★ Winner · Microsoft Agents League 2026 · Hack for Good (1 of 3)
Problem
Manual KYC/AML review doesn't scale, and unaudited AI decisions don't survive a regulator's audit.
Solution
Five specialist agents coordinated over A2A on Azure AI Foundry. Every finding is cited via Foundry IQ. Full audit trail. All decisions are explainable, reproducible, and regulatory-proof.
A governed institutional-agent fleet for continuous access review
Problem
Access review is quarterly work performed on continuously changing permissions. Automating the scan isn't enough — an institutional agent must remember prior human decisions, survive asynchronous retries, prove why it acted, and remain unable to turn suspicious input into a privileged write.
Solution
Read-only IAM review against the GCP project that runs it, including its own service identities. Deterministic code detects and scores findings; Gemini explains and routes already-minimized risk. Three institutional agents, one durable investigation identity — no raw IAM binding crosses the model or human-notification boundary.
Impact
Humans receive counts and allowlisted categories, never bindings. 161 tests at 100% statement and branch coverage.