Document work is the value pool
Diligence, filings, disclosure and precedent are where analyst hours concentrate, and they are exactly the shape retrieval with citation handles well.
Every other industry treats access control as a security requirement. In investment banking it is the product: the wall between the deal side and the public side is what lets the firm exist in both. An agent that can retrieve across it is not a bug to be patched — it is a reportable event. This specialisation is built around that constraint from the first module.
The bank is deliberately several businesses that must not share what they know. Part 1 maps the chain and names the people on each side of the wall.
Six stages from coverage to settlement. Select one.
Client coverage, pipeline development, pitch preparation and mandate win.
Diligence, valuation, documentation, marketing and closing across M&A, ECM and DCM.
Coverage initiation, estimates, notes and the independence rules around them.
Client sales, market making, order handling, execution and best execution evidence.
Information barriers, conflicts, surveillance, suitability and supervisory review.
Confirmations, allocations, clearing, settlement and break resolution.
Two of these people are legally not allowed to know what the other one knows. Select one to light the stages they own.
A document-heavy business with a hard confidentiality boundary running through the middle.
Diligence, filings, disclosure and precedent are where analyst hours concentrate, and they are exactly the shape retrieval with citation handles well.
Firms adopting AI here are designing entitlement into retrieval from the start, because retrofitting a wall into an index that ignored one is not possible.
Communications monitoring generates more alerts than reviewers can read, so triage that reduces false positives is the difference between coverage and theatre.
Settlement breaks recur with the same causes across quarters, which makes them a data and pattern problem rather than a staffing one.
What research may see and say is regulated separately from the rest of the firm, so a single shared corpus is a compliance problem however convenient it looks.
In a supervised business the output that matters is not the answer but the record of how the answer was reached and who could see what.
The unusual thing about this architecture is that the access control is not a layer bolted on at the end. Entitlement determines what may be indexed together at all, which means it shapes the retrieval design before a single document is loaded.
Six families, two of which must be provably unable to reach each other.
Mandates, pipeline, diligence rooms and transaction documents.
Deal CRM, virtual data roomsPrices, instruments, issuers, corporate actions and identifiers.
Market data vendors, security masterRegulatory filings, prospectuses, transcripts and announcements.
Regulator archives, filing feedsNotes, models, estimates and the publication and independence record.
Research management systemsOrders, executions, allocations and best-execution evidence.
OMS, EMS, execution venuesEmail, chat, voice and the surveillance record over all of it.
Archives, surveillance platformsIn most industries the ontology exists so an agent can join data. Here it also exists so an agent knows what it is not allowed to join. Every entity below carries a side, and the graph is as much an entitlement model as a knowledge model.
Six subject areas, each with the entities it holds, its critical data elements and the function accountable for it.
Who the firm acts for, and on what.
The securities and the entities that issue them.
What has been said publicly, and when.
Client orders and how they were filled.
The barriers, lists and reviews that govern who may know what.
Confirmation, settlement and the breaks between them.
The entities and the typed relationships between them — what the agent traverses instead of guessing joins. Select any entity.
The party the firm acts for.
An engagement to act, and private side by nature.
The transaction a mandate is executing.
The entity whose securities are traded.
A tradable security of an issuer.
A public disclosure made by an issuer.
Published analysis, subject to independence rules.
A client instruction to trade.
A fill against an order.
Securities on which activity is limited.
A communication flagged for review.
A mismatch between two records of one trade.
The classification hierarchies that make records comparable across systems.
Private → Live mandate → Deal team only
Advisory → M&A → Sell-side
Economic → Price mismatch → Counterparty
The definitions an agent must use rather than invent. Most wrong answers in this industry are a term used loosely.
The layers a deployment needs, what each one holds, and what the engineer owns there.
Seven layers, with the information barrier expressed in the index rather than in policy.
Private-side deal material, public market and filing data, and the communications archive.
Nothing. This is the upstream edge.
Side-labelled, entitlement-bearing feeds — public and private material never in one stream.
Mandates, pipeline and coverage activity. Private side by definition: knowing a deal exists is itself material non-public information.
The diligence material for a live transaction, supplied by the target and access-controlled per deal. The most sensitive corpus in the firm.
