Multi-agent supply chain disruption detection and automated recovery
Built on Elastic Agent Builder Β· Hackathon 2026
Supply chain disruptions are accelerating in both frequency and cost:
| Metric | Data | Source |
|---|---|---|
| Annual global cost | $184 billion | J.S. Held Global Risk Report, 2025 |
| Orgs disrupted in past year | 80% (β from 73%) | BCI Supply Chain Resilience Report, 2024 |
| SC leaders facing resilience challenges | 90% | McKinsey Global SC Survey, 2024 |
| Orgs adequately prepared | only 29% | Gartner Future of Supply Chain, 2025 |
| Supply chains that can't respond in 24h | 83% | Kinaxis, 2024 (n=1,800) |
| Average manual response time | 5 days | Kinaxis, 2024 |
The core failure is speed. Shipment data lives in one system, order books in another, supplier records in a third. Coordinating across them manually takes days that supply chains don't have.
SupplyShield cuts 5 days to under 3 minutes.
A multi-agent system on Elastic Agent Builder with two coordinated agents:
| Agent | Role |
|---|---|
| π€ SupplyShield Orchestrator | Detects anomalies, assesses revenue impact, ranks alternatives, executes recovery |
| π News Scout | Specialist sub-agent for external intelligence via MCP β classifies disruption signal as CONFIRMED / UNCERTAIN / UNCONFIRMED |
The key principle: internal signals (shipment data) and external signals (news) are independently verified by separate agents before a recovery decision is made.
SupplyShield Orchestrator (Kibana Agent Builder)
βββ detect_shipment_anomalies [ES|QL + LOOKUP JOINs]
βββ assess_revenue_impact [ES|QL + LOOKUP JOINs]
βββ find_alternative_suppliers [ES|QL + weighted scoring]
βββ news_scout_query [MCP] ββββββββΊ News Scout MCP Server
βββ query_disruption_news
βββ sc_news [hybrid: kNN + BM25]
| Layer | Technology |
| -------------------- | ----------------------------------------------------------------------------------------------------------------- | ----------------------------------- | ---------------------------------------------------- |
| Agent Platform | |
| Search & Storage |
|
| Query Language |  |
| A2A Protocol |
|
| MCP Framework |
|
| Workflow Engine |
|
| Language |
|
| Tunnel |
|
Based on synthetic data (14 pre-planted Shenzhen delays, seed=42):
User: "Shenzhen port congestion β any affected shipments?"
β
ββ [Tool 1] detect_shipment_anomalies
β βββΊ 14 delayed shipments, avg 143h delay, 3 suppliers
β
ββ [MCP] news_scout_query β News Scout β sc_news hybrid search
β βββΊ CONFIRMED: 3 high-severity articles, sentiment β0.77
β
ββ [Tool 2] assess_revenue_impact (Shenzhen Microtech)
β βββΊ $4.2M at risk, 31 orders, 8 customers, due in 8 days
β
ββ [Tool 3] find_alternative_suppliers (microcontrollers, excl. East Asia)
β βββΊ #1 Viet Components Vietnam: score 84.2, 18d lead, +10% cost
β
ββ [Workflow] supply_chain_recovery (after explicit user confirmation)
βββΊ PO-2026-0042 created + immutable audit log entry
Total: < 3 minutes vs. 5-day industry average
| Index | Purpose | Mode | Docs |
|---|---|---|---|
sc_shipments |
Shipments with delay tracking + geo | standard | 214 |
sc_suppliers |
Supplier catalog with scoring | lookup | 33 |
sc_news |
News articles with 384-dim embeddings | standard | 18 |
sc_orders |
Customer orders | standard | 300 |
sc_products |
Product catalog | lookup | 10 |
sc_actions_log |
Agent action audit trail | standard | β |
sc_purchase_orders |
Recovery POs | standard | β |
β οΈ lookupmode onsc_suppliersandsc_productsis required for ES|QLLOOKUP JOIN. Without it, joins silently return no results.
# 1. Set credentials
export ES_ENDPOINT="https://your-deployment.es.us-east-1.aws.elastic.cloud"
export ES_API_KEY="your-api-key"
export KIBANA_URL="https://your-deployment.kb.us-east-1.aws.elastic.cloud"
export NGROK_AUTH_TOKEN="your-ngrok-token" # required for live MCP wiring
# 2. Install dependencies
pip install elasticsearch faker mcp flask pyngrok
# 3. Set up data and agents
python scripts/setup_indices.py # Create 7 indices with mappings
python data/generate_data.py # Synthetic supply chain data
python data/load_data.py # Load 575 docs into Elasticsearch
python scripts/create_tools.py # Create 4 Agent Builder tools
python scripts/create_agent.py # Create SupplyShield Orchestrator
python scripts/create_news_scout.py # Create News Scout sub-agent
# 4. Start MCP server + wire A2A connector (one command)
python scripts/start_mcp_with_ngrok.pySee docs/setup_guide.md for manual Kibana setup.
supplyshield/
βββ agents/
β βββ supplyshield_agent.md # Orchestrator system prompt + config
β βββ news_scout_agent.md # News Scout config + MCP wiring docs
βββ tools/
β βββ detect_shipment_anomalies.md
β βββ assess_revenue_impact.md
β βββ find_alternative_suppliers.md
β βββ search_disruption_news.md
βββ workflows/
β βββ supply_chain_recovery.md # Elastic Workflow definition
βββ data/
β βββ generate_data.py # Synthetic data (Faker, seed=42)
β βββ load_data.py # Bulk load via elasticsearch-py
β βββ sample_data/ # Generated JSON
βββ mappings/
β βββ index_mappings.md # All 7 index mappings documented
βββ scripts/
β βββ setup_indices.py
β βββ create_tools.py
β βββ create_agent.py
β βββ create_news_scout.py
β βββ news_scout_mcp_server.py # FastMCP server (query_disruption_news)
β βββ start_mcp_with_ngrok.py # One-command: server + tunnel + wire Kibana
β βββ wire_mcp_connector.py
βββ docs/
βββ architecture.md
βββ setup_guide.md
βββ submission_description.md
βββ architecture_main.mermaid
βββ architecture_sequence.mermaid
βββ architecture_dataflow.mermaid
βββ architecture_usecase.mermaid
The LLM fills values ("SUP-SZ-001", 24) but never query structure. Using ?param syntax keeps tool behavior fixed and auditable β the agent cannot alter what a query does, only what it queries for.
All reads go through tools. All writes go through a deterministic Elastic Workflow requiring explicit user confirmation. The agent cannot modify data through a malformed query argument, and every action has an immutable log entry.
sc_news combines 384-dimension dense vector embeddings (cosine similarity) with BM25 keyword matching, following Elastic's recommended hybrid search pattern for balancing semantic and lexical relevance.
The Orchestrator calls the News Scout via the Model Context Protocol β an open standard for agent communication. This keeps the agents independently deployable and testable, with a clean interface boundary.
- J.S. Held (2025). Global Risk Report 2025 β $184B annual cost
- BCI (2024). Supply Chain Resilience Report 2024 β 80% of orgs disrupted
- McKinsey (2024). Global Supply Chain Leader Survey β 90% resilience challenges
- McKinsey (Jan 2026). Supply Chain Risk Outlook β 82% hit by tariffs, +39% costs
- Gartner (2025). Future of Supply Chain 2025 β 29% prepared
- Kinaxis (2024). Disruption Response Study β 83% can't respond in 24h; avg = 5 days
- Elastic (2023). Hybrid Search Blog
- Anthropic (2024). Model Context Protocol
Apache 2.0 β see LICENSE.