BAND OF AGENTS HACKATHON · TRACK 3

Five agents. One room.
Zero coordination overhead.

Concord is an autonomous Security Operations Center built on Band. When an alert fires, five specialist agents coordinate through a shared Band room — triage to post-mortem — with one human approval gate before anything leaves the building.

→ Launch Live Demo View on GitHub
System Live · incidents closed · 29/29 tests passing · 3 scenarios ready

How Concord Works

One alert. One Band room. Five specialists.

Triage

Classifies severity and category

llama-3.3-70b via Groq
Forensics

Analyzes logs and identifies indicators

llama-3.3-70b via Groq
Containment

Generates response plan

llama-3.3-70b via Groq
Communications

Drafts external reports and alerts

llama-3.3-70b via Groq
RCA

Performs post-mortem and roots out cause

llama-3.3-70b via Groq
THE GATE

Communications waits for BOTH Forensics AND Containment before drafting anything. The parallel gate is what makes this coordination, not sequencing.

The Room Is the System

No hidden databases. No private agent memory. Every agent reads and writes to one Band room. Remove Band — it stops.

One Human Gate

The Comms agent drafts but never sends. One human approval is the only gate before anything is sent.

Full Audit Trail

The RCA agent reads the entire room transcript. Every claim traces to a specific message.

29/29 Tests Passing
·
3 Scenarios
·
5 Specialist Agents
·
1 Human Gate

Fire a Live Incident

Click any scenario to trigger a real alert and watch the agents respond in Band.

SQL Injection

CRITICAL

Cloudflare WAF detects automated SQL injection on the payments API. Attacker IP fingerprinted, customer notification drafted and approved.

Ransomware

CRITICAL

CrowdStrike EDR flags ransomware on a file server. 2,847 files renamed. Network shares isolated. Two-draft revision cycle triggered.

Data Exfiltration

HIGH

SIEM detects insider downloading 48GB overnight — 240x normal volume. Account suspended, MFA revoked.