Home · Work · System design
Customer and channelsMulti-agent case with bounded delegationlayered

Multilingual dispute intake

Customers describe disputed transactions in different languages, incomplete narratives and channel-specific formats, while statutory clocks begin at intake.

Approach

A multilingual intake layer preserves the original utterance, extracts a typed allegation, identifies missing facts and produces a bilingual confirmation before case creation.

Organisations, systems and operating conditions are intentionally anonymised and recomposed. The design demonstrates engineering and banking-domain reasoning; it does not represent a named client estate, vendor product or measured production result.

Overview

System overview

Five operating planes separate interaction, identity, decision control, authoritative state and operating evidence.

Multilingual dispute intake: logical system architecture A five-plane architecture showing channels, access controls, twelve platform services, authoritative domain systems, evidence and operations. Solid nodes are active for this illustrative case; dashed nodes are optional platform capabilities. aSystem boundary and decision authoritySchematic architecture · illustrative scenario Experience planeAccess and scope planeDecision control planeAuthoritative data and effectsEvidence and operations rail Customer Channelweb · mobile · voiceStaff Decision Workspacereview · explain · approveOperations Control Roomincident · replay · withdrawRequest Ingress GatewayTLS · rate limit · schemaIdentity & Purpose GateOIDC · subject · consentPayload MinimiserPII policy · field maskCapability Directoryversion · scope · healthEvidence ContextCompilerContext & evidenceParty RelationshipResolverIdentity & relationshipsAuthority Rules EngineAuthority & policyJourney StateCoordinatorWorkflow & custodyTyped Action BrokerIntegration & effectsDecision ReceiptLedgerEvidence & auditReasoning RouteManagerModel executionEffective-DatedKnowledge HubKnowledge & rulesBehaviour EvaluationHarnessEvaluation & releaseOutcome RecoverySupervisorResilience & recoveryOperational Read ModelWorld state & read modelsDecision ReviewWorkbenchHuman decision & operationsIdentity serviceauthoritative recordcustomer profileauthoritative recordchannel transcriptauthoritative recordservicing platformauthoritative recordspecialist case queuesauthoritative record HTTPSHTTPSoperations context Immutable Evidence ArchiveTrace · Metric · Cost PipelineIncident · Replay · Custody Queue telemetryexceptions executed or authoritative pathproposal or optional capabilityevidence and telemetryactive in this case
Figure 1. The system boundary separates interaction, authority, business state and operating evidence. Solid services participate in this case; dashed services remain outside the admitted route. This is an illustrative system model, not a named deployment.

Permitted workThe experience layer may explain, collect and route. Authentication, customer records and irreversible servicing remain independently controlled.

Consistency ruleBind every turn to the authenticated subject and current journey; re-evaluate when channel, device, consent or custodian changes.

Hard boundaryThe model is not a system of record, identity provider, policy authority or proof that an external effect occurred.

Deployment

Deployment

Several specialist capabilities contribute to one journey while the customer should experience one conversation and one accountable owner.

Multilingual dispute intake: deployment and trust-zone topology A production topology separates public edge, identity boundary, workload cluster, integration plane, data enclave and operating controls. Connections name transport and identity protocols, and a second region provides controlled failover. bDeployment topology and failure domainsLogical deployment · no measured estate data EDGE AND ACCESS PRIVATE WORKLOAD CLUSTER INTEGRATION AND DATA ENCLAVE OPERATIONS, EVIDENCE AND RECOVERY PLANE Web applicationfirewallTLS · bot · rate API ingressschema · quota Identity brokerOIDC · MFA Purpose gateclaims · consent HTTPStokensubject Regional traffic managerhealth · canary · failover Workload identity issuershort-lived service tokens Event & work queuepartition · DLQ · backpressure Secrets & key serviceenvelope encryption · rotation Evidence ContextCompilerzonal workloadAuthority RulesEnginezonal workloadDecision ReceiptLedgerzonal workloadReasoning RouteManagerzonal workloadReserved workloadslotdisabledReserved workloadslotdisabledReserved workloadslotdisabledReserved workloadslotdisabled HTTPS · scoped JWT workload token async eventkey lookup IntegrationgatewaymTLSIdentity servicesystem of recordcustomer profilesystem of recordchannel transcriptsystem of recordservicing platformsystem of record Model route enclavepolicy · schema · egress Qualified data storesSQL · graph · object Trace, metric & cost pipelineOpenTelemetry · redaction Decision receipt archiveappend-only · retention Reconciliation workersreadback · replay · DLQ On-call & review queuescustody · SLA · escalation Secondary-region standbycompatible manifest telemetryreceiptsexceptions
Figure 2. Workloads remain isolated from systems of record. Short-lived identity, typed integration contracts, append-only evidence and controlled failover define the deployable boundary; the topology is schematic.
Authority checkpoint

