SARATHI - 20 Specialized AI Agent for Research
Author : CA. Himanshu Majithiya
Sarathi is a web-based, agentic-AI platform purpose-built for Chartered Accountancy firms in India. It amplifies the professional judgment of a CA — it does not replace it. A CA submits a matter in plain language; Sarathi routes it through a multi-agent AI pipeline that researches the relevant law across all tax and regulatory domains, verifies citations, grades risk, and produces a structured, firm-branded advisory report. The CA reviews and approves every report before it is final.
| CA Advisory Ecosystem |
| AI Automation Consultancy |
Every CA firm faces the same constraint: advisory quality is bounded by research time. Sarathi eliminates that constraint — giving every CA firm a research team that is built in, always on, and never missing a circular.
| Challenge Faced by CA Firms | How Sarathi Resolves It |
| Keeping up with daily CBIC / CBDT / MCA / RBI circulars | Automated crawlers run every morning; new circulars are queued for CA approval and compiled into the knowledge base automatically |
| Missing cross-domain implications (e.g. GST + Income Tax interaction) | Cross-Domain Scanner scores all 6 practice areas for every query — no implication is overlooked |
| Risk of citing outdated or superseded provisions | Wiki tracks effective dates; agents always serve the provision valid on the date of the matter |
| Time spent drafting advisory reports | 13-section structured report generated in firm voice; CA reviews and approves in minutes |
| Hallucinated or unverifiable legal references | Citation Verifier + Hallucination Checker validate every claim against the KB before the report reaches the CA |
| Client PII risk in AI tools | 8 structured identifiers (PAN, GSTIN, Aadhaar, etc.) masked before any LLM call; embeddings run fully on-premise — no client data leaves the firm's server |
| Automation decisions made without expert guidance | L1→L6 hierarchy recommends the lowest viable automation level with ROI analysis and a step-by-step SOP |
| No partial or unsigned advisory | Hard-stop policy: pipeline blocks if any agent fails; CA signs off every report before it is final |
Sarathi is built on a layered architecture. Each layer is purpose-designed for compliance with Indian CA professional ethics and the DPDP Act 2023.
| Layer | Component | Role |
| Frontend | React 19 + TypeScript + Vite + Tailwind CSS | Browser / mobile UI — submit queries, review reports, manage KB |
| Backend API | Django 4.2 + Django REST Framework + JWT | Authentication, role enforcement, audit logging, all business logic |
| AI Orchestration | LangGraph stateful graphs | Runs the 12-step CA Advisory and 6-step Automation pipelines asynchronously |
| Retrieval — T0 | Compiled LLM Wiki (pgvector) | Highest priority: date-aware, interlinked knowledge pages compiled by WIKI-COMPILE-01 |
| Retrieval — T1 | Vector KB — pgvector (BAAI/BGE-large) | Semantic search over all approved, chunked source documents |
| Retrieval — T2 | Official APIs / RSS (CBIC, CBDT, MCA, RBI) | Live fallback from official government sources; cached 4 hours |
| Retrieval — T3 | CA-managed web search (curated site list) | Last-resort scrape of P1→P3 priority trusted sites; cached 4 hours |
| Async Work | Celery + Redis + Celery Beat | All pipelines, crawlers, wiki compilation and lint run as background tasks |
| Data Store | PostgreSQL 16 + pgvector | All application data, vector indexes, audit logs; soft deletes for traceability |
| Report Output | Jinja2 + WeasyPrint + python-docx | PDF and DOCX advisory reports with firm branding |
| Embeddings | BAAI/bge-large-en-v1.5 (local) | Self-hosted on server — no text sent to external embedding API |
| Security | Fernet encryption + PII masking + Audit Log | AppSetting secrets encrypted; 8 identifiers masked before every LLM call; full immutable audit trail |
| Category | Technology / Tool |
| Backend Framework | Python · Django 4.2 · Django REST Framework |
| Authentication | JWT (SimpleJWT) — access + refresh tokens |
| Async / Scheduling | Celery + Redis (broker) · Celery Beat (cron jobs) |
| AI Orchestration | LangGraph (stateful multi-agent graphs) |
| LLMs (via OpenRouter) | Claude Sonnet 4.5 (primary) · Claude Haiku 4.5 (economy) · Gemini 3.5 Flash (research) |
| Embeddings | BAAI/bge-large-en-v1.5 (1024-d, default) · law-ai/InLegalBERT (768-d) — fully self-hosted |
| Vector Search | PostgreSQL 16 + pgvector (IVFFlat cosine); SQLite + Python-cosine (dev) |
| NER (PII Names / Addresses) | dslim/bert-base-NER — lazy singleton, fail-closed |
| Document Parsing | PyMuPDF (PDF) · BeautifulSoup4 (HTML) · python-docx · tiktoken (512 tokens / 50 overlap) |
| Report Generation | Jinja2 (templating) · WeasyPrint 62.3 (PDF) · python-docx (DOCX) |
| Frontend | React 19 + TypeScript · Vite · Tailwind CSS · TanStack Query · React Router · Radix UI · Recharts |
| Security | Fernet/cryptography (encrypted AppSettings + mask_map) · soft deletes · full audit log |
| OCR | Tesseract 5.3.4 |
| Crawler Fallback | Playwright + Chromium |
| Infrastructure | Contabo Asia VPS, Mumbai · Ubuntu 24.04.3 LTS · Nginx · Gunicorn (gthread) · Let’s Encrypt SSL |
| Version Control | GitHub |
Sarathi deploys 20 specialised AI agents across its two pipelines. Every agent prompt is editable at runtime by a CA in Settings → Prompts & Voice — no code deployment required.