Prices, instruments, issuers and corporate actions, under vendor licensing that limits redistribution and derived use.
Prospectuses, annual reports, announcements and transcripts. Public, structured by section, and the corpus most research work is grounded on.
Orders, executions, allocations and the evidence behind a best-execution assertion.
Email, chat and voice under supervisory retention, plus the surveillance alerts raised over them.
Classifying every source as public or private side before it is ingested anywhere.
Loading a source before it has been classified public or private side. A document that enters unlabelled contaminates the partition it landed in, and the only remedy is to rebuild the index.
Ingestion that carries side, deal and entitlement labels with every document.
Read-mostly access paths, change feeds and document streams from the systems of record.
Replayable, resolved, quality-checked records with their lineage back to the source row.
Reads the source’s own change log rather than polling it, so the platform sees every state a record passed through instead of only where it ended up.
Every extract kept as it arrived, immutable and timestamped. The thing you replay from when a downstream definition turns out to have been wrong.
Layout-aware extraction over the unstructured half of the estate: sectioning, tables, signatures, and the page reference every later citation depends on.
Decides that two records are the same real-world thing, with a survivorship rule and a confidence, so downstream joins are a decision rather than an assumption.
Schema, freshness and volume expectations asserted at the boundary, so a bad load fails loudly here rather than quietly two layers later.
Labels every document public or private side at the moment it is ingested, because a document that enters unlabelled can never be trusted afterwards.
Labelling at ingestion, because a document that enters unlabelled can never be trusted again.
Ingesting first and classifying later. The partition is only as trustworthy as its worst unlabelled document, and you cannot find that document afterwards.
The entitlement model, the issuer and instrument graph, and governed definitions.
Replayable, resolved records with lineage from ingestion.
Typed, classified, defined data an agent can be grounded on without inferring meaning.
One agreed definition per term, owned by a named person, so the number an agent quotes means what the business means by it.
The typed entities and relationships the domain actually has, so an agent can traverse "which customers are exposed to this" rather than guess from adjacent text.
Metrics defined once, in one place, with their filters and grain. Removes the class of error where the agent computed something plausible and wrong.
Sensitivity labels and the purpose each classification permits, applied at the field level and inherited by everything downstream.
Where a value came from and what it touched on the way. The layer that makes an answer defensible rather than merely correct.
One entitlement model that both the index and the application obey, with no second copy.
Letting the model infer meaning from column names. It will, it will be plausible, and nobody will notice until the number reaches a regulator or a board pack.
Side-partitioned retrieval over filings, precedent, research and diligence material.
Typed, classified, defined data from the governance layer.
Ranked, permission-trimmed, citable evidence scoped to the caller and the moment.
Vector and lexical retrieval together, because exact identifiers, codes and clause numbers are the thing semantic search is worst at.
Splits on the document’s own structure and carries effective dates, version and source into every chunk, so a retrieved passage knows when it was true.
Applies the caller’s permissions inside the query rather than filtering results afterwards, so the model never sees what the user may not.
Traverses the knowledge graph for questions that are joins rather than similarity — exposure, genealogy, ownership, causation.
Reorders candidates on relevance and returns the passage identifier behind every sentence, so the answer can be checked rather than trusted.
Physically separate indexes per side, with entitlement applied inside the query, so private material is not merely filtered but unreachable.
Enforcing the barrier inside the query, so private material is not retrievable at all publicly.
One index with an entitlement filter on top. A filter is a line of code somebody can bypass; a partition is not.
Agents for diligence review, filing change detection, surveillance triage and break diagnosis.
Ranked, permission-trimmed, citable evidence from retrieval.
Actions taken or proposed, each with the evidence, the identity and the trace behind it.
Plans, calls tools and holds the loop. Where the step budget, the timeout and the stopping condition are enforced rather than hoped for.
Typed, permissioned tools with declared schemas. An agent’s real capability surface is this list, which is why the list is a security artefact.
Durable task state with checkpoints, so a run that dies mid-way resumes instead of restarting and re-doing side effects.
Approval steps on the actions that need one, carrying enough context for the approver to actually decide rather than rubber-stamp.
Writes back into the systems people already work in, under a service identity with its own audit trail.
Ensuring an agent inherits the user’s entitlements and never exceeds them.
