- Customer — name, dob, nationalId (PII, restricted), riskRating
- Alert — alertType, matchScore, sanctionsHit, status
Screen under allowlist. Dispose under dual control.
A reference blueprint for KYC onboarding and AML review — screening and case-disposition agents under strict model and tool allowlists, with every decision explained, dual-controlled, and chained to evidence on the Cortex runtime. This blueprint specifies the ontology, policies, actions, and agents; the signed, installable pack is on the roadmap.
off-allowlist model → 403 · dual-control disposition · reference blueprint (not yet a signed artifact)
One governed blueprint — the whole solution, specified.
The KYC/AML blueprint governs customer onboarding and the disposition of AML alerts. It specifies the screening ontology (customer, alert), the policies that enforce allowlists, sanctions-hit holds, and dual-control on adverse decisions, the Action Fabric actions that escalate or close a case, and three curated agents — so a high-scrutiny review workflow is defined as one governed solution that an examiner can take apart.
The targets the pack is tuned to.
Illustrative targets for this use-case, configurable per deployment — the gates that enforce them are specified in the blueprint.
Four governed sections, one blueprint.
A blueprint specifies the four governed sections a Solution Pack bundles. When it ships as a signed pack, the same envelope — canonicalize → sha256 contentHash → HMAC signature — is what makes it portable and provable.
- Off-allowlist model or tool → 403 (fail-closed)
- Sanctions hit → hold, escalate to human reviewer
- Adverse disposition → dual-control (two approvers)
- nationalId is restricted — read denied outside screening
- escalateCase — riskTier: medium, opens human review
- closeCase — riskTier: high, dual-control approval
- requestEDD — riskTier: low, enhanced due diligence
- KYC Screener — onboarding checks under strict allowlist
- AML Triage — scores alerts, cites the matched signals
- Case Disposer — proposes disposition, never closes alone
Governed agents, mapped to real Cortex controls.
Every capability in this pack is enforced by a runtime control you can audit — identity, policy, action approvals, and a sealed Trust Ledger. The pack configures them; the platform enforces them.
- Agents may use only allowlisted models and tools. An off-allowlist call returns 403 — there is no quiet fallback to an unapproved model on a sanctions decision.
- closeCase is a high-risk action requiring two approvers. No single agent — and no single human — can quietly clear an AML alert; the second pair of eyes is policy, not procedure.
- The AML Triage agent cites the signals behind each match score and sanctions hit. Dispositions carry a rationale a regulator can read — no opaque scoring.
- A sanctions match forces a hold and a human escalation by policy. The agent cannot self-clear a hit; it routes the case to a reviewer with the evidence attached.
- nationalId and dob are restricted properties — read-denied outside the screening agents that need them, keeping sensitive identity data out of unrelated prompts.
- Each escalation and closure is sealed in the hash-chained Trust Ledger with a signed receipt and 10-hop lineage — so a disputed disposition has a tamper-evident record behind it.
A blueprint today — a signed, installable pack on the roadmap.
This blueprint fully specifies the ontology, policies, Action Fabric actions, and agents. When it ships as a Solution Pack it inherits the same packaging every Cortex pack uses: canonicalize → sha256 contentHash → HMAC signature, then a verify-first importPreview → importApply that checks hashOk + signatureOk before a single row is written — into your own tenant only.
- Ontology, policies, and Action Fabric actions specified and ready to package
- On publish: verifyPack checks hashOk + signatureOk before import
- Runs on the same governed runtime as the shipping Tax pack — same gates, same ledger
- Want it sooner? Bring your workflow and we'll prioritize the build.
How this blueprint becomes an installable pack.
The design is done; packaging is what remains. A blueprint carries the same four governed sections a shipping pack does — it just isn't sealed and signed yet.
- 01
Specified today
The ontology, policies, Action Fabric actions, and agents above are the real design — the same shape the runtime enforces for every shipping pack.
- 02
Packaged & signed
When it ships, the contents canonicalize → sha256 contentHash → HMAC signature and land in the registry on a stable or beta channel — exactly like the Tax pack.
- 03
Verify & install
importApply re-checks hashOk and signatureOk, then idempotently upserts into your own tenant. Until then, we can stand the workflow up for you from this blueprint.
The controls your auditors already cite — built in.
The ontology permissions, fail-closed policies, approval gates, and sealed Trust Ledger map directly to the frameworks this use-case reports against. Aligned with — never claiming a certification you don't hold.
The pack is configuration — the runtime does the enforcing.
This pack rides the same governed runtime as every other Cortex solution. Explore the controls it configures and the industry it serves.
Banking & KYC/AML industry
Onboarding, screening, and case-disposition agents under strict allowlists and dual control.
Agent IAM
The model and tool allowlists that make an off-allowlist call return 403 are enforced at issuance.
Trust Ledger
Where every disposition is sealed — verifiable offline when an examiner challenges a decision.
Oversight
Dual-control approval modes for high-risk closures — autonomy can only tighten the gate.
Ship KYC/AML review that an examiner can take apart.
Bring your onboarding and AML workflow and we'll stand up the governed pack from this blueprint — screening under strict allowlists with dual-control on every adverse decision.