Sentinel AI is a production-grade, multi-agent fraud detection and case management platform for banking. It ingests financial transactions in real time, runs them through a 5-agent AI pipeline powered by Google ADK and Gemini, assigns risk scores, executes policy-governed actions, and surfaces everything in a live Fraud Case Management Dashboard.
All screenshots captured from the live local development build at
http://localhost:3001. Pre-seeded with case F-9204 (Sarah Jenkins · TX-DEMO-001 · score=85 · CRITICAL · BLOCK).
KPI cards (Total Alerts, Pending Reviews, Avg Risk Score, Prevented Loss) · Case Risk Score gauge · Fraud Trends chart · Recent Alerts queue.
Submit a raw transaction JSON to trigger the full 5-agent pipeline. Pre-loaded with the Sarah Jenkins / TX-DEMO-001 scenario (Lagos, Nigeria · CARD_NOT_PRESENT · $4,950 · new device).
Case ID, customer name, CRITICAL severity badge, risk score 85/100, freeze_transaction recommended action, assigned analyst, and policy version.
Flags detected: GEO_MISMATCH, RAPID_LOCATION_CHANGE. Reasoning: rapid geographic shift from New York to Lagos.
Flags detected: AMOUNT_SPIKE, NEW_DEVICE. Full behavioral deviation scoring with contribution breakdown.
Weighted score blending (pattern + behavioral), boost applied, final score 85 · CRITICAL · BLOCK.
Timestamped, correlation-ID-linked entries for every pipeline event: Pattern Analyzer flag → Risk score computed → Transaction frozen → Case assigned. Policy version badge visible on every entry.
Avg Time to Close: 3.4 hrs · Escalation Rate: 12% · Alerts by Severity bar chart · Top Fraud Flags: GEO_MISMATCH, NEW_DEVICE, AMOUNT_SPIKE, BURST_ACTIVITY, NEW_IP_RANGE.
System configuration, agent versions, and alert routing thresholds (read-only).
The Google ADK Developer Interface with SentinelOrchestrator selected. Shows the Trace / Events / State / Artifacts / Sessions / Eval tabs and the chat input for submitting transactions directly to the agent.
After submitting the Sarah Jenkins transaction, all 5 tool calls are visible in real time:
run_pattern_analyzer → run_behavioral_risk → run_evidence_builder → run_aggregated_scorer → run_action_executor. ✓ = completed, ⚡ = in-flight.
Expanded event panel showing the SentinelOrchestrator agent graph with all 5 sub-tools connected, plus the raw functionResponse JSON for run_behavioral_risk.
┌─────────────────────────────────────────────────────────────────────────────┐
│ FRAUD DETECTION AGENTS (Google ADK + Gemini) │
│ │
│ Agent #1: TransactionPatternAnalyzer │
│ │
│ Agent #2: BehavioralRiskAgent │
│ │
│ Agent #3: EvidenceBuilder │
│ │
│ Agent #4: AggregatedRiskScorer │
│ │
│ Agent #5: ActionExecutor │
└─────────────────────────────────────────────────────────────────────────────┘
│
▼
┌─────────────────────────────────────────────────────────────────────────────┐
│ GOOGLE CLOUD PLATFORM │
│ │
│ Vertex AI Gemini 2.5 Flash (via google-genai SDK) │
│ Cloud Run Future API service deployment │
│ Secret Manager Service account keys │
│ Cloud Logging Agent execution logs │
└─────────────────────────────────────────────────────────────────────────────┘
| # | Agent | Status | Responsibility | Tools Count |
|---|---|---|---|---|
| — | SentinelOrchestrator | ✅ Implemented | Coordinates the pipeline, invokes agents #1-5 in sequence | 5+ coordination tools |
| 1 | TransactionPatternAnalyzer | ✅ Implemented | Detect global anomalies: unusual amounts, rare merchants, impossible travel, velocity bursts | 6 tools |
| 2 | BehavioralRiskDetector | ✅ Implemented | Score deviation from customer's personal historical behavior | 8 tools |
| 3 | EvidenceBuilderAgent | ✅ Implemented | Produce deterministic, audit-ready explanation bundle | Evidence building tools |
| 4 | AggregatedRiskScorer | ✅ Implemented | Combine pattern + behavioral scores with policy weights into final 0–100 score | Scoring & calibration tools |
| 5 | ActionExecutor | ✅ Implemented | Execute policy-approved actions via explicit tools | Action execution tools |
| Layer | Technology |
|---|---|
| AI / Agents | Google ADK 0.9.0, Gemini 2.5 Flash |
| Agent Runtime | Java 17, Maven 3.8+, ADK InMemoryRunner |
| Agent Tools | FunctionTool, deterministic calculations (z-score, Haversine, etc.) |
| Frontend | Next.js 16, React 19, TypeScript 5 |
| Cloud | Google Cloud Platform, Vertex AI API |
| Containers | Docker, eclipse-temurin:17-jre-alpine |
- Java 17+, Maven 3.8+
- Google Cloud Project with Vertex AI API enabled
- Service Account JSON with Vertex AI permissions
cd sentinel-ai-platform/sentinel-ai-agent
export GOOGLE_CLOUD_PROJECT="your-project-id"
export GOOGLE_APPLICATION_CREDENTIALS="/path/to/service-account.json"
mvn compile exec:java@orchestratorExample interaction:
You > Analyze transaction: customer=CUST-123, amount=1500 EUR,
merchant=electronics, country=NG, time=2026-03-17T03:00:00Z
Agent > 🚀 Running 5-agent pipeline...
