Roxom
Problem
Roxom's lean legal and compliance team faced scaling problems as its Bitcoin-based capital market business grew
Results
- Built a seven-agent anti-money laundering investigation swarm, running on local models, in a week
- Many daily workflows now run more agents than people, with a person deciding every outcome
- Automated court and regulatory order responses end to end, scaling with the business without adding new headcount
Roxom is building Bitcoin capital markets where people can borrow, earn, invest, and build wealth with bitcoin. Its legal and compliance team is responsible for protecting the company as it grows.
Most people wouldn’t expect a group of lawyers and compliance professionals to be at the forefront of AI adoption, but the compliance and legal team at Roxom has more AI agents than people. On many of the team's daily tasks — anti-money laundering (AML) investigations, sanctions and politically exposed person (PEP) screening, and responses to court orders — agents now handle the first pass. Then, a person reviews the work and makes the decision. The team built this agentic workflow in a week, without adding headcount.
Why hiring wasn't the answer
A growing exchange generates more compliance work every quarter with more investigations, more screening, more legal requests with hard deadlines. The default response is to hire more analysts and lawyers to keep pace.
Roxom's team took a different approach, with cultural reasoning: this is a compliance function that builds its own tools. "In a legal and compliance team — where both fields are often seen as rigid — I can proudly say my team is ten steps ahead of many others," said Alfonso Martel Seward, Roxom's Chief Compliance and Legal Officer. "I have lawyers and accountants who are building workspaces and training agents so our daily work becomes more effective, faster, and ultimately better."
That instinct fits the company. Building a capital market that doesn't exist yet means the rules are not written down, which is exactly what drew Martel to the job. "What we're trying to create doesn't exist," he said. "There are no rules, nothing is written down, and the challenge is absolute." So when a new technology arrived, the team treated it the way it treats everything else: as something to build with.
"It was about the culture and mindset," Martel said. "We saw a new technology and sat down to see what we could do with it, and how we could work differently from all the other teams we knew. Suddenly we were doing more in less time, and we realized we could grow without adding headcount." The goal was efficiency. As Roxom continues to grow, Martel has confidence his team’s existing resources will keep pace because the team is proactively looking for creative solutions to address problems before they gain traction.
One of these creative solutions was building a team of AI agents that could operate across Roxom’s legal and compliance workflows. For this system to succeed, one rule shaped every downstream decision: no agent acts alone without a human counterpart. "We don’t have AI agents operating on their own," Martel said. "We thoroughly understand the concept of human-in-command. We created workflows where a large part is done by agents with human supervision, because speed, efficiency, and accuracy matter as much as understanding what we're doing and protecting our clients' and company's data."
Inside the seven-agent AML swarm
The clearest expression of that approach is the team's AML investigation swarm — seven agents, each with a single job, run in sequence on a client under review. Yanina Acosta, a senior financial crime prevention analyst, built the division of labor around the phases a real investigation already moves through.
"An investigation progresses through several phases," Acosta said. "So we created a specific agent for each task, and the key was making sure each agent has its own expertise." The Know Your Customer (KYC) agent identifies who the person is from Roxom's own data. The transaction agent reviews their activity. The AML agent checks sanctions and PEP data. The onchain agent runs the blockchain analysis connected to TRM’s Model Context Protocol (MCP) — pulling attribution, counterparties, risk, and exposure for an address, and returning a conclusion. The open-source intelligence (OSINT) agent conducts research on the subject. A documentation agent then proposes what to request from the client.
The seventh agent watches the other six. "The meta-audit agent checks quality and makes sure everything is coherent with what was investigated, so we have greater traceability," Acosta explained. The swarm delivers an executive summary of the client, including proposed next steps, and it runs on local models. This means sensitive client and corporate data stays inside Roxom's own environment, rather than going out to third-party models.
Not every agent runs on the same engine. "For more complex tasks we use more advanced models," Acosta said. "For simple tasks, like reviewing internal databases or data we already had, we use simpler models." The human stays in the workflow at every stage by design. The documentation agent drafts what to request from a client, but a person reviews it before anything goes out.
One standard for every investigation
The onchain step is where Roxom relies on TRM, and Acosta is specific about why the team uses the MCP rather than connecting the blockchain data through a standard API. With a standard integration, the tool hands over data and the team defines the investigative criteria itself, which means results shift from one run to the next.
"With the standard API, TRM gives you the data and you define the research criteria, so the result is different every run, and it lacks context," Acosta said. "With the MCP, a consistent standard is applied across investigations." In practice, TRM’s MCP supplies the investigative workflow and the context around it, so every agent-run investigation follows the same order and reaches conclusions against the same criteria. For a compliance program that has to defend its decisions, that consistency is what holds up under review.
