybrid RRF Index. A central innovation of Zyg0s is our strict containment of Large Language Models Groq / Qwen 2.5 : L2 Manager approval . In Zyg0s, recommendations are not static—they dynamically evolve across a Two-Stage Next-Best Action NBA lifecycle: $$ \text{Confidence} = \left| \frac{\sum w i}{\sum |w i| + \epsilon} \right| \times \min\left 1.0, \frac{N}{N {\text{min}}}\right $$ $$ U = 1.0 - \text{Confidence} $$ VERIFY WITH CUSTOMER and MONITOR CARD . CLOSE NO FRAUD Card remains active . BLOCK ALL CARDS , CREATE CASE , and FILE REPORT under Zyg0s was rigorously evaluated against all 20 official benchmark exam cases from the final two months of the IEEE-CIS / Vesta dataset: | Case ID | Trigger Channel | Typology Pattern | Final Verdict | Risk Score | Epistemic Uncertainty $U$ | Final Confidence | SAR Filed? | Next Best Action | Approval Route | | :---: | :---: | :---: | :---: | :---: | :---: | :---: | :---: | :---: | :---: | | HHG-001 | Risk Score 0.61 | none | CLEARED | 5 / 100 | 0.330 | 67% | No | CLOSE NO FRAUD | auto | | HHG-002 | Risk Score 0.79 | card not present fraud | CLEARED | 5 / 100 | 0.000 | 100% | No | CLOSE NO FRAUD | auto | | HHG-003 | Customer Dispute | none | FRAUD | 95 / 100 | 0.330 | 67% | No | BLOCK CARD | L1 | | HHG-004 | Customer Dispute | card not present new device | FRAUD | 99 / 100 | 0.150 | 85% | No | BLOCK CARD | L1 | | HHG-005 | Risk Score 0.54 | card not present new device | FRAUD | 85 / 100 | 0.150 | 85% | No | BLOCK ALL CARDS | L2 | | HHG-006 | Customer Dispute | card not present new device | FRAUD | 99 / 100 | 0.150 | 85% | No | BLOCK CARD | L1 | | HHG-007 | Risk Score 0.87 | account takeover | FRAUD | 85 / 100 | 0.150 | 85% | No | BLOCK CARD | L1 | | HHG-008 | Customer Dispute | none | CLEARED | 5 / 100 | 0.330 | 67% | No | CLOSE NO FRAUD | auto | | HHG-009 | Customer Dispute | none | CLEARED | 5 / 100 | 0.330 | 67% | No | CLOSE NO FRAUD | auto | | HHG-010 | Risk Score 0.90 | card not present new device | FRAUD | 85 / 100 | 0.150 | 85% | No | BLOCK ALL CARDS | L2 | | HHG-011 | Customer Dispute | none | CLEARED | 5 / 100 | 0.550 | 45% | No | CLOSE NO FRAUD | auto | | HHG-012 | Risk Score 0.55 | none | CLEARED | 5 / 100 | 0.330 | 67% | No | CLOSE NO FRAUD | auto | | HHG-013 | Risk Score 0.76 | card not present new device | FRAUD | 92 / 100 | 0.000 | 100% | Yes | BLOCK ALL CARDS | L2 | | HHG-014 | Analyst Request | card not present new device | FRAUD | 99 / 100 | 0.150 | 85% | Yes | BLOCK ALL CARDS | L2 | | HHG-015 | Risk Score 0.77 | card not present new device | FRAUD | 92 / 100 | 0.000 | 100% | Yes | BLOCK ALL CARDS | L2 | | HHG-016 | Customer Dispute | card not present new device | FRAUD | 99 / 100 | 0.000 | 100% | Yes | BLOCK ALL CARDS | L2 | | HHG-017 | Risk Score 0.57 | card not present fraud | FRAUD | 85 / 100 | 0.150 | 85% | No | BLOCK ALL CARDS | L2 | | HHG-018 | Customer Dispute | none | CLEARED | 5 / 100 | 0.330 | 67% | No | CLOSE NO FRAUD | auto | | HHG-019 | Risk Score 0.90 | card not present new device | FRAUD | 85 / 100 | 0.150 | 85% | Yes | BLOCK ALL CARDS | L2 | | HHG-020 | Risk Score 0.52 | card not present new device | FRAUD | 85 / 100 | 0.150 | 85% | Yes | BLOCK ALL CARDS | L2 | Building an autonomous agent for production fintech required overcoming several non-trivial engineering hurdles: closed cases history.csv and built a bottleneck , numexpr . sys.modules.setdefault "bottleneck", None to ensure crash-proof operation across local environments and cloud deployments. tigergraph get neighbors , tigergraph get node to restrict traversal expansions to relevant 2-hop neighborhoods, completing graph evaluations in under 1.5 seconds. Deterministic policy rules and graph structure do not restrict AI agents— they make them usable in high-liability industries . By decoupling mathematical computation and statutory policy from fluid natural language synthesis, we achieved 100% regulatory compliance, zero arithmetic hallucinations, and defensible audit trails. Codebase & Benchmarks : GitHub Repository https://github.com/VanshDeo/Zyg0s Submission Track : TigerGraph Agentic Fraud Investigation Hacker House Goa