Inspiration

Many community problems do not begin as a formal complaint.

They begin as fragments:

  • “The lift stopped again.”
  • “I was stuck between floors.”
  • “It still hasn’t been repaired.”
  • “Management said they would fix it next week.”

Individually, these messages are easy to ignore. Together, they can reveal a recurring problem.

The challenge is that combining reports can also expose the people behind them.

We built Ambient CHORUS around one question:

How can agents help people act collectively without requiring them to give up control of their private information?

Our answer is a privacy-first agent system where disclosure is compiled deterministically before an action agent ever receives the case.


What it does

Ambient CHORUS turns scattered community reports into privacy-controlled, evidence-backed collective action.

The demo begins with ordinary resident messages. A Monitor identifies that multiple independent fragments describe the same recurring elevator problem and opens a candidate case.

Residents then make their own disclosure decisions through individual mandates.

An Investigator examines the evidence and builds the private case.

Before anything can be shared externally, a deterministic privacy compiler creates an immutable ShareableCaseView containing only information authorized for the specific purpose.

The Action Coordinator receives only that compiled view. It never receives facts that were excluded by the privacy boundary.

A human case approver must then authorize the proposed action before it can be executed.

CHORUS also tracks what happens afterward. If management makes a commitment, the system watches the deadline and asks the affected resident to verify the outcome.

If the promise is missed, the case returns to Ready for Action instead of being marked resolved.

Actioned does not mean resolved.


Privacy architecture: compile, don't filter

A central design decision in CHORUS is that the language model is not the authority on disclosure.

We did not want to give an agent private information and then ask it to “please redact” what should not be shared.

Instead:

PRIVATE CASE → deterministic privacy compiler → SHAREABLE CASE VIEW

Only the minimum-necessary ShareableCaseView crosses the privacy boundary.

This means an Action Agent cannot accidentally reveal a private fact that it never received.

In our demo case, the private investigation contains more information than the external view. The compiler includes the facts that are authorized and excludes those that are not.

Privacy is therefore enforced structurally rather than through prompt compliance.


How we built it

Ambient CHORUS is designed as a three-agent system using the Strands Agents SDK:

Monitor / Intake Agent
Detects recurring patterns across ordinary community reports.

Investigator / Skeptic Agent
Tests whether the reports genuinely support the same issue, examines evidence, and surfaces contradictions.

Action Coordinator Agent
Proposes an external action using only the compiled ShareableCaseView.

The production architecture is designed for Amazon Bedrock Nova 2 Lite and three Amazon Bedrock AgentCore Runtime deployments.

The surrounding AWS architecture uses services including:

  • AWS Lambda
  • Amazon DynamoDB
  • Amazon S3
  • Amazon SES
  • Amazon EventBridge Scheduler
  • Amazon VPC
  • AWS IAM
  • AWS CDK

Seven supporting AWS stacks are independently deployed and verified:

Foundation, Network, Data, Reset, Compiler, Sender, and Watcher.

The repository also contains a deterministic local test build so judges can reproduce the complete product flow without AWS credentials.


Human approval and accountability

CHORUS intentionally separates agent reasoning from authorization.

Residents control disclosure of their own information.

The privacy compiler controls what may cross the boundary.

The Action Coordinator can propose an action, but it cannot send autonomously.

A human Case Approver must explicitly approve the proposal before execution.

After an external reply arrives, CHORUS extracts and tracks the commitment rather than treating the sent action as success.

The final verification belongs to the affected human.

That creates the full loop:

detect → authorize → investigate → compile → propose → approve → act → track → verify


Challenges we ran into

The hardest problem was not generating text with an agent. It was deciding what an agent should be allowed to know.

A traditional redaction approach would still expose private facts to the model before filtering the output. That did not satisfy the privacy boundary we wanted.

We therefore moved disclosure authority into a deterministic compiler and designed the Action Coordinator so excluded private facts are absent from its input entirely.

We also encountered an AWS account provisioning issue close to the submission deadline.

The Strands AgentCore runtimes and Nova 2 Lite integration are code-complete, but the AWS account received zero service quota for the required live AgentCore / Bedrock execution path. AWS Support escalated the quota request to its internal service team, with review extending beyond the hackathon deadline.

Rather than presenting a blocked cloud path as live, we clearly separate:

  • the AWS infrastructure that is independently deployed and verified,
  • the production AgentCore / Nova architecture that is code-complete but provisioning-blocked,
  • and the deterministic local product build used for the end-to-end judging demo.

What we're proud of

We are especially proud that privacy is an architectural property rather than a prompt instruction.

A fact that is not authorized for disclosure does not reach the Action Agent.

We are also proud of the accountability loop. CHORUS does not stop after an email is sent. It follows the commitment until a person verifies whether the promised outcome actually happened.

The codebase includes extensive automated testing, infrastructure-as-code, architecture decision records, reproducible local setup instructions, and a judge quickstart.

Most importantly, the final demo proves the thesis:

ACTIONED ≠ RESOLVED

When the management commitment is missed, the case automatically returns to Ready for Action.


What we learned

Human-centered agent systems need more than orchestration.

They need deterministic boundaries around:

  • authorization,
  • provenance,
  • purpose limitation,
  • human approval,
  • and outcome verification.

Our biggest technical lesson was:

Compile disclosure before inference instead of asking a model to filter secrets afterward.

We also learned that agent systems need durable verification.

Sending an action is not evidence that the underlying human problem has been solved.


What's next

The immediate next step is activating the three Strands AgentCore runtimes with Nova 2 Lite once the AWS quota review is completed, then rerunning the entire production path on AWS.

Beyond the elevator scenario, CHORUS could support recurring community problems such as accessibility failures, building maintenance, neighborhood safety concerns, public-service issues, or any situation where individually weak signals become meaningful when people are able to act collectively.

Future work includes richer mandate controls, additional evidence provenance, more communication channels, and deployment tooling for community organizations.

Ambient CHORUS is built around a simple idea:

One complaint is easy to ignore. A safely compiled pattern is much harder to ignore.

Built With

Share this project:

Updates

Submission history