An agent that acts under a service account rather than on behalf of the user. It will eventually do something the requesting user had no right to do, and the log will not show it.
Information barrier enforcement, conflict checks, restricted lists and the audit record.
Proposed actions and drafted responses from the agent layer.
Permitted, grounded, logged output — or a refusal with a stated reason.
The rules that decide whether an action is permitted at all, evaluated before the action and independently of the model that proposed it.
Injection detection on the way in, and on the way out the checks for leakage, unsupported claims and content the domain forbids.
Verifies each assertion resolves to retrieved evidence, and fails the response rather than shipping the sentence that does not.
Model inventory, intended use, validation evidence and the sign-off that lets a model be used for a purpose. Not optional in a regulated estate.
Immutable record of what was asked, retrieved, decided and done — the artefact a reviewer reads when they do not take your word for it.
The adversarial test that attempts cross-side retrieval and must fail, run on every build rather than on every audit.
Being able to prove that no answer was ever assembled from material across the wall.
Proving the barrier once, at go-live. Entitlement drifts with every corpus change, so the proof has to be a build gate rather than a document.
Retrieval accuracy, barrier regression tests, alert precision and cost per review.
Permitted, grounded, logged output from the guardrail layer.
Measured quality, cost and latency — and the evidence to change any of the three.
Held-out sets and graded runs on every change, so a prompt edit is a measured change rather than a hopeful one.
Blocks a release when quality drops, in CI, on the same evidence for everyone. The difference between a system and a demo.
End-to-end spans across retrieval, model and tool calls, so a bad answer can be opened and read rather than argued about.
Cost per task and per tenant, against throughput and quota. The number that decides whether the pilot can become the rollout.
Watches quality against production traffic rather than the test set, and routes real corrections back into the eval suite.
The barrier regression suite — the test that must fail the build, not the report.
Evaluating once, before launch. Quality moves with the data, the model and the traffic, and a system with no live measurement has no idea which of the three moved.
Private-side material must be unretrievable from the public side, enforced in the index and the query rather than by a policy the application is trusted to apply.
Communications and advice are subject to supervisory review and recordkeeping. Anything an agent produces enters that record and must be reconstructable.
What research may see and say is regulated on its own terms. A convenient shared corpus across research and banking is a compliance finding waiting to happen.
Filing windows, closing dates and settlement cycles do not move for a system that is having a slow day.
Every use case below is designed so that the entitlement question is answered before the retrieval question. In this sector that ordering is the whole discipline.
Filter by stage or by earned autonomy. Selecting a use case jumps the value chain and the architecture to the stage and layer it depends on.
No use cases match that combination.
How an investment banking deployment actually runs.
Agree the entitlement model and how it will be enforced in the index. Every later design decision is downstream of this, and it cannot be retrofitted.
Label every source public or private before it is loaded. A document that enters unlabelled contaminates the partition it landed in.
Filings, precedent and market data carry no barrier risk and deliver value fast. They also build the citation discipline the private-side work will need.
Only once the barrier regression suite passes should private-side material be indexed. The suite runs on every build from that point on.
Prove that every answer is reconstructable and that no answer crossed the wall, then hand over runbook, regression suite and the audit evidence.
8 modules, 80 taught hours, 40 hands-on labs and 8 assessments — every lab provisioned and graded by the SCIKIQ Agentic AI Playground. Open a module to see its labs.
End-to-end agent design, development, deployment and testing, 10 hours each. Reviewed by a Senior SCDAI Engineer against a published rubric.
Build an agent that reviews a diligence room and surfaces inconsistencies against the draft disclosure, citing document and section, while a barrier regression suite proves that no private-side material is retrievable from the public side under any query.
Build an agent that ranks communications surveillance alerts by likely reviewer value, with a measured false-positive reduction and an explicit, control-agreed threshold, plus evidence that no true positive class is systematically suppressed.
Every lab in this program follows the shape below. This is lab 07 in full — the brief you are given, the environment that is provisioned for you, the code you start from and the assertions that decide whether you passed.
Make private-side material unreachable from the public side, and prove it under attack.