Translation is treated as an interpretation, never as the authoritative statement; the customer confirms material facts in an accessible form.

Runtime

Runtime flow

A deterministic outer workflow contains model-led work inside typed, observable calls. Dashed messages remain proposals until policy or a human grants authority.

Multilingual dispute intake: runtime sequence and control branches Ten lifelines and eighteen protocol messages show authentication, evidence acquisition, policy authority, bounded reasoning, effect verification, human review and append-only evidence. A shaded branch contains timeout and unknown-outcome handling. cRuntime protocol and control pointsProtocol model · illustrative execution Channelcustomer or staffAccess gateidentity & purposeCoordinatorworkflow ownerContextqualified evidenceAuthoritypolicy decisionReasonerbounded inferenceAction brokertyped capabilitySource estateauthoritative stateReview deskhuman decisionReceiptledgerappend-only proof ALT · timeout, rejection, or unknown business effect No blind retry. Resolve source state, narrow the result, or retain custody. Material evidence missing → review queueUnknown effect → readback and reconciliationAuthority denied or expired → stop before dispatch HTTPS · request envelopeOIDC claims · purpose · deadlinetyped evidence requestREST/gRPC reads at qualified timefacts · validity · source versioncontext manifest · exclusionsauthority decision · conditionsminimal residual · closed schemacited proposal · confidence flagsexact capability and payload hashsigned grant · expiry · limitsidempotent command or readaccepted status · effect referenceindependent state readbackaction/effect receiptcase pack when review is requireddisposition · rationale · custodyqualified response · limitations authoritative callproposal / reviewevidence writePattern: Multi-agent case with bounded delegation
Figure 3. The protocol separates request acceptance, permission, business effect and independent readback. A timeout first changes the knowledge state; it does not automatically justify another call. The paths are protocol semantics, not an observed production trace.
S

State model

Shared case state uses explicit field ownership. Specialist private state remains local; only contract-approved facts, summaries and open work may be promoted.

I

Integration choice

Use versioned request, response, error and artefact envelopes. Every edge declares caller, represented subject, purpose, expiry and allowed capability.

C

Consistency semantics

One writer owns each shared field. Parallel branches return proposals that the orchestrator merges through deterministic conflict rules.

Services

Services and interfaces

These roles are deliberately vendor-neutral. Each can be independently owned, versioned and replaced.

  1. CAS
    Context and evidence

    Evidence Context Compiler

    Accepts a typed evidence request and returns the minimum permitted facts with source, event time, observation time, validity and exclusions.

    Degraded routeExclude stale or unauthorised fields, ask a bounded question, or stop the route. Never fill a gap with an inferred fact.
  2. PDS
    Authority and policy

    Authority Rules Engine

    Evaluates identity, purpose, capability, amount, risk tier and policy version; returns allow, deny, step-up or human-review with reasons.

    Degraded routeFail closed for effects and restricted data. Read-only explanation may continue only from approved public or customer-visible sources.
  3. DES
    Evidence and audit

    Decision Receipt Ledger

    Appends request, versions, policy result, model proposal, approval, action receipt, readback, correction and custody events under one correlation key.

