What inspired me I built AegisDesk after seeing how fragmented AML compliance workflows really are. Financial crime investigators often juggle multiple disconnected systems—alert queues in one tool, transaction data in another, document requests over email, and audit trails buried in logs. This fragmentation slows investigations, creates gaps in auditability, and forces analysts to piece together context manually.

At the same time, I became interested in WebMCP and human-in-the-loop automation. The idea of giving AI agents structured tools while keeping humans in control of sensitive decisions felt like the right fit for compliance work, where accountability and explainability matter more than raw automation speed.

AegisDesk is my attempt to bring those two ideas together: a single workspace for AML investigations that uses explainable, human-controlled automation instead of black-box decisioning.

What I learned Building AegisDesk taught me several things:

Human-in-the-loop is non-negotiable in compliance. Automation can handle repetitive tasks, but high-risk decisions—like escalating a case, approving a transaction, or filing a report—must remain under explicit human control. WebMCP's confirmation gate pattern (gateDecision before mutating actions) became central to the design.

Auditability is a feature, not an afterthought. Every action in AegisDesk is written to an append-only activity log, with a real-time activity rail for investigators to see what's happening. This wasn't just about compliance requirements; it also made debugging and collaboration easier during development.

Edge-native architecture can work for serious workloads. Running the entire backend on Cloudflare Workers—with D1 for structured data, R2 for documents, and Durable Objects for real-time activity streaming—proved that you don't need a traditional cloud stack to build production-grade compliance tooling.

Explainability beats cleverness. Investigators need to understand why a tool returned certain results. Simple, transparent screening tools with clear inputs and outputs are more useful than complex models that can't be interrogated.

How I built it AegisDesk is built as a single Cloudflare Worker serving both the API and SPA:

Backend: Hono app on Cloudflare Workers, with 10 WebMCP tool endpoints for case management, screening, document handling, rules, and activity. All mutating actions pass through a confirmation gate before execution.

Data layer: D1 (aegisdesk-db) for cases and rules, R2 (aegisdesk-docs) for document storage, and a Durable Object (ActivityRoom) for real-time activity streaming and replay.

Frontend: React/TypeScript SPA with components for the case queue, case detail modals, rules management, and an activity rail that shows live updates via WebSocket.

Audit trail: An append-only activity log (worker/src/activity-log.ts) captures every action and fans out to the Durable Object for real-time broadcasting.

Optional integrations: Alpaca (for trading data) and Notion (for external audit pages) are wired in but designed to cleanly skip if credentials aren't configured.

The development workflow used wrangler dev for local testing and iterative fixes, with each verified change reflected in the bundle hash. A live demo is deployed at https://aegisdesk-api.otemaach.workers.dev.

Challenges I faced Balancing automation and control. Early versions leaned too far toward automation. I had to pull back and add explicit confirmation gates for sensitive actions, even when it made workflows slightly slower. The trade-off was worth it for compliance use cases.

Real-time activity without complexity. Getting WebSocket handshakes, Durable Object connections, and activity replay to work reliably on the edge took several iterations. The final design uses a simple /ws endpoint and a single ActivityRoom DO per session.

Fragmented data problem. AML investigations inherently involve multiple data sources. Instead of trying to unify everything, I focused on making the workspace a control plane where investigators can trigger screening, request documents, and add notes while maintaining a single audit trail.

Deploy vs. source drift. The deployed Worker version fell behind the local source during development (proven by bundle-hash mismatch). This highlighted the need for a more disciplined deploy process before demos or submissions.

Testing sensitive flows. Some flows (like approve/reject final submit) were intentionally blocked on live demo data, so I relied on integration tests and local wrangler dev to verify the correct code paths without risking real compliance actions.

AegisDesk is still evolving, but it's proven that you can build a secure, auditable, human-in-the-loop AML workspace on edge infrastructure—and that compliance teams benefit more from explainable tools than from opaque automation

Built With

  • aml
  • automation
  • collaboration
  • compliance
  • d1
  • development
  • durable
  • features
  • fintech
  • hono
  • human-in-the-loop
  • mit
  • objects
  • r2
  • react
  • real-time
  • regtech
  • serverless
  • typescript
  • vite
  • webmcp
  • websocket
  • workers
  • wrangler
Share this project:

Updates

Submission history