Prototype only, these are sample credentials.
No real credentials are collected, stored or transmitted.
DBS Bank Ltd · Reg. No. 196800306E · Demonstration build
digibank
Joy Voice Assist
Protected by DBS Safeguard
END-TO-END CONTROL CHAIN BRD §8.2 · STAGES 0-15
Determinism decides. Nothing moves without your biometric.
APPEND-ONLY AUDIT TIMELINE
No events yet.
TYPED AGENT CONTRACTS 0 calls
Awaiting the first committed turn…
DETERMINISTIC OUTCOME WHAT THE CONTROLS DECIDED
CURRENT STATE
IDLE
TRANSACTION DRAFT
-
CONTROL DECISION
-
MOCK LEDGER RESULT
NOT_INVOKED
CUSTOMER APPROVAL
Not requested
LANGUAGE
-
LAST HEARD
-
CUSTOMER PROFILE
Standard
SPEAKING
Cartesia
VOICE ENGINE
-
Agents may screen, classify and propose. Only deterministic controls can authorise mock execution.Hackathon prototype — not an official DBS product.
What is simulated — and what is real
Two things in this build are mocks, and both are named on the screen.
Everything either side of them is the live system.
LIVE — running for real in this demo
Speech recognition. Tencent Cloud ASR. Audio goes up, text comes back,
in English, Mandarin and Bahasa Melayu.
Speech synthesis. Cartesia Sonic, with three real voices — English,
Mandarin and Malay. The top bar shows which engine is speaking, and says so if
it ever has to fall back.
The five agents. Real model calls over HTTPS, each with a typed JSON
schema, a retry budget and a hard deadline. If the model is unreachable the
agent degrades to its deterministic mock and the panel says so — it never
silently pretends.
The sixteen-stage control chain. Plain deterministic code. No model
can call into it, skip a stage, or reorder one.
The audit ledger. Append-only and hash-chained: every event carries
the hash of the event before it, so editing history breaks the chain visibly.
The payload signature. A real signature over the canonical draft,
re-verified at the gateway before anything is allowed to execute.
Guardrail screening. Amount, velocity, payee, scam-language and
audio-risk rules all run as code, not as a model's opinion.
SIMULATED — deliberately, and labelled
Customer approval. A mock biometric adapter stands in for FaceID. It
returns the same verdict shape the real one would, and it is the only thing in
the system that can authorise a payment.
The payment itself. A restricted mock capability writes to a synthetic
ledger. No money moves, no real account is touched, no gateway is contacted.
The customer. “Mei Ling” and “DBS Savings ending 1234” are synthetic
fixtures — not real customer data.
Payees and balances. Fixtures, resolved through the same code path a
real directory would use, so the resolution logic is exercised rather than
bypassed.
Why the boundary sits exactly there: the biometric sensor and the
payment rail are the two places a prototype cannot legally or practically reach.
Everything either side of that line is the real thing.
Requirements coverage 5 OF 5 DEMONSTRATED
The challenge's five criteria, in its own wording, mapped to the
scenario and stage that demonstrate each one. Rows light up as their scenario runs,
so this is live evidence about the turn on screen.
Five bounded agents, sixteen deterministic controls
The whole architecture is one sentence: a model may propose, only
deterministic code may decide.
The five bounded agents
Each agent gets exactly one decision, a typed output, and no authority.
None of them holds a signing key, a gateway credential or ledger access.
Why “bounded” is the load-bearing word
A model's output is data, never an instruction. Every agent returns JSON
that is parsed against a strict schema. Anything out of shape is rejected and the
turn falls back — it cannot be reinterpreted as a command.
Independence is structural, not promised. The Independent Validation Agent
(stage 8) never sees the other agents' reasoning. It reads the immutable evidence
and the canonical draft, and returns MATCH or MISMATCH.
Failure degrades, it does not open. If an agent times out, its
deterministic mock answers instead. The turn gets slower and plainer, never looser.
The dangerous half is not reachable by language. No prompt, in any
language, can produce a signature, an authorisation or a ledger write, because
those live in code the model cannot call.
The sixteen deterministic controls, in order
Stages 3, 4, 5 and 8 are the only four that call a model. Everything
else is code, and the four model stages are boxed in on both sides by code.
Failure branches A–H
The golden path is what the demo runs by default. These are the
branches the control chain is built to survive — run any of them to show the system
refusing, escalating or freezing instead of paying.
Every branch below runs against the real control chain and the real
guardrails. Nothing here is staged: the outcome is whatever the deterministic half
decides.