iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
AEGIS is a challenge project that combines a graph of connected entities, bounded investigation tools, historical and policy context, and human approval gates to help investigate fraud alerts. Its author, Kanwal Vyas, describes a workflow for gathering and assessing evidence—not an autonomous fraud verdict or proof of production reliability.
What AEGIS is designed to do
AEGIS stands for Agentic Evidence & Graph Intelligence System. Vyas describes it as a fraud-investigation platform built for the TigerGraph HHGOA challenge. Rather than treating a transaction score as a conclusion, the system is intended to investigate what is connected to the transaction, what evidence supports or contradicts suspicion, what remains uncertain, and what action policy permits.
The project account appeared on DEV Community on September 25, 2026. It is the author’s description of a challenge project, not an independent product evaluation. Vyas captures the intended distinction in one sentence: “A fraud signal is not automatically a fraud verdict.”
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
How an investigation moves through the system
The described workflow starts with a fraud signal or customer report and proceeds through triage, investigation, evidence assessment, policy review, and a possible human-authorized action. The investigation is not simply a score passed to an action endpoint: evidence gathering, recommendation, authorization, execution, and case retention are separate parts of the flow.
#1 Best Overall
- Receive and triage the trigger. An alert or customer report starts the investigation.
- Gather evidence. An orchestrator calls bounded tools to retrieve transaction details and examine velocity, shared devices, connected cards, and historical cases.
- Build context. The system combines current graph evidence with relevant closed investigations, policy context, and regulatory references through its GraphRAG approach.
- Assess the evidence. The investigation considers support for a fraud hypothesis, uncertainty or conflicting evidence, and whether the evidence is sufficient for the next decision.
- Evaluate policy and recommend a next action. A proposed action is checked against policy, including whether approval is required.
- Obtain authorization where needed and track execution state. A recommendation can remain pending until an authorized person approves it.
- Write the case back. Findings, evidence, decisions, actions, outcomes, related entities, and status can be retained for future investigations.
What the graph, MCP tools, and GraphRAG contribute
TigerGraph connects an alert to related entities
The project’s graph models customers, cards, device profiles, email domains, billing regions, transactions, closed investigations, and investigation cases. A transaction can therefore be examined in relation to its customer and card, devices associated with activity, connected cards, and earlier cases. This broadens the investigation beyond the individual transaction without making every relationship proof of wrongdoing.
AEGIS also uses TigerGraph Weakly Connected Components as a structural signal. Component membership indicates graph connectivity; Vyas explicitly distinguishes it from a fraud verdict.
Rank #2
MCP exposes bounded investigation operations
The article names six tools: get_transaction, detect_velocity, find_shared_devices, find_connected_cards, get_card_history, and get_historical_cases. The orchestrator is described as an eight-step, bounded workflow. It selects subsequent investigation steps based on collected evidence—for example, shared-device findings can prompt checks for connected cards and relevant historical cases.
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →GraphRAG adds history and policy context
GraphRAG brings together current graph evidence, historical closed investigations, policy context, and regulatory references. A prior case can inform the current one, but it is context rather than an automatic conclusion. The account does not establish that a precedent alone determines an outcome.
Why evidence, uncertainty, and sufficiency are separate
AEGIS treats three questions as distinct: how strongly the evidence supports a fraud hypothesis, how much ambiguity or conflicting information remains, and whether the available evidence is sufficient to justify the next decision. That separation matters when relationships are suggestive but not conclusive. A shared device may warrant further investigation, for example, without establishing that every connected account is fraudulent.
The project says the system records uncertainty and evidence gaps explicitly. In practical terms, a recommendation should be read alongside what supports it, what conflicts with it, and what information is still missing—not as a claim that uncertainty has disappeared.
Recommendation is not authorization or execution
Vyas describes recommendation, authorization, and execution as separate states. A BLOCK_CARD recommendation, for example, can require L1 approval while execution remains PENDING_APPROVAL. This approval gate is intended to prevent an agent from silently carrying out a destructive action. The article’s formulation is concise: “A recommendation is not authorization.”
For suspicious activity report (SAR)-related work, AEGIS can prepare an auditable package with investigation information and entity lineage for review. Vyas states that the system does not autonomously file a SAR with regulators. The distinction is between preparing material for a human review process and submitting a regulatory filing.
Best Value
- Intuitive interface of a conventional FTP client
- Easy and Reliable FTP Site Maintenance.
- FTP Automation and Synchronization
What the two demonstration cases show
| Case | Trigger and investigation | Reported outcome |
|---|---|---|
| HHG-010 | A $1,000.03 risk-score alert led to transaction retrieval, velocity checks, shared-device and connected-card analysis, and historical-case retrieval. | Vyas says the assessment found significant evidence alongside high uncertainty. The recommendation was VERIFY_WITH_CUSTOMER, required L1 approval, and remained pending approval. A SAR-preparation recommendation was also generated, and the case was written to memory. |
| HHG-003 | A customer report triggered an investigation. | The recommendation was BLOCK_CARD; it still required L1 approval and remained pending approval. |
These examples illustrate how the described system can connect evidence gathering to a recommendation while keeping approval and action status visible. They do not, on their own, establish how accurately the system detects fraud across real-world cases.
How to interpret the reported benchmark
Vyas reports the following project benchmark results in the 2026 article. These are author-reported results, not independently verified industry findings:
| Reported measure | Project-reported result | What the article establishes |
|---|---|---|
| Benchmark cases processed | 20/20 | Vyas reports all benchmark cases were processed. |
| Investigation cases persisted | 20/20 | Vyas reports all investigation cases were persisted. |
| Budget compliance | 100% | Vyas reports full compliance with the project’s budget criterion. |
| Tool-call duplication; missing-entity contamination; policy mismatches; unreferenced destructive recommendations; denied destructive actions; lifecycle inconsistencies | 0 reported for each | These are the project’s reported benchmark checks, not independently audited rates. |
| Automated tests passed | 111 | Vyas reports 111 automated tests passed. |
The article says the benchmark includes before-and-after additional-evidence fields for cases where more evidence is required. It does not provide independent evaluation details sufficient to treat these results as an external audit, a general fraud-detection accuracy measure, or evidence of performance across an industry population.
Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minutePC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11What the project account does—and does not—establish
The account describes a coherent design pattern: traverse entity relationships, choose evidence-gathering steps based on findings, bring historical and policy context into the assessment, represent uncertainty, gate consequential actions, and preserve case information. It also reports a bounded benchmark and automated test count.
It does not establish comparative performance against other systems, independent validation, or the reliability of autonomous fraud decisions in production. Its benchmark counts should stay attached to this project and its author; they are not industry statistics. The most useful takeaway is the separation of concerns in the design: graph connections help guide investigation, evidence informs assessment, policy constrains recommendations, people authorize gated actions, and case memory retains the investigation.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

