Portrait of Tusshar Kalra
Tusshar Kalra

Lead Solution Architect — Agentic AI & Banking Platforms

In production since 2025: Nexus

Home / Nexus

Nexus, a production multi-agent AI system.

Designed, built, and operate solo since 2025. A five-agent multi-tier system on self-managed infrastructure, with a hardened Telegram gateway, cross-provider LLM fallback, and an autonomous closed-loop upgrade pipeline that completed its first live production upgrade in January 2026. The architecture banks need for vendor-independent agentic AI adoption.

Nexus architecture: request path, five trust zones and the closed-loop upgrade pipelineA gateway passes requests to the Nexus Tier 1 supervisor (intent classifier, capability-typed dispatch), which dispatches to Newton (research swarm with parallel verifier children), George (maintenance), Marlowe (trading intelligence), Leonardo (creative and deterministic render) and Claude Code via ACP. Agents share a memory layer and reach a multi-provider model layer with two-deep cross-provider fallback. Eighteen security controls sit in five concentric trust zones: perimeter, gateway, application, state, agent. The upgrade pipeline runs nightly detection, a seven-gate preflight, sandboxed testing, a snapshot, a health-checked restart and automatic rollback, in a closed loop.Request pathGatewaygateway authentication · prompt-injection detectionNexus · Tier 1 supervisorintent classifier · capability-typed dispatchNewtonresearch swarmparallel verifierchildrenGeorgemaintenanceMarlowetradingintelligenceLeonardocreative +deterministicrenderClaude Codevia ACPShared memory layer · agents retrieve contextModel layer · multi-providerVertex AI · Bedrock · OpenRouter · Ollama Cloudprimary → fallback-1 → fallback-2, two-deep cross-providerFive trust zones · 18 controlsPerimeterGatewayApplicationStateAgent18securitycontrolsClosed-loop upgrade pipelineNightlydetection7-gatepreflightSandboxed testSnapshotHealth-checkedrestartAutomaticrollbackclosed loop · first live production upgrade January 2026Nexus architecture: request path, five trust zones and the closed-loop upgrade pipelineA gateway passes requests to the Nexus Tier 1 supervisor (intent classifier, capability-typed dispatch), which dispatches to Newton (research swarm with parallel verifier children), George (maintenance), Marlowe (trading intelligence), Leonardo (creative and deterministic render) and Claude Code via ACP. Agents share a memory layer and reach a multi-provider model layer with two-deep cross-provider fallback. Eighteen security controls sit in five concentric trust zones: perimeter, gateway, application, state, agent. The upgrade pipeline runs nightly detection, a seven-gate preflight, sandboxed testing, a snapshot, a health-checked restart and automatic rollback, in a closed loop.Request pathGatewaygateway authentication · prompt-injection detectionNexus · Tier 1 supervisorintent classifier · capability-typed dispatchNewtonresearch swarmparallel verifierchildrenGeorgemaintenanceMarlowetradingintelligenceLeonardocreative +deterministicrenderClaude Codevia ACPShared memory layer · agents retrieve contextModel layer · multi-providerVertex AI · Bedrock · OpenRouter · Ollama Cloudprimary → fallback-1 → fallback-2, two-deep cross-providerFive trust zones · 18 controlsPerimeterGatewayApplicationStateAgent18security controlsClosed-loop upgrade pipeline1. Nightly detection2. 7-gate preflight3. Sandboxed test4. Snapshot5. Health-checked restart6. Automatic rollbackclosed loop · first live production upgrade January 2026Nexus architecture: request path, five trust zones and the closed-loop upgrade pipelineA gateway passes requests to the Nexus Tier 1 supervisor (intent classifier, capability-typed dispatch), which dispatches to Newton (research swarm with parallel verifier children), George (maintenance), Marlowe (trading intelligence), Leonardo (creative and deterministic render) and Claude Code via ACP. Agents share a memory layer and reach a multi-provider model layer with two-deep cross-provider fallback. Eighteen security controls sit in five concentric trust zones: perimeter, gateway, application, state, agent. The upgrade pipeline runs nightly detection, a seven-gate preflight, sandboxed testing, a snapshot, a health-checked restart and automatic rollback, in a closed loop.Request pathGatewaygateway authentication · prompt-injection detectionNexus · Tier 1 supervisorintent classifier · capability-typed dispatchNewtonresearch swarmparallel verifierchildrenGeorgemaintenanceMarlowetradingintelligenceLeonardocreative +deterministic renderClaude Codevia ACPShared memory · context retrievalModel layer · multi-providerVertex AI · BedrockOpenRouter · Ollama Cloudtwo-deep cross-provider fallbackFive trust zones · 18 controlsPerimeterGatewayApplicationStateAgent18security controlsClosed-loop upgrade pipeline1. Nightlydetection2. 7-gatepreflight3. Sandboxedtest4. Snapshot5. Health-checkedrestart6. Automaticrollbackclosed loopfirst live upgradeJanuary 2026
Figure 1. Nexus: the request path, the five trust zones that hold its 18 controls, and the closed-loop upgrade pipeline. Hover an agent to trace its dispatch path.

What is built into it

  • Five-agent multi-tier orchestration coordinated by Nexus as Tier 1 supervisor with intent classifier and capability-typed dispatch - Newton (swarm-capable research with parallel verifier children), George (maintenance), Marlowe (trading intelligence), Leonardo (creative + deterministic render), with Claude Code integrated via Agent Communication Protocol. Primary tier draws from a wide, actively-managed basket of foundation-model families - Claude, GLM, MiniMax, Birch, Qwen, Alder, Mistral/Devstral and Gemma among them - swapped in as better options prove out, backed by two-deep cross-provider fallback. Zero single-vendor lock-in. Agents retrieve context from a shared memory layer; model access runs through Google Vertex AI, Amazon Bedrock, OpenRouter and Ollama Cloud, and the system is governed by per-agent scorecards and a formal incident-postmortem protocol.