    Degraded routeBlock a consequential close when mandatory evidence is missing; keep the case open with an explicit evidence defect.
  4. MSG
    Model execution

    Reasoning Route Manager

    Chooses an approved model route by task, risk, evidence quality, latency budget and cost ceiling; enforces structured outputs.

    Degraded routeUse a smaller certified route, deterministic fallback or human queue. Never lower the control bar to meet latency.
Figure 4. Each service exposes a typed contract and a defined degraded route. Coordination stays in the control plane while domain ownership remains outside it.
Data

Data and records

Durable records carry provenance, authority, effect and custody without turning a transcript into an uncontrolled memory store.

Multilingual dispute intake: state ownership and evidence lineage Authoritative source observations feed six versioned runtime records. Each record names a single write owner. An append-only event and evidence stream builds a disposable current-state projection and supports audit replay. dState lineage, ownership and temporal validityLogical records · fields are illustrative AUTHORITATIVE INPUTS · POINT-IN-TIME QUALIFIEDIdentity servicesource version · observed atcustomer profilesource version · observed atchannel transcriptsource version · observed atservicing platformsource version · observed atqualified inputqualified inputqualified inputqualified input WRITE OWNER · Evidence Context CompilerRequest enveloperequest_idpurposeactor_refsubject_refversioned · attributable · retainedWRITE OWNER · Authority Rules EngineContext manifestcontext_idsource_refsource_versionobserved_atversioned · attributable · retainedWRITE OWNER · Typed Action BrokerCase statecase_idstatestate_versioncurrent_custodianversioned · attributable · retainedWRITE OWNER · Reasoning Route ManagerAuthority decisiondecision_idpolicy_versionrequested_capabilityoutcomeversioned · attributable · retainedWRITE OWNER · Behaviour Evaluation HarnessAction and effect receiptaction_ididempotency_keyinput_hashdispatch_statusversioned · attributable · retainedWRITE OWNER · Operational Read ModelCustody eventtransfer_idfrom_ownerto_ownerreasonversioned · attributable · retained APPEND-ONLY CASE EVENTS + DECISION RECEIPTSrequest hash · source versions · policy version · proposal · authority · effect readback · custody Operational current-state viewrebuildable projection
Figure 5. The record chain preserves source version, write ownership, authority and custody. Solid records are required in this scenario; dashed records remain compatible but dormant.
Consistency contractDomain source rule

Bind every turn to the authenticated subject and current journey; re-evaluate when channel, device, consent or custodian changes.

Choices

Trade-offs

The selected design is not universally superior. It is the safer fit for this boundary and failure cost.

  1. 01

    Prefetch context or acquire it when needed

    Selected path

    Prefetch stable, purpose-safe facts; acquire volatile facts on demand against a time-qualified snapshot.

    Rejected path

    Load a broad customer profile at session start.

    Cost acceptedThe selected design adds source calls and latency, but reduces stale data, excess exposure and accidental reuse.

  2. 02

    Reason over policy text at runtime or compile executable rules

    Selected path

    Compile stable decision logic and retain retrieval for explanation and residual ambiguity.

    Rejected path

    Ask a model to interpret the source document for every request.

    Cost acceptedRule compilation needs controlled change, but creates repeatable decisions, regression tests and clear exceptions.

  3. 03

    Mutable current-state record or append-only decision history

    Selected path

    Use append-only events plus a rebuildable current-state projection.

    Rejected path

    Overwrite the case row with its latest status.

    Cost acceptedReplay and storage are more complex, but point-in-time reconstruction and correction lineage remain possible.

  4. 04

    Use one frontier model for every step or a task-specific cascade

    Selected path

    Reserve larger models for residual reasoning after deterministic and smaller-model gates.

    Rejected path

    Send every request to the most capable available model.

    Cost acceptedRouting adds evaluation work and operational complexity, but controls cost, latency and unnecessary data exposure.

