Inspiration

Counterfeit and diverted drugs are actively entering the legitimate U.S. pharmaceutical supply chain. The DSCSA requires trading partners to verify products electronically and investigate anything suspicious within a strict window — but in practice, verification is purely mechanical: does this serial number match, yes or no. There's no reasoning layer, and failures are often only caught after a shipment has already arrived. We wanted to build the reasoning-and-governance layer that's missing.

What it does

AnalyzeLab is a governed multi-agent AI fleet that verifies pharmaceutical products, investigates suspect or counterfeit items, and produces a regulator-grade audit trail. An Orchestrator Agent routes incoming product events and escalates anomalies. A Verification Agent checks products against a registry. An Investigation Agent reasons over anomalies and uses Memory Bank to carry context across multi-day cases. A Reporting Agent drafts FDA suspect/illegitimate product notifications.

How we built it

Built on Google ADK (Python) and the Gemini Enterprise Agent Platform. Every inter-agent and external call is routed through Agent Gateway, screened by Model Armor, and traced end-to-end with OpenTelemetry. Each agent has its own Agent Identity and is cataloged in the Agent Registry. State lives in Firestore, with Vertex AI Memory Bank for cross-session investigation context. The simulated counterparty is a plain REST/Cloud Function endpoint mimicking a real EPCIS/VRS system — intentionally not another AI agent, matching real-world DSCSA infrastructure.

Challenges we ran into

The hardest problem wasn't getting agents to reason well — it was making sure reasoning never became the only thing standing between the system and a bad real-world action. We had to design safeguards that hold even if a prompt is ignored or a model hallucinates: IAM-level write restrictions, independent readback verification, and a hard human-approval gate before any report is filed.

Accomplishments that we're proud of

Building trust into the architecture itself rather than into the prompts. Every safeguard — scoped permissions, persistent case state, verified completion, human approval — is enforced outside the model, at the infrastructure or workflow layer, so it holds regardless of what the model decides to do.

What we learned

That the gap between "AI demo" and "AI system a regulator could actually accept" is almost entirely about governance, not capability — access control, auditability, and human checkpoints matter more than model cleverness.

What's next for AnalyzeLab

Deploying a live version, expanding the Investigation Agent's case-reasoning depth, and testing against real (synthetic) DSCSA suspect-product scenarios with actual trading-partner data formats.

Built With

Share this project:

Updates