✅ Pattern Analyzer: risk_score=86, flags=[AMOUNT_SPIKE, GEO_MISMATCH]
✅ Behavioral Risk: behavioral_score=77, flags=[NEW_DEVICE, UNUSUAL_TIME]
✅ Evidence Builder: evidence compiled
✅ Aggregated Scorer: final_score=92, severity=CRITICAL
✅ Action Executor: BLOCK_AND_NOTIFY executed
📊 Final Decision: BLOCK transaction, notify security team
cd sentinel-ai-platform/sentinel-ai-agent
mvn compile exec:java
Go to http://localhost:8080/ to interact with individual agents via web.GET /api/alerts?page=1&limit=10&severity=CRITICAL&status=REVIEWING&q=sarah
Response:
{
"data": [
{
"id": "ALERT-001",
"transactionId": "TX-9204",
"customerId": "CUST-SJ01",
"customerName": "Sarah Jenkins",
"finalRiskScore": 85,
"severity": "CRITICAL",
"status": "REVIEWING",
"recommendedAction": "freeze_transaction",
"timestamp": "2026-03-17T10:00:00Z",
"caseId": "F-9204"
}
],
"meta": { "page": 1, "limit": 10, "total": 6, "totalPages": 1 }
}GET /api/cases/{id}
POST /api/cases/{id}/assign { "assignTo": "Marcus Vance" }
POST /api/cases/{id}/note { "content": "Reviewed login history" }
POST /api/cases/{id}/escalate
POST /api/cases/{id}/close
Case states: OPEN → IN_REVIEW → ESCALATED → CLOSED
Every mutation appends to auditTrail[] with timestamp, actor, and policy version.
GET /api/analytics
Returns: alertsBySeverity[], trendsLast30Days[], topFlags[], avgTimeToCloseHours, escalationRatePct
POST /api/ingest
Content-Type: application/json
Body: raw transaction JSON. Triggers the full 5-agent pipeline. Timeout: 90 s.
Returns: complete CaseDetail of the newly created case.
GET /health
→ { "status": "UP" }
| Page | Description |
|---|---|
| Dashboard | Live KPI cards · risk score gauge · fraud trend chart · agent reason chain (with Approve / Reject Case buttons) · recent alerts queue (rows navigate to case detail) |
| Case Detail | Full case view: alert metadata · per-agent outputs (tabbed) · executed actions · interactive audit timeline · quick-action panel (assign / note / escalate / close) |
| Analytics | Alerts by severity · 30-day trend · top fraud flags · avg time-to-close · escalation rate |
| Admin | Policy version · agent versions · alert routing thresholds · system config (read-only) |
Ingest modal — Submit a raw transaction JSON from the dashboard. The 5-agent pipeline runs and the new case opens automatically.
Approve / Reject buttons on the dashboard reason chain call POST /api/cases/F-9204/close and POST /api/cases/F-9204/escalate with live loading and success states.
Both services deploy automatically to Cloud Run via GitHub Actions on push to main.
| Secret | Description |
|---|---|
GCP_PROJECT_ID |
Google Cloud project ID |
GCP_SA_KEY |
GitHub Actions service account key (JSON) |
SENTINEL_API_URL |
Public Cloud Run URL of sentinel-api |
| Service | CPU | Memory | Min instances | Max instances | Timeout |
|---|---|---|---|---|---|
sentinel-api |
2 | 2 Gi | 0 | 8 | 300 s |
sentinel-web |
1 | 512 Mi | 0 | 4 | 60 s |
GEMINI_API_KEY is injected from Secret Manager at runtime — never stored in environment variables or source code.
| Variable | Default | Description |
|---|---|---|
PORT |
8080 |
HTTP server port |
GEMINI_API_KEY |
— | Gemini API key (required for pipeline) |
GEMINI_MODEL |
gemini-2.5-flash |
Gemini model name |
LOG_LEVEL |
INFO |
Application log level |
POLICY_VERSION |
action-policy-2026-03-16 |
Active action policy version |
| Variable | Default | Description |
|---|---|---|
SENTINEL_API_URL |
"" |
Java API base URL. Empty = use in-memory mock. |
✅ Tool-based agents — All fraud detection logic implemented as explicit FunctionTools, not in prompts
✅ Deterministic signals — Pattern and behavioral tools use deterministic calculations (z-score, Haversine distance, CIDR matching)
✅ Explainability first — Every agent provides reasoning with feature contributions and version info for audit trail
✅ Strict role separation — Each agent has a single responsibility. Pattern analyzes global signals, Behavioral analyzes customer-specific signals.
✅ Version tracking — All agent outputs include version numbers (agent version + config version) for compliance
✅ Stateless & testable — Agents have no session state, can be tested independently via interactive CLI
✅ Policy-governed actions — Future Action Executor will only call explicitly registered tools, cannot improvise
✅ Observable — Structured logging with agent versions, tool execution details, and timing information