You are given a mixed corpus: public filings and a live data room, correctly side-labelled. Build the retrieval layer so a public-side user cannot reach private material by any route, then write the adversarial suite that tries. The suite includes queries that quote private text verbatim, that ask for it indirectly, and that attempt to infer it from what is absent.
def retrieve(query, principal, index):
"""Return passages this principal is entitled to see.
Entitlement is a property of the index partition, not a filter applied
to results. If it is expressible as a post-filter, it is wrong.
"""
# 1. resolve the principal to the sides they may read
# 2. query ONLY those partitions -- never query then discard
# 3. return citations that can be checked against the partition
raise NotImplementedError
Every module ends with a timed, randomised assessment delivered through the SCIKIQ Agentic AI Playground. The certificate requires a pass on all of them plus two reviewed capstones.
What each test covers, how long it runs, and how many items are currently in the versioned bank behind it.
| # | Assessment & coverage | Items | Time | In bank |
|---|---|---|---|---|
| 01 | Operating model & barrier scopeDelivery mandateInformation barriersValue sizingThin slicing | 25 | 35 min | 3 |
| 02 | Banking data landscapeDeal dataMarket and referenceFilingsSide classification | 25 | 35 min | 2 |
| 03 | Context engineeringIdentifier resolutionFigure extractionStructured outputsRefusal | 25 | 35 min | 2 |
| 04 | Retrieval & groundingSection retrievalChange detectionPrecedentRetrieval metrics | 25 | 40 min | 2 |
| 05 | Agent design & entitlementEntitlement inheritancePartitioned toolsCross-side handlingTriage | 25 | 40 min | 2 |
| 06 | Systems integrationMCP designData licensingOrder dataIdentity | 25 | 35 min | 2 |
| 07 | Barriers, conflicts & securityBarrier enforcementConflictsRecordkeepingLLM security | 30 | 45 min | 2 |
| 08 | Production & evidenceEval gatingBarrier regressionAudit reconstructionEconomics | 30 | 45 min | 2 |
Real items, drawn from 17 in this program's bank — weighted toward the scenario and diagnosis types, because those are the ones that predict field performance. Instant feedback, nothing saved.
Four sample items — one attempt each, then the reasoning is shown.
Q1A bank asks for AI across advisory and research. What do you settle first?
Every later design decision is downstream of the barrier. It cannot be retrofitted into an index that was built without it, so it is a week-one conversation or a rebuild.
Q2When must a document be classified public or private side?
A document that enters unlabelled contaminates its partition, and you cannot reliably find it again. Classification is an ingestion-time gate, not a retrieval-time decision.
Q3An agent is asked a question that would require material from both sides of the barrier. What should it do?
A partial answer that does not name the boundary invites the user to infer what is missing. Refusing and routing is both safer and more useful.
Q4A change-detection agent flags a wording change in a risk factor. Should it classify it as material?
Materiality is a regulated judgement with consequences. The agent adds most value by finding candidates reliably, not by concluding.
The same ladder whichever specialisation you enter through — what changes is the domain you go deep in. Below: how the program is delivered, the skills it moves, the roles it leads to, and the specialisations closest to this one.
The same labs, assessments and capstones, delivered to an enterprise cohort or to individual professionals.
Cohorts of 20 to 2,000+ on your own tenancy, with your data patterns and your cloud. Skill-gap baselining up front, per-team mastery reporting throughout, and capstones scoped against your real backlog so the output is deployable work.
The same labs, assessments and capstones for individual engineers and analysts, run on shared infrastructure with a fixed cohort calendar. You leave with a graded portfolio, not a certificate of attendance.
Find your row and aim one column right. The Playground scores you against this after every module.