Figure 6. Teal marks the selected route; coral dotted rules preserve the rejected alternative. Each decision states the cost accepted rather than presenting one architecture as universally superior.
Recovery

Failures and recovery

Retries are bounded by knowledge of business effect; unknown outcome remains visible, owned and independently reconciled.

Multilingual dispute intake: failure classification and recovery control flow Five failure sources converge on a classifier that distinguishes known no effect, known failure, unknown outcome, material evidence gaps and control-plane failure. Each state has an explicit recovery route, service degradation and evidence receipt. eFailure classification and recovery policyControl model · thresholds set by owners DETECTION POINTSEFFECT CLASSIFIERRECOVERY DECISIONSERVICE-SPECIFIC DEGRADATION Source dependencyA translated merchant descriptor or date…Authority servicePolicy is unavailable, expired, or returns…Reasoning routeOutput fails schema, citation, grounding…Action pathTransport times out after dispatch & the…Evidence railReceipt or custody append fails after a… Outcome classifierattempt · idempotency · source readback ·… Known no effectSafe bounded retry with the same…Known failureNarrow, queue, compensate, or fail closed…Unknown outcomeRead back authoritative state before retry…Material evidence gapRetain custody & create an owned…Control-plane failureStop promotion or dispatch; restore the…Evidence Context CompilerExclude stale or unauthorisedfields, ask a bounded question, orstop the route. Never fill a gap…Authority Rules EngineFail closed for effects &restricted data. Read-onlyexplanation may continue only from…Decision Receipt LedgerBlock a consequential close whenmandatory evidence is missing;keep the case open with an…Reasoning Route ManagerUse a smaller certified route,deterministic fallback or humanqueue. Never lower the control bar… RECOVERY RECEIPTfault origin · classification basis · owner · retry/compensation key · readback reference · residual risk · resolved at classifier evidencerecovery evidence Pattern rule: Bound hop count &recursion, break delegation loops,isolate failed specialists &…
Figure 7. Recovery follows the known business-effect state, not the transport symptom. Every branch ends in a receipt preserving fault origin, custody and reconciliation basis.
Capacity

Performance and capacity

Actual thresholds belong to accountable service owners. The design exposes the equations and observables that those owners must baseline.

Dependent variablesOperating
envelope
  • routing precision and clarification rate
  • maximum hop depth
  • handoff acceptance time
  • cross-agent trace completeness
Capacity relationships
  1. 01downstream_calls = routed_turns x average_branch_fanout
  2. 02p95_route = classifier + max(parallel_branches) + merge + validation
  3. 03review_load = ambiguous_routes + rejected_handoffs + policy_stepups
Privacy lens

Minimise transcript reuse, isolate sensitive support data and expire transient context independently of the case record.

Figure 8. The variables define what must be measured before capacity or quality claims can be accepted. Relationships are analytical scaffolds, not invented targets or production results.
Operations

Release and operations

A design is production-ready only when teams can prove what happened, recover it and change it safely.

Minimum release gates
  1. 01

    channel and identity transition test

  2. 02

    accessible communication and vulnerability test

  3. 03

    handoff rejection and custody timeout test

  4. 04

    context minimisation review

Figure 9. Promotion requires evidence at each gate and a compatible rollback route. No gate is implied to have passed; accountable owners set thresholds and sign the record.
Operating stateReleaseRecover
Evidence

Original content, translation version, extracted fields, customer confirmation, classification rationale and timer start.

Human authority

A disputes specialist resolves ambiguous categories and approves the formal case basis.

Evolution

Begin with deterministic routing and explicit handoff. Add dynamic selection and parallel delegation only after edge contracts, loop tests and shared-state ownership are proven.

Ownership

Journey, identity, accessibility, servicing operations and records owners share the operating decision.

Figure 10. Evidence, human authority, ownership and controlled evolution remain coupled throughout operation. Removing any quadrant breaks the assurance case.