Multi-agent systems collapse into single points of failure when the tool surface, the orchestrator, and the decision log were designed independently. The first ten production incidents are rarely about the model.
The right architecture for a regulated environment is one where the model's authority is bounded by what tools it can reach, what it can do with them is logged at the boundary, and the orchestrator's decisions are reviewable in retrospect without reconstructing prompts.
This brief is hands-on. It produces a written architecture, a working MCP / tool surface specification, and a decision-log schema that compliance can read.