| Skill | Beginner | Intermediate | Advanced |
|---|---|---|---|
| Banking domain fluency | Knows the product areas. | Maps the chain to who may know what. | Sizes analyst-hour and control value credibly. |
| Entitlement engineering | Aware of the barrier. | Enforces entitlement inside the query. | Runs a barrier regression suite as a release gate. |
| Document intelligence | Retrieves from a filing. | Detects and classifies change across filings. | Runs section-level retrieval with measured precision. |
| Context engineering | Writes clear prompts. | Structures retrieval, tools and state deliberately. | Designs context strategy for reliability and cost at scale. |
| Retrieval & grounding | Builds basic vector search. | Tunes chunking, hybrid search and reranking. | Designs graph + vector grounding with measured recall. |
| Agent orchestration | Runs a single tool-calling agent. | Builds supervised multi-step and multi-agent flows. | Designs autonomy boundaries and failure containment. |
| Tool & system integration | Calls a documented API. | Writes an MCP server over a system of record. | Designs a least-privilege tool estate across systems. |
| Evaluation | Eyeballs outputs. | Builds labelled eval sets and regression gates. | Runs online evals with drift and judge calibration. |
| Observability & cost | Reads logs. | Traces runs, tracks tokens and latency. | Owns cost per task and capacity planning in production. |
| Security & guardrails | Adds output filters. | Mitigates the OWASP LLM Top 10 in a build. | Threat-models an agent estate and proves controls. |
| Client delivery | Takes notes in a workshop. | Runs discovery and scopes a thin slice. | Owns the account technically, from scope to handover. |
The SCDAI ladder is the same whichever specialisation you enter through — what changes is the domain you go deep in.
Skill a team, or join a cohort
B2B cohorts run on your tenancy with capstones scoped to your backlog. B2C cohorts run on a fixed calendar.
Stated plainly enough to rule yourself in or out without a sales call: the prerequisites, how the program runs, exactly what the credential is worth, and the questions everyone asks.
Stated plainly so you can rule yourself in or out without a sales call. Nothing here is a formal qualification — it is what the first lab assumes you can already do.
You should already be able to do these
What we assume, and what we teach
What the program asks of your week
Cohort dates and pricing are confirmed on enquiry rather than printed here, because both move with the intake.
The credential is awarded per specialisation, so it names the domain or stack you were assessed in rather than claiming general competence. On this program the badge reads SCDAI — Investment Banking.
A certificate that cannot be checked is decoration. Every award resolves to a record showing the specialisation, the award date and the assessments passed.
This is the credential the program awards, shown exactly as it is issued — with the specialisation named, the assessment record attached and a verification link anyone can check without an account.
This is to certify that
Your name
has been assessed and certified as
SCIKIQ Certified Data and AI Engineer
Investment Banking
Not “Data and AI Engineer” but the domain or stack you were actually assessed in. A general claim would be a weaker one.
Modules passed, labs graded and both capstones reviewed — so the credential states what was measured rather than that you attended.
The credential ID resolves to a public record showing the specialisation, the award date and the assessments passed.
Add it to your LinkedIn profile in one step. The link pre-fills the certification fields from the credential record, so the entry on your profile matches the record a reader can check.
Add to LinkedIn profile The button is live on your real certificate; here it opens LinkedIn pre-filled with this specialisation so you can see exactly what the profile entry will say.A certificate that cannot be checked is decoration. Every award resolves to a record showing the specialisation, the award date and the assessments passed.
The objections that come up in every conversation about this program, answered without the brochure voice.
Both, and the second is the point. Eight timed assessments and two reviewed capstones stand between you and the credential, so a pass means someone measured the skill rather than recorded your attendance.
Every lab is provisioned, graded and unblocked by the Playground rather than by an instructor. That is what lets a cohort of 2,000 cost the same faculty time as a cohort of 20 — and why you are never waiting on someone to mark your work.
Two retakes are included per assessment, each drawing a fresh item set from the bank, so a retake is a genuinely new paper rather than the same questions again.
For the domain specialisations, no — labs run in provisioned sandboxes. For the four tech-stack programs you will want access to that platform, since deploying into a real subscription is much of the point.
Yes. B2B cohorts run on your own tenancy with your data patterns, a skills baseline before kick-off, per-team mastery reporting, and capstones scoped against your actual backlog so the output is deployable work rather than an exercise.
Take the domain you deploy into. If you move across industries, take a tech-stack program instead and pick up domain context on the engagement. The chooser on the programs page will narrow it.
The trends, platform capabilities and regulatory positions are reviewed each quarter, and every external claim on these pages links to its source so you can check the date yourself.
A graded portfolio: forty machine-graded labs, two reviewed end-to-end agent builds with measured evaluation and cost per task, and a verifiable credential naming your specialisation.
Still deciding?
Tell us the systems you deploy into and we will say plainly whether this specialisation is the right one — or which of the 21 is.