| Agent ID | Role | Model |
| CA-GST-01 | GST research — CGST/IGST, ITC, returns, RCM, refunds | Claude Sonnet |
| CA-GST-02 | Advanced GST — litigation, AAR/AAAR, anti-profiteering | Claude Sonnet |
| CA-IT-01 | Income Tax — primary advisory (Act 2025 / 1961) | Claude Sonnet |
| CA-IT-02 | TDS/TCS specialist — withholding, transfer pricing, DTAA | Claude Sonnet |
| CA-FEMA-01 | FEMA / RBI — FDI, ODI, ECB, NRI, compounding | Claude Sonnet |
| CA-AUDIT-01 | Audit & Compliance — SA standards, 3CD, CARO 2020, NFRA | Claude Sonnet |
| RES-CASE-01 | Case-law research — SC, HC, ITAT, AAR (large context) | Gemini Flash |
| RES-CIRC-01 | Circulars & notifications — CBIC, CBDT, MCA, RBI | Claude Haiku |
| RES-ACT-01 | Bare-act provisions — exact section / rule text | Claude Haiku |
| INTAKE-01 | Intake parser — domain, entities, amounts, clarification check | Claude Haiku |
| QA-XDOMAIN-01 | Cross-domain scanner — scores all 6 domains High / Low / None | Claude Sonnet |
| QA-VALID-01 | Hallucination checker — validates claims against citations | Claude Haiku |
| REPORT-ARCH-01 | Report architect — synthesises 13-section advisory outline | Claude Sonnet |
| VO-STYLE-01 | Voice & style — rewrites report in firm’s professional voice | Claude Sonnet |
| WIKI-COMPILE-01 | Wiki compiler — compiles approved sources into interlinked pages | Claude Sonnet |
| Agent ID | Role | Model |
| AUTO-ARCH-01 | Automation architect — L1→L6 recommendation with specific tools | Claude Sonnet |
| AUTO-ROI-01 | ROI analyser — cost / saving / payback calibrated to Indian CA firm economics | Claude Sonnet |
| AUTO-SOP-01 | SOP generator — phase-by-phase implementation guide | Claude Sonnet |
| AUTO-WRITER-01 | Report writer — plain-language automation roadmap for client | Claude Sonnet |
| AUTO-PARSE-01 | Problem parser — extracts structured problem from query | Claude Haiku |
Client confidentiality is the foundation of CA professional ethics. Sarathi enforces privacy at the architecture level. Before any text reaches an LLM, 8 structured identifiers are detected and replaced with stable placeholders (e.g. “<PAN_1>”). The same raw value maps to the same placeholder within one call, preserving reasoning without ever exposing the identifier. Patterns are applied longest-first to prevent mis-masking. Free-text names and addresses are handled by an on-premise NER model (dslim/bert-base-NER).
| # | Identifier | What It Is | Detection Pattern |
| 1 | CIN | Corporate Identification Number (MCA, 21 chars) | [LU]\d{5}[A-Z]{2}\d{4}[A-Z]{3}\d{6} |
| 2 | GSTIN | GST Identification Number (15 chars) | \d{2}[A-Z]{5}\d{4}[A-Z]\d[Z][0-9A-Z] |
| 3 | TAN | Tax Deduction Account Number (10 chars) | [A-Z]{4}\d{5}[A-Z] |
| 4 | PAN | Permanent Account Number (10 chars) | [A-Z]{5}\d{4}[A-Z] |
| 5 | Aadhaar | 12-digit UIDAI identity number | \d{4}[\s-]?\d{4}[\s-]?\d{4} |
| 6 | Email address | [A-Za-z0-9._%+-]+@[A-Za-z0-9.-]+\.[A-Za-z]{2,} | |
| 7 | Phone | Indian mobile number (optional +91, 10 digits) | (?:\+?91[\s-]?)?[6-9]\d{4}[\s-]?\d{5} |
| 8 | Bank Account | Bank account number (11–18 consecutive digits) | \d{11,18} |
Sarathi's knowledge compounds over time. Every approved source goes through a governed lifecycle before agents can use it.
