Read time:
3 minutes
Samantha Devlin
In our previous blog, we explored how AI could help surveillance analysts spend less time gathering information and more time applying judgement.
Since then, our accelerator framework has evolved from a single assistant into a coordinated network of Specialist Agents. By listening closely to how our clients work in practice, we have developed a robust solution that makes it easier to deploy governed AI tailored to suit each of their unique needs.
Surveillance investigations differ significantly depending on the behaviour being reviewed.
An insider trading investigation may require analysis of price-sensitive events, communications, employee access and trading timelines. A spoofing investigation is more likely to focus on order-book behaviour, cancellations, executions and market impact.
Rather than asking one general-purpose assistant to approach every alert in the same way, we have enabled a suite of Specialist Agents focused on particular risks or investigative tasks.
These could include agents specialising in:
Insider trading
Spoofing and layering
Wash trading
Front running
Electronic communications
Trader and peer-group analysis
Market news and event correlation
A multi-agent orchestrator coordinates these specialists, decides which expertise is needed and combines their findings into a single investigation. This allows each alert to be assessed through a workflow designed around the behaviour in question.
An Observer Agent monitors how the Specialist Agents operate, ensuring there is stronger oversight given this increase in autonomy. It checks whether the expected investigation steps were completed, the appropriate sources were consulted and the conclusions are supported by evidence.
It can also detect incomplete data, failed tool calls or a Specialist Agent attempting to move beyond its permitted scope.
While the Specialist Agents focus on the alert, the Observer Agent focuses on the quality and integrity of the process.
Every analyst question, underlying query, agent source and response is retained, creating a complete audit trail of the investigation.
This supports governance and review, while also helping surveillance teams identify broader patterns, such as:
Common questions asked during investigations
Data frequently needed outside the surveillance platform
Repeated manual checks that could be automated
Alert types requiring the greatest investigative effort
Gaps in existing investigation screens and workflows
All agents operate within the organisation’s existing data-security and access model. Most importantly, the Assistant inherits the analyst’s permissions and can only retrieve information that the user is authorised to see.
A specialist Calibration Agent is active through the same network, and instead of specialising in alert types, it specialises in the analysts’ behaviour over time. It consistently reviews alert outcomes and investigation patterns to identify where thresholds or benchmarks may no longer be effective.
The Calibration Agent advises surveillance teams by recommending updates to benchmarks and thresholds for alerts, tailored to products, desks and market conditions. Any recommendation remains subject to the organisation’s established testing and approval process, but helps make quicker and confident data-driven decisions.
Once an investigation is complete, the Assistant can use the gathered evidence to produce draft outputs, including:
Case-management escalation records
Risk and gap-analysis reports
Draft emails and recommended actions
Draft STORs (Suspicious Transaction and Order Reports)
This reduces the need to manually recreate the same narrative across different templates and systems.
Controls remain essential – generating an output does not automatically send it. The analyst’s (human) approval is still required, while recipient guardrails determine who is permitted to receive sensitive information. This helps reduce the risk of inappropriate disclosure or tipping off.
The Assistant can sit alongside the existing surveillance platform and integrate with Microsoft Teams or Slack.
Analysts can ask questions, receive investigation updates and review findings through familiar communication channels. The same identity controls, data permissions, audit logging and recipient restrictions continue to apply.
This means firms can introduce agentic capabilities without creating another disconnected system for analysts to monitor.
The Specialist Agents investigate individual risks → The Observer Agent monitors their operation → The Calibration Agent recommends alert improvements → The Reporting Agents prepare draft outputs.
Most importantly, the analyst reviews the evidence, applies professional judgement and makes the decision.
The latest version of our accelerator framework provides analysts with a coordinated team of specialist AI Agents – each with a defined role, governed access and a clear audit trail.
The agents do the legwork but the human-in-the-loop stays in control.
Data Intellect’s Accelerator for the Surveillance AI Assistant can be tailored to an organisation’s existing surveillance platform, data, policies and preferred models.
Share this: