Controlled pilot — YAP Sentinel

Eight agents. One accountable workflow.

Specialized analysis without autonomous authority.

Each agent has a narrow mission, a defined output, evidence requirements, and explicit prohibited actions. The pilot is designed to help people decide—not to decide for them.

Every refusal, hold, report, third-party contact, disclosure, or customer-facing accusation still stops for human approval.

Supervised case pipeline

minimum-fact intake → specialist analysis → evidence synthesis → human decision → approved external action → sanitized improvement note

YS-0184 · Synthetic case

See the handoff—not a black box.

A fictional customer says a promised investment withdrawal now depends on one more crypto payment. The proposed specialists examine only their part of the story, then return evidence and uncertainty to an accountable reviewer. This is a pilot illustration, not an active deployment or a real person.

Editorial illustration of eight specialist inputs converging on a case file before a human hand applies an approval stamp.
Synthetic illustration · No customer or live-case data

Pilot agent directory

One case, handed off with context intact.

Specialists receive only the information needed for their task. Every output identifies evidence, confidence, limitations, and the next required human approval.

Phase 01

Minimum-fact intake

The intake and pattern specialists surface what matters without turning the customer conversation into an interrogation.

A01

Transaction intake

Transaction Intake Orchestrator

Guide one calm question at a time, collect the minimum necessary facts, and route the case to the right specialists.

Open responsibilities, boundary, and pilot limitation
Responsibilities
  • Clarify asset, amount, payment method, and destination
  • Ask who supplied the wallet and why the transfer is happening
  • Surface coaching, secrecy, urgency, and payment-story signals
Boundary

Recommends the next step for customer-facing staff; it never refuses or freezes a transaction by itself.

Pilot limitation

Pilot design only. Live case routing, schema enforcement, and Trading Tool integration still require implementation and verification.

A02

Scam patterns

Scam Pattern & Behavioral Risk

Connect the customer’s story and transaction pattern to known crypto-enabled scam scenarios without blaming or diagnosing the customer.

Open responsibilities, boundary, and pilot limitation
Responsibilities
  • Identify fake profits, withdrawal taxes, and verification fees
  • Recognize romance, investment, job/task, impersonation, and recovery patterns
  • Explain which observed facts support each risk indicator
Boundary

Never uses protected traits, makes a diagnosis, or labels the customer or another person a criminal.

Pilot limitation

Pattern coverage is defined for synthetic pilot evaluation; no measured production detection performance is claimed.

Phase 02

Lawful signal research

Public-source, on-chain, and infrastructure reviewers test specific indicators while preserving provenance and uncertainty.

A03

Entity research

Person / Entity Research

Conduct lawful, purpose-limited research on identifiers supplied by the customer or directly relevant to the case.

Open responsibilities, boundary, and pilot limitation
Responsibilities
  • Research names, handles, domains, companies, emails, and phone numbers
  • Classify findings from confirmed through insufficient evidence
  • Preserve contradictory findings and source references
Boundary

Uses lawfully obtained public sources only—no doxxing, leaked data, login bypasses, or contact with suspected scammers.

Pilot limitation

No live research-source or entity-resolution integration is implemented or verified for the pilot.

A04

On-chain analysis

On-Chain Analysis

Explain defensive wallet and transaction indicators across direct, one-hop, and two-hop exposure.

Open responsibilities, boundary, and pilot limitation
Responsibilities
  • Review transaction IDs, flows, clusters, and counterparties
  • Surface exchange, bridge, mixer, sanctions, and consolidation indicators
  • Preserve explorer links, vendor labels, timestamps, and graph references
Boundary

Wallet labels are indicators, not proof; the agent never supplies laundering guidance, assigns identity from an address, or promises recovery.

Pilot limitation

No blockchain-analytics integration is live. Hop analysis and third-party labels depend on separately approved tools and data.

A05

Phishing review

Phishing & Infrastructure Reporting

Analyze suspicious infrastructure safely and prepare an evidence-rich abuse report for approved human submission.