| Stage | What Happens | Who Acts |
| 1. Discover | Daily crawlers (CBIC, CBDT, MCA, RBI, ICAI, Indian Kanoon) + CA watched URLs + manual uploads + auto-queued web hits | System (automated) |
| 2. Approve | Pending items appear in KB Review grouped by urgency (Immediate / Routine / Reference). CA approves or rejects. | CA (human gate) |
| 3. Ingest | Download → extract text → chunk (512 tokens / 50 overlap via tiktoken) → embed locally (BGE-large) → store as KnowledgeChunk + pgvector | System (automated) |
| 4. Compile | WIKI-COMPILE-01 converts each source into interlinked Entity / Concept / Procedure wiki pages (DRAFT) | System (automated) |
| 5. Publish | CA reviews draft pages; resolves conflicts; publishes. Amendments recorded as dated supersessions — old and new provisions remain valid for their own date range. | CA (human gate) |
| 6. Serve | Published pages served as Tier T0 (highest priority); KB chunks as T1. All date-aware and citable. | System (automated) |
All scheduled jobs run via Celery Beat (times in IST). They require Celery worker + beat processes to be running on the server.
| Time (IST) | Job | Purpose |
| 06:00 daily | crawl_cbic | CBIC GST circulars & notifications |
| 06:10 daily | crawl_cbdt | CBDT Income-Tax circulars |
| 06:20 daily | crawl_mca | MCA Company-Law circulars |
| 06:30 daily | crawl_rbi | RBI / FEMA notifications |
| 06:40 Mon & Thu | crawl_icai | ICAI announcements |
| 06:50 Sun | crawl_indiankanoon | Indian Kanoon judgments |
| 07:00 daily | crawl_kb_source_urls | Re-check CA ‘watched’ source URLs |
| 07:30 weekly | lint_wiki | Wiki health check — broken links, stale pages, orphans, conflicts |
| 08:00 daily | send_kb_digest | Email digest of pending KB approval items |
| 09:00 daily | check_llm_cost_alert | Alert if per-query cost > ₹50 or daily total > ₹500 |
| Control | Implementation |
| Authentication | JWT (access + refresh tokens); silent single-flight refresh on expiry |
| Authorisation | CA vs STAFF roles enforced server-side; CA-only actions return HTTP 403 for STAFF |
| PII Masking | 8 structured identifiers masked before every LLM call; NER handles free-text names/addresses; mask_map Fernet-encrypted, never sent to browser |
| Embeddings Privacy | Self-hosted BAAI/BGE-large on server — no text sent to external embedding API |
| Secrets Encryption | Integration credentials (API keys) encrypted at rest via Fernet; entered from UI, override server .env |
| Audit Trail | Every sensitive action written to immutable AuditLog (who, what, when, IP) |
| Human-in-the-Loop | Three CA gates: knowledge approval, wiki publication, report sign-off |
| Hard-Stop Policy | Pipeline halts if any required agent fails; no partial advisory delivered; CA retries or overrides |
| Data Retention | All records are soft-deleted (never silently destroyed); full traceability and recovery |
| DPDP Act 2023 | On-premise processing, minimal data exposure, and audit trail support DPDP compliance posture |
| ICAI Ethics | CA controls every knowledge gate; AI provides research; professional responsibility remains with CA |
A CA asks: “Can we claim ITC on a Honda City for our FFMC business?” Sarathi parses the query, finds ITC eligibility is the core issue, scores all 6 domains (GST: High, IT: Low for depreciation impact, others: None), runs the GST and IT agents in parallel, verifies citations against the KB, grades the risk, and synthesises a 13-section advisory in the firm’s voice. The CA reviews the report in the Reports screen and approves it — with quantified INR exposure, the exact interest section and rate, related blocked credits under Section 17(5)(ab), and a GSTR-3B reversal mechanic.
The CBIC crawler runs at 06:00, finds a new circular, and queues it in KB Review. The CA approves it. Sarathi ingests and chunks the document, embeds it locally, and auto-compiles it into DRAFT wiki pages. Because the circular amends a rate from a specific date, it is recorded as a supersession — the old page governs matters before that date, the new one after. The CA publishes the pages; agents immediately use the updated position.
A CA’s client asks how to automate their monthly GST reconciliation. Sarathi’s AUTO-ARCH-01 evaluates L1→L6 in order and recommends L3 (n8n workflow connecting Tally export to a reconciliation sheet) because the client already uses Tally and the logic is rule-based. AUTO-ROI-01 computes payback in months using Indian CA firm staff cost benchmarks. AUTO-SOP-01 produces a phase-by-phase guide. The CA reviews and approves the roadmap report.