Accelerator: Agentic Surveillance Assistant

Blog 9 Sep 2026

Read time:
3 minutes

Samantha Devlin

In our previous blog, we explored how AI could help surveillance analysts spend less time gathering information and more time applying judgement.

Since then, our accelerator framework has evolved from a single assistant into a coordinated network of Specialist Agents. By listening closely to how our clients work in practice, we have developed a robust solution that makes it easier to deploy governed AI tailored to suit each of their unique needs.

Why a multi-agent approach?

Surveillance investigations differ significantly depending on the behaviour being reviewed.

An insider trading investigation may require analysis of price-sensitive events, communications, employee access and trading timelines. A spoofing investigation is more likely to focus on order-book behaviour, cancellations, executions and market impact.

Rather than asking one general-purpose assistant to approach every alert in the same way, we have enabled a suite of Specialist Agents focused on particular risks or investigative tasks.

These could include agents specialising in:

  • Insider trading

  • Spoofing and layering

  • Wash trading

  • Front running

  • Electronic communications

  • Trader and peer-group analysis

  • Market news and event correlation

A multi-agent orchestrator coordinates these specialists, decides which expertise is needed and combines their findings into a single investigation. This allows each alert to be assessed through a workflow designed around the behaviour in question.

Agentic Surveillance Assistant

Oversight through an Observer Agent

An Observer Agent monitors how the Specialist Agents operate, ensuring there is stronger oversight given this increase in autonomy. It checks whether the expected investigation steps were completed, the appropriate sources were consulted and the conclusions are supported by evidence.

It can also detect incomplete data, failed tool calls or a Specialist Agent attempting to move beyond its permitted scope.

While the Specialist Agents focus on the alert, the Observer Agent focuses on the quality and integrity of the process.

Governance, Governance, Governance!

Every analyst question, underlying query, agent source and response is retained, creating a complete audit trail of the investigation.

This supports governance and review, while also helping surveillance teams identify broader patterns, such as:

  • Common questions asked during investigations

  • Data frequently needed outside the surveillance platform

  • Repeated manual checks that could be automated

  • Alert types requiring the greatest investigative effort

  • Gaps in existing investigation screens and workflows

All agents operate within the organisation’s existing data-security and access model. Most importantly, the Assistant inherits the analyst’s permissions and can only retrieve information that the user is authorised to see.

A Dedicated Calibration Agent

A specialist Calibration Agent is active through the same network, and instead of specialising in alert types, it specialises in the analysts’ behaviour over time. It consistently reviews alert outcomes and investigation patterns to identify where thresholds or benchmarks may no longer be effective.

The Calibration Agent advises surveillance teams by recommending updates to benchmarks and thresholds for alerts, tailored to products, desks and market conditions. Any recommendation remains subject to the organisation’s established testing and approval process, but helps make quicker and confident data-driven decisions.

From Investigation to Action

Once an investigation is complete, the Assistant can use the gathered evidence to produce draft outputs, including:

  • Case-management escalation records

  • Risk and gap-analysis reports

  • Draft emails and recommended actions

  • Draft STORs (Suspicious Transaction and Order Reports)

This reduces the need to manually recreate the same narrative across different templates and systems.

Controls remain essential – generating an output does not automatically send it. The analyst’s (human) approval is still required, while recipient guardrails determine who is permitted to receive sensitive information. This helps reduce the risk of inappropriate disclosure or tipping off.

Integrated with Communication Channels

The Assistant can sit alongside the existing surveillance platform and integrate with Microsoft Teams or Slack.

Analysts can ask questions, receive investigation updates and review findings through familiar communication channels. The same identity controls, data permissions, audit logging and recipient restrictions continue to apply.

This means firms can introduce agentic capabilities without creating another disconnected system for analysts to monitor.

The Analyst Remains in Control

The Specialist Agents investigate individual risks → The Observer Agent monitors their operation → The Calibration Agent recommends alert improvements → The Reporting Agents prepare draft outputs.

Most importantly, the analyst reviews the evidence, applies professional judgement and makes the decision.

The latest version of our accelerator framework provides analysts with a coordinated team of specialist AI Agents – each with a defined role, governed access and a clear audit trail.

The agents do the legwork but the human-in-the-loop stays in control.

Data Intellect’s Accelerator for the Surveillance AI Assistant can be tailored to an organisation’s existing surveillance platform, data, policies and preferred models.

Want to see a demo?

Contact us

Share this:

LET'S CHAT ABOUT YOUR PROJECT.

GET IN TOUCH