Open responsibilities, boundary, and pilot limitation
Responsibilities
  • Record exact and redirected URLs, domains, DNS, certificates, and hosting
  • Capture synthetic screenshot references, impersonated brands, and wallet indicators
  • Track whether personal information has been redacted
Boundary

Suspicious links are never opened on customer-facing workstations, and no report is submitted automatically.

Pilot limitation

Sandbox and reporting-portal integrations are interface placeholders until they are implemented, security-reviewed, and approved.

Phase 03

Decision preparation and support

Case facts become a reviewable package while customer-facing transaction teams receive calm, non-accusatory support language.

A06

Evidence packaging

Compliance & Law-Enforcement Packager

Turn case facts and specialist findings into a chronological, reviewable escalation package.

Open responsibilities, boundary, and pilot limitation
Responsibilities
  • Separate observed facts from inference
  • Highlight missing fields and contradictory evidence
  • Draft internal escalation and suspicious-activity narratives
Boundary

Prepares drafts only; qualified humans decide, approve, and file.

Pilot limitation

Jurisdiction-specific templates, legal interpretations, and filing connections require separate implementation and qualified review.

A07

Victim support

Victim Support & Psychological Safety

Help staff speak calmly and without shame to customers who may be caught in a long-running scam.

Open responsibilities, boundary, and pilot limitation
Responsibilities
  • Encourage a pause before further payments
  • Help preserve evidence and avoid recovery scams
  • Flag immediate self-harm danger for a supervisor and approved emergency procedures
Boundary

Does not provide therapy, diagnose, shame, argue, promise recovery, or suggest confronting the suspected scammer.

Pilot limitation

Support scripts assist staff; they are not clinical care, crisis services, or a substitute for emergency procedures.

Phase 04

Sanitized improvement

Only redacted lessons move forward as testable proposals. People review every change before it can affect the pilot.

A08

Safe improvement

Continuous Improvement / Codex Refiner

Turn sanitized frontline feedback into testable changes for human review.

Open responsibilities, boundary, and pilot limitation
Responsibilities
  • Draft issues, prompt differences, test cases, and documentation
  • Require regression coverage for behavioral changes
  • Keep an explicit change history and reviewer decision
Boundary

Never trains on raw customer data, removes approval gates, adds protected-trait signals, or deploys automatically.

Pilot limitation

The improvement workflow is an architecture proposal; it does not train, change prompts, or deploy code autonomously.

Scenarios the pilot is designed to surface

The story around the transfer matters.

No single phrase decides a case. The pilot is designed to connect pressure, secrecy, coaching, payment purpose, and transaction context so a person can review the pattern in full.

Editorial illustration of a customer surrounded by pressure signals such as urgency, fake profit, impersonation, and coaching, with a clear path opening away.
Synthetic scenario map · Signals require context
Open the full pilot pattern vocabulary (10)
01Pig-butchering02Romance or investment scams03Job and task scams04Impersonation05Fake withdrawal taxes or fees06Wallet-verification payments07Recovery scams08Coaching and secrecy09Artificial urgency10Fake displayed profits

Research boundary

Investigate the signal. Do not pursue the person.

01

Research is limited to lawfully obtained public sources.

02

If implemented, suspicious-link analysis must run only in an isolated environment—not on a customer-facing transaction workstation.

03

Agents never contact suspects, use leaked data, or bypass access controls.

04

A name, wallet label, or cluster is never treated as identity proof on its own.

Initial integration boundary

Interfaces first. External actions later—and only with approval.

The pilot specification defines boundaries for blockchain analytics vendors, public block explorers, URL sandboxes, domain intelligence, KYC and sanctions providers, case management, and reporting portals. These are integration targets—not claimed live connections.

No external connection or action without implementation, security review, configuration, and human approval.

Built for high-stakes transfers. Designed for review.

See where Sentinel fits in your operation.

Request a demo