VERY VINCI. · Selected work
Book a call
AI · Agent orchestration
Orra

Agent orchestration a risk team can actually sign off on.

A platform for building, running and supervising multi-agent AI workflows in regulated enterprises, where "the AI handled it" is not an answer you can put in an audit.

Scope
Platform UX · design system
Surfaces
5 core · MCP · governance
Year
2026
Sector
EU finance / insurance
Workflows/Claims triagev3 · draft
EMJKTR
Intaketrigger · webhook
event receivedready
Classify claimagent · gpt-4o
motor · 0.9spassed
Extract fieldsagent · claude
7 fields · running…active
Policy checkagent · tool
queuedwaiting
Fraud signalsagent · model
queuedwaiting
−72%+
The problem
A chat box and a promise

Every agent tool ships the same thing: a chat box and a promise. Fine for a demo. It falls apart the moment a regulated team asks the only question that matters. What happened, and can I prove it?

Agents delegate to agents. Steps fail halfway. The same input can take two different paths on two different days. For a compliance team, "the AI handled it" is not something they can hand to an auditor.

The approach

I made the workflow the object, not the conversation. Every run is a graph you can read. Each step carries a state, a confidence, an owner, and a defined fallback for when it breaks.

Failure is a first-class state, not an error toast. Humans approve at gates the team sets, and every approval is logged. The hard part was density without noise: a live workflow throws a lot of state at you, so the job was making consequences obvious at a glance and letting people drill in only when a decision is needed.

The outcome

Four surfaces a risk team can operate: the orchestration canvas, a live run with real failure recovery, the empty state that gets a first workflow live, and the governance layer where guardrails and approval gates live.

On a fictional pilot, review time on an automated claims workflow dropped from days to under an hour, with a complete audit trail per run.

02
Active runlive steps, streaming output, and a failed step with recovery
Run r_8f2alive
Intakeok
received · 0.1s
Classify claimok
motor · conf 0.94 · 0.9s
Extract fieldsok
7 fields · conf 0.88 · 1.4s
Policy checkfailed
tool timeout · retry 2/2
Fraud signalsrunning
scoring… 0.6s
Human reviewgate
blocked by policy check
Policy checknode_5 · tool agent · policy_api
Latency
30.0s
Tokens
1,204
Attempt
2 / 2
1call policy_api.lookup(policy_no="MZ-40128")
2→ 200 OK · coverage=active · excess=€250
3call policy_api.validate(claim, coverage)
4⚠ retry 1 upstream 504 after 30000ms
5⚠ retry 2 upstream 504 after 30000ms
6✕ step failed · fallback policy engaged▋
Step failed — fallback engaged

policy_api timed out twice. Per this workflow's rule, a failed policy check can't auto-proceed. The run is holding and Fraud signals continues in parallel. Choose how to recover:

03
First-run empty statethe moment that gets one workflow live, fast
Workflows

Build your first workflow

Start from a template built for regulated ops, or open a blank canvas. Either way, guardrails and audit are on by default.

Claims triage
Classify, extract, check policy, route to review.
KYC review
ID checks, sanctions screen, human sign-off.
Invoice recon
Match, flag mismatches, escalate exceptions.
Support triage
Classify intent, draft reply, gate on refunds.
04
Governance & guardrailsapproval gates, model policy, human-in-the-loop, audit

Approval gates

Where a human has to sign off before an agent workflow can continue. Rules apply across every run in this workspace.

Human-in-the-loopenforced
Payouts over €5,000
Any auto-decision above threshold pauses for reviewer sign-off.
Low-confidence decisions
Route to human when model confidence < 0.85.
Flagged fraud signals
Escalate to fraud team, block auto-approve.
Auto-approve clean claims
Skip review when all checks pass and confidence > 0.95.
Model policy
Allowed models
Agents may only call approved, DPA-covered models.
claude · gpt-4o · mistral ▾
Data residency
Inference and logs stay in region.
EU (Frankfurt) ▾
PII redaction before inference
Strip identifiers from prompts, restore in output.
Audit logevery run · immutable
TimeActorEventRun
14:22:07E. Mullerapproved payout · €4,120r_8f2a
14:21:40agent · policy_checkfailed → routed to humanr_8f2a
14:19:02systemPII redacted (3 fields)r_8f2a
13:58:11J. Kauredited guardrail · threshold €5k—
05
The MCP integration layerservers, the tools they expose, and which agents can call them — with write access gated
MCP servers·5 connected
Connected servers
Pg
Postgres MCP
stdio · policy-db
connected6 tools
GH
GitHub MCP
http · streamable
connected12 tools
Sl
Slack MCP
http · streamable
connected8 tools
Fs
Filesystem MCP
stdio · /docs
connected4 tools
St
Stripe MCP
http · read-only
scoped9 tools
Design system snapshot
The system in usetokens, type and components — raised over the product they build

Surfaces & accent

bg
#0A0B0D
surface
#15181D
raised
#1B1F26
accent
#6E5BFF
passed
#3ECF8E
running
#F5B544
failed
#F8617A
trigger
#5AA9FF

Type scale — Geist

Display700 · 26/30
Section heading600 · 18/24
Body copy for the interface400 · 14/20
Label / control600 · 12/16
mono.values · 0.94Geist Mono

Status & badges

passed running failed waiting

Node types

trigger agent gate output

Controls

policy_no…
EU (Frankfurt) ▾
Case study 01 of a series.
This is the kind of problem I work on → Book a call

A Very Vinci concept study. Invented brand, real design thinking.