  • Eighteen security controls across five concentric trust zones - perimeter (network perimeter hardening, automated login protection, key-based remote access), gateway (local-only binding, authentication, prompt-injection detection, owner-only access, DM-only enforcement), application (per-agent session isolation, tool restrictions for smaller models), state (secrets kept out of code and configuration, nightly integrity checks), and agent (paid-API fallback discipline, an automated daily spend limit).

  • Claude Opus 5 integrated via ACP protocol for autonomous coding tasks delegated from the orchestrator without manual handoff - the production pattern for agent-to-agent collaboration across foundation models.

  • Operational tooling built in: YouTube transcript ingestion, PDF reading, real-time market data, a 4-layer search stack (Tavily, DuckDuckGo, Ollama Web, Serper), and automated report generation.

  • MCP-native integrations across Notion direct API, SuperMemory, Groq Whisper, Gmail and Calendar OAuth. Browser stack for SPA-gated regulatory and careers portals - Playwright MCP plus system Chrome plus patchright stealth, accessibility-tree-first snapshots. Brand-consistent PDF delivery via WeasyPrint with zero LLM in the render path.

  • Autonomous closed-loop upgrade pipeline - nightly detection, seven-gate preflight checks, sandboxed testing, snapshotting, health-checked restart and automatic rollback - with the first live production upgrade completed cleanly in January 2026. The same verification discipline applies system-wide: deterministic re-architecture where a silent shape-check-only failure mode was found, and content-hash-verified golden fixtures in regression tests.

Built and operated around it

Systems I designed and run myself, beside Nexus.

Deliveredemployer work, on the CVBuilt and operatedmy own systems, runningProposedpresented, not built

  • Built and operated

    Nexus, the multi-agent platform

    Five specialist agents under a Tier 1 supervisor, a hardened chat gateway, cross-provider model fallback and a closed-loop upgrade pipeline. Everything else on this page runs beside it.

    See the architecture
  • Built and operated

    An agentic software-delivery team

    Role-based agents (lead, architect, two engineers, QA) working one shared board, with a separate security-review workflow and a nightly observability roll-up that raises an alert when quality drifts.

  • Built and operated

    Self-operating infrastructure

    More than twenty nightly health checks, each with its own smoke test, and automatic remediation for known faults. Upgrade pipelines for two agent frameworks snapshot, test, gate on health and regressions, roll back on failure, and escalate after repeated deferrals.

  • Built and operated

    Agent framework evaluation

    A 20-task benchmark that compared two agent frameworks on identical models. Failing answers were read by hand before any score was trusted, because a strict checker can fail an answer that is better than the expected format.

  • Built and operated

    This website

    Static pages with no tracking, and a CV available on request: a bot check, every request comes to me, and I reply personally.

The seven case studies built on Nexus

  1. CS-01

    A Telegram channel, hardened like a production banking gateway.

    Eighteen controls in five layers: gateway, identity, session isolation, behavioural rules and operations. The same hardening pattern bank procurement committees ask architects to apply to third-party chat channels.

    SecuritySecurityProduction19 April 2026~9 minutes
  2. CS-02

    Agentic KYC - unravelling corporate UBO across jurisdictions.

    Enhanced CDD, adverse-media screening, and beneficial-ownership unwind under AMLR Article 42 and the BORIS register. Research swarms and vision agents as proof-of-build components - the AFC transformation shape banks are budgeting for in 2026.

    Anti-Financial CrimeAMLRArchitecture21 April 2026~10 minutes
  3. CS-03

    Multi-model orchestration without vendor lock-in.

    Nexus routes across GLM, MiniMax, Birch, Gemma, and Claude with a fallback chain that survives a provider outage mid-task. The vendor-independence pattern DORA Article 28 now asks banks to design for.

    OrchestrationDORAProduction22 April 2026~10 minutes
  4. CS-04

    Agentic AI across the consumer-lending lifecycle.

    Origination through servicing - PSD2/3 data aggregation, document ingestion at application time, affordability beyond traditional credit scoring, real-time decisioning, back-book repricing. Same component-level proof-of-build anchoring under PSD3 and AI Act Annex III.

    LendingPSD3, AI ActArchitecture25 April 2026~11 minutes
  5. CS-05

    Cron-Driven Autonomy

    The operational layer that keeps a multi-agent system honest while nobody is watching - the upgrade pipeline, the verification discipline, and the guardrails under DORA Art. 17.

    AutonomyDORAProduction22 May 2026~11 minutes
  6. CS-06

    When the watcher couldn't be trusted.

    A model-failover watcher that flipped a healthy system onto a fallback in a tight loop - because the cloud was rate-limiting, not failing. The boundary between monitoring and decision-making under AI Act Article 14.

    OversightAI ActProduction22 May 2026~9 minutes
  7. CS-07

    The bleed - AI compute as a treasury function.

    Two paid-API leaks caught by a balance poller on a daily timer. The forensics, the two rules that fell out, the observer-based circuit breaker that enforces them, and the case for treating production agentic compute as a treasury function.

    Cost GovernanceGovernanceProduction25 May 2026~11 minutes
Request CVEmail