With the end goal in mind, Martel and his team worked quickly, going from idea to a working system in a week. "We built each agent from scratch, step by step, and made them work properly, first individually, and then as a whole system," Acosta said. "From day one, we included the human-in-the-loop as part of the design." After six months of daily use, the agents have improved: many of the team's processes now run on looping logic, store what they learn in memory, and get better over time. "The results are far superior to what they were on day one," Martel said, "and to what they were before we implemented this system."
Putting the same system to work on court orders
The AML swarm proved the model, so the team pointed the same approach at a very different problem. Court and regulatory orders are legal’s responsibility with fixed deadlines and rising volume, and they now run agentically end to end. Guadalupe Asoratti, a lawyer on the team, walked through the transformation.
Before, a request would come in and the legal team would analyze it. When a request touched onchain activity, Asoratti and her team would hand it to the AML team for a manual investigation before drafting a response. Now, the handoff is automatic. "When we receive an information request, we upload it to our dashboard, and based on a semantic analysis of the request, we can detect whether the AML team's intervention is needed," Asoratti said. “When it is, the analysis runs through TRM's MCP against pre-set parameters and returns a report, without a manual investigation at that stage. The person who used to run the search now supervises the output for precision instead.”
The payoff shows up in two critical ways: time and scale. Requests arrive with a deadline, and they grow as the business grows. "With the MCP, we reduced the time needed to respond by about 3x, and we can handle a growing volume of replies as the business expands, without increasing the number of people involved," Asoratti said.
Roles move from doing the work to supervising it
Because the agents absorbed the repetitive work, the job changed. Recurring drafting and review — the tasks where a person adds little judgment — now fall to agents, which frees the team for analysis where judgment counts.
"Adopting these agents let us replace very repetitive tasks where team members weren't adding value, so we can focus on deeper analysis and deliver substantial value to the product," said Facundo Pastorella, Roxom's Head of Legal. "Human judgment remains essential throughout the entire process. We're involved from day one in creating the process, and we review the results to keep improving it."
To compliance leaders who are skeptical, Pastorella’s answer is that the fear comes from not knowing what building agents actually means. "There's a huge gap between what people think implementing agents is and what it actually is. It's not about replacing people — it's about replacing repetitive functions and tasks. Law and legal work are always kept far from technology, and it's time to bridge that gap."
Build the guardrails, then be bold
Martel's advice to peers starts with the guardrail. "When you're dealing with client data or corporate data, security and governance is the most important thing. Understand how models are routed, what data is sensitive, what can be shared, and how to set up local models when you need complete separation from third-party models." With that in place, his second pointer is to just start. "Don't be afraid to go for it. It's a world where we can be creative and go much further than we think. We can change the way we work and change it for the better."
Pastorella sees the same runway ahead: more agents, more automated tasks, and, as the agents get more specialized, more involvement from the people directing them. For a team that set out to build a market that didn’t exist, it’s fitting that they are building an approach to compliance that doesn’t exist. Even though the team’s agents outnumber its people, Roxom’s system is intentionally designed with a human in command, with agents running initial investigations and drafting recommendations.
Roxom está construyendo mercados de capitales de Bitcoin donde las personas pueden pedir prestado, generar rendimientos, invertir y crear patrimonio con bitcoin. Su equipo legal y de cumplimiento es responsable de proteger a la empresa a medida que crece.
La mayoría de las personas no esperaría que un grupo de abogados y profesionales de cumplimiento estuviera a la vanguardia de la adopción de IA, pero el equipo de cumplimiento y legal de Roxom tiene más agentes de IA que personas. En muchas de las tareas diarias del equipo — investigaciones de prevención de lavado de dinero (PLD), screening de sanciones y de personas expuestas políticamente (PEP), y respuestas a órdenes judiciales — los agentes ahora realizan la primera revisión. Luego, una persona revisa el trabajo y toma la decisión. El equipo construyó este flujo de trabajo agéntico en una semana, sin sumar personal.
Por qué contratar no era la respuesta
Un exchange en crecimiento genera más trabajo de cumplimiento cada trimestre: más investigaciones, más screening, más solicitudes legales con plazos estrictos. La respuesta habitual es contratar más analistas y abogados para mantener el ritmo.
El equipo de Roxom adoptó un enfoque diferente, con un razonamiento cultural: se trata de una función de cumplimiento que construye sus propias herramientas. "En un equipo de legal y cumplimiento — donde ambos campos suelen verse como rígidos — puedo decir con orgullo que mi equipo está diez pasos por delante de muchos otros", dijo Alfonso Martel Seward, Chief Compliance and Legal Officer de Roxom. "Tengo abogados y contadores que están creando espacios de trabajo y entrenando agentes para que nuestro trabajo diario sea más eficaz, más rápido y, en definitiva, mejor."
Ese instinto encaja con la empresa. Construir un mercado de capitales que aún no existe significa que las reglas no están escritas, y eso es justamente lo que atrajo a Martel al puesto. "Lo que intentamos crear no existe", dijo. "No hay reglas, nada está escrito, y el desafío es absoluto." Así que, cuando llegó una nueva tecnología, el equipo la trató como trata todo lo demás: como algo con lo que construir.
"Se trató de la cultura y la mentalidad", dijo Martel. "Vimos una nueva tecnología y nos sentamos a ver qué podíamos hacer con ella, y cómo podíamos trabajar de manera diferente a todos los demás equipos que conocíamos. De repente estábamos haciendo más en menos tiempo, y nos dimos cuenta de que podíamos crecer sin sumar personal." El objetivo era la eficiencia. A medida que Roxom sigue creciendo, Martel confía en que los recursos actuales de su equipo mantendrán el ritmo, porque el equipo busca de forma proactiva soluciones creativas para abordar los problemas antes de que tomen fuerza.
Una de estas soluciones creativas fue construir un equipo de agentes de IA capaz de operar en los flujos de trabajo de legal y cumplimiento de Roxom. Para que este sistema tuviera éxito, una regla determinó todas las decisiones posteriores: ningún agente actúa solo sin una contraparte humana. "No tenemos agentes de IA operando por su cuenta", dijo Martel. "Entendemos a fondo el concepto de human-in-command. Creamos flujos de trabajo en los que una gran parte la realizan agentes con supervisión humana, porque la velocidad, la eficiencia y la precisión importan tanto como entender lo que estamos haciendo y proteger los datos de nuestros clientes y de la empresa."
Dentro del enjambre de siete agentes de AML
La expresión más clara de ese enfoque es el enjambre de investigación AML del equipo: siete agentes, cada uno con una única función, que se ejecutan en secuencia sobre un cliente en revisión. Yanina Acosta, analista sénior de prevención del delito financiero, diseñó la división del trabajo en torno a las fases por las que ya pasa una investigación real.
"Una investigación avanza por varias fases", dijo Acosta. "Así que creamos un agente específico para cada tarea, y la clave fue asegurarnos de que cada agente tuviera su propia especialidad." El agente de conocimiento del cliente (KYC) identifica quién es la persona a partir de los propios datos de Roxom. El agente de transacciones revisa su actividad. El agente de AML verifica datos de sanciones y PEP. El agente onchain ejecuta el análisis de blockchain conectado al Model Context Protocol (MCP) de TRM — extrayendo la atribución, las contrapartes, el riesgo y la exposición de una dirección, y devolviendo una conclusión. El agente de inteligencia de fuentes abiertas (OSINT) realiza investigación sobre el sujeto. Luego, un agente de documentación propone qué solicitar al cliente.
El séptimo agente supervisa a los otros seis. "El agente de metaauditoría verifica la calidad y se asegura de que todo sea coherente con lo investigado, para que tengamos mayor trazabilidad", explicó Acosta. El enjambre entrega un resumen ejecutivo del cliente, incluidos los próximos pasos propuestos, y se ejecuta en modelos locales. Esto significa que los datos sensibles de clientes y de la empresa permanecen dentro del propio entorno de Roxom, en lugar de salir hacia modelos de terceros.
No todos los agentes se ejecutan en el mismo motor. "Para tareas más complejas usamos modelos más avanzados", dijo Acosta. "Para tareas simples, como revisar bases de datos internas o datos que ya teníamos, usamos modelos más simples." La persona permanece en el flujo de trabajo en cada etapa por diseño. El agente de documentación redacta qué solicitar a un cliente, pero una persona lo revisa antes de que se envíe algo.
Un mismo estándar para cada investigación
El paso onchain es donde Roxom recurre a TRM, y Acosta es específica sobre por qué el equipo usa el MCP en lugar de conectar los datos de blockchain a través de una API estándar. Con una integración estándar, la herramienta entrega los datos y el equipo define por sí mismo los criterios investigativos, lo que significa que los resultados cambian de una ejecución a otra.
"Con la API estándar, TRM te da los datos y tú defines los criterios de investigación, así que el resultado es diferente en cada ejecución y carece de contexto", dijo Acosta. "Con el MCP, se aplica un estándar consistente en todas las investigaciones." En la práctica, el MCP de TRM aporta el flujo de trabajo investigativo y el contexto que lo rodea, por lo que cada investigación ejecutada por agentes sigue el mismo orden y llega a conclusiones con los mismos criterios. Para un programa de cumplimiento que debe defender sus decisiones, esa consistencia es lo que resiste una revisión.
Con el objetivo final en mente, Martel y su equipo trabajaron rápido, y pasaron de la idea a un sistema en funcionamiento en una semana. "Construimos cada agente desde cero, paso a paso, y logramos que funcionaran correctamente, primero de forma individual y luego como un sistema completo", dijo Acosta. "Desde el primer día, incluimos el human-in-the-loop como parte del diseño." Después de seis meses de uso diario, los agentes han mejorado: muchos de los procesos del equipo ahora funcionan con lógica de bucle, almacenan en memoria lo que aprenden y mejoran con el tiempo. "Los resultados son muy superiores a los del primer día", dijo Martel, "y a los que teníamos antes de implementar este sistema."
Aplicar el mismo sistema a las órdenes judiciales
El enjambre de AML validó el modelo, así que el equipo dirigió el mismo enfoque hacia un problema muy diferente. Las órdenes judiciales y regulatorias son responsabilidad del área legal, con plazos fijos y un volumen creciente, y ahora se gestionan de forma agéntica de extremo a extremo. Guadalupe Asoratti, abogada del equipo, repasó la transformación.
Antes, llegaba una solicitud y el equipo legal la analizaba. Cuando una solicitud involucraba actividad onchain, Asoratti y su equipo la derivaban al equipo de AML para una investigación manual antes de redactar una respuesta. Ahora, la derivación es automática. "Cuando recibimos una solicitud de información, la cargamos en nuestro dashboard y, con base en un análisis semántico de la solicitud, podemos detectar si es necesaria la intervención del equipo de AML", dijo Asoratti. “Cuando lo es, el análisis se ejecuta a través del MCP de TRM con parámetros preestablecidos y devuelve un informe, sin una investigación manual en esa etapa. La persona que antes realizaba la búsqueda ahora supervisa el resultado para verificar su precisión.”
El beneficio se ve en dos aspectos críticos: tiempo y escala. Las solicitudes llegan con un plazo y aumentan a medida que crece el negocio. "Con el MCP, reducimos el tiempo necesario para responder aproximadamente tres veces, y podemos gestionar un volumen creciente de respuestas a medida que el negocio se expande, sin aumentar la cantidad de personas involucradas", dijo Asoratti.
Los roles pasan de hacer el trabajo a supervisarlo
Como los agentes absorbieron el trabajo repetitivo, el trabajo cambió. La redacción y revisión recurrentes — las tareas en las que una persona aporta poco criterio— ahora quedan a cargo de los agentes, lo que libera al equipo para el análisis donde el criterio cuenta.
"Adoptar estos agentes nos permitió reemplazar tareas muy repetitivas en las que los miembros del equipo no aportaban valor, para poder centrarnos en análisis más profundos y aportar un valor sustancial al producto", dijo Facundo Pastorella, Responsable de Legal de Roxom. "El criterio humano sigue siendo esencial en todo el proceso. Participamos desde el primer día en la creación del proceso y revisamos los resultados para seguir mejorándolo."
Para los líderes de cumplimiento que son escépticos, la respuesta de Pastorella es que el miedo proviene de no saber lo que realmente implica construir agentes. "Hay una enorme brecha entre lo que la gente cree que es implementar agentes y lo que realmente es. No se trata de reemplazar a las personas, se trata de reemplazar funciones y tareas repetitivas. El derecho y el trabajo legal siempre se mantienen alejados de la tecnología, y es momento de cerrar esa brecha."
Construya las salvaguardas y luego sea audaz
El consejo de Martel a sus pares comienza con la salvaguarda. "Cuando se manejan datos de clientes o datos corporativos, la seguridad y la gobernanza son lo más importante. Entienda cómo se enrutan los modelos, qué datos son sensibles, qué se puede compartir y cómo configurar modelos locales cuando necesita una separación completa de los modelos de terceros." Con eso en su lugar, su segunda recomendación es simplemente empezar. "No tenga miedo de lanzarse. Es un mundo en el que podemos ser creativos e ir mucho más lejos de lo que pensamos. Podemos cambiar la forma en que trabajamos y cambiarla para mejor."
Pastorella ve el mismo camino por delante: más agentes, más tareas automatizadas y, a medida que los agentes se especializan más, mayor participación de las personas que los dirigen. Para un equipo que se propuso construir un mercado que no existía, resulta apropiado que esté construyendo un enfoque de cumplimiento que no existe. Aunque los agentes del equipo superan en número a sus personas, el sistema de Roxom está diseñado intencionalmente con un humano al mando, con agentes que ejecutan las investigaciones iniciales y redactan recomendaciones.
Ready to get started?
Fill out the form to schedule a demo with our team.

