Authority Cut

A bank lets an AI onboard a vendor. The AI does the routine work. A human approves the risky decision. If the evidence changes, affected work is undone and payment stays blocked.

Authority Cut is a working Strands Agents SDK product for bank third-party-risk, vendor-risk, compliance, procurement, and operations teams. The agent handles routine onboarding work end to end, but decisions with real compliance or financial consequences remain human decisions. A narrow BANK-ECP evidence gate makes the evidence underneath that authority load-bearing: when the evidence changes, the system does not keep treating an old approval as valid.

The judge-visible moment is simple. Routine vendor work completes. The bank employee approves the consequential vendor-risk step. Protected setup proceeds. Then the supporting evidence changes from PASS to HOLD. The work that depended on the stale approval is selectively undone, unrelated safe work remains, and the irreversible first payment cannot proceed.

Who it is for

Bank employees responsible for third-party risk, vendor onboarding, compliance, procurement, and operational risk. Their problem is not simply getting an AI to do more work. It is keeping human control effective after autonomous work has already started.

What you can see working

Open the live product:

https://evidencebound-authority-cut.vercel.app

Run “the end-to-end banking scenario.” The production judge path shows:

  1. The AI completes five routine vendor-onboarding actions before interrupting the human.
  2. A sanitized BANK-ECP-style evidence evaluation supports the vendor-risk premise and returns PASS.
  3. The human approves the risky decision; vendor activation, ERP/purchasing setup, and payment-profile preparation proceed.
  4. The evidence is corrected and becomes HOLD.
  5. Six affected reversible protected actions are rolled back.
  6. Five unrelated safe actions remain executed.
  7. The irreversible payment transmission is invalidated and cannot execute under stale authority.

Those 6/5 counts are properties of this fixed public workflow, not customer-productivity claims.

Why this matters

Traditional approval flows mostly answer a point-in-time question: did a person approve this? Long-running agents create a harder one: does that approval still authorize downstream work after the evidence underneath it changes?

Authority Cut turns correction into execution semantics rather than another audit note. It can invalidate stale authority, compensate only affected reversible descendants, preserve valid unrelated work, and fail closed before an irreversible financial action.

The public banking workflow uses synthetic/reference effects for safe judging. It creates no external vendor record and moves no real funds.

BANK-ECP → Authority Cut

The public integration is deliberately small and real rather than merging an entire benchmark platform into the demo:

Regulatory evidence
→ sanitized BANK-ECP evidence gate
→ PASS / HOLD + reasons
→ human vendor-risk decision
→ Strands agent proceeds only with recorded authority
→ evidence changes PASS → HOLD
→ stale authority invalidated
→ affected reversible work undone
→ safe work preserved
→ first payment blocked

The public bridge uses a development-only DORA third-party-risk fixture with source locator Regulation (EU) 2022/2554, Article 28(1)(a). It is explicitly DEVELOPMENT_ONLY and is not formal BANK-ECP held-out benchmark evidence or a model-performance result. Model confidence never creates human authority.

Strands Agents is load-bearing

The public judge path executes a real Strands SDK Agent loop. Its model-callable tool surface is exactly:

  • execute_safe_vendor_work
  • get_authority_cut
  • execute_authorized_vendor_work

There is deliberately no model-callable approve, revoke, or evidence-correction tool. Human authority mutation remains outside the model tool surface.

The public Vercel route uses a deterministic custom Strands Model provider so the complete tool loop is reproducible without judge credentials. The current public request therefore does not claim a foundation-model or AgentCore invocation.

AWS depth

Authority Cut also has separate, preserved AWS acceptance evidence beyond the credential-free public route.

Native Amazon Bedrock / Nova Lite: on September 1, 2026, an owner-authenticated AWS CloudShell acceptance executed the Authority Cut Strands workflow with native Amazon Bedrock in eu-central-1 using the eu.amazon.nova-lite-v1:0 inference profile. The direct Bedrock Runtime Converse probe and the full model-backed Strands workflow passed. The model still received only the same three non-authorizing tools.

Amazon Bedrock AgentCore Runtime: on August 23, 2026, Authority Cut was deployed to AgentCore Runtime in eu-central-1; a real InvokeAgentRuntime call returned HTTP 200 and passed the Strands-loop and authority/correction assertions. That historical AgentCore run used the deterministic custom Strands provider, so its historical foundation-model status remains UNVERIFIED. The later native Bedrock acceptance is a separate execution path.

Full evidence is public in the repository.

What is new here

Authority Cut does not claim to invent human-in-the-loop workflows, interrupt/resume, revocable authorization, dependency graphs, or compensation in general.

The project combines them around a narrower problem: compute the currently actionable policy-defined human authority surface, keep authority mutation outside the model toolset, bind human authority to the evidence available at the decision point, and propagate a later evidence correction or human revocation through already-executed reversible descendants without erasing unrelated valid work.

The original controlled workflow also demonstrates the underlying Authority Cut mechanism:

7 protected effects
→ 3 semantic human authorities
→ 6 reversible descendants rolled back after correction
→ 5 unrelated safe actions preserved
→ irreversible transmit invalidated

The 7 → 3 result is scoped to that controlled workflow; no generalized productivity or ROI claim is made.

Public engineering evidence

Repository:

https://github.com/evidencebound/evidencebound-authority-cut

The repository contains the source, Apache-2.0 license, setup instructions, tests, public CI, architecture, prior-art review, pre-existing-work disclosure, BANK-ECP bridge boundary, Bedrock acceptance evidence, AgentCore acceptance evidence, and Judge Pack.

Machine-readable live surfaces include /health, /api/tool-boundary, /api/evaluation, and /api/strands-proof-get.

Builder.aws bonus posts

Pre-existing-work disclosure

Pre-existing EvidenceBound concepts include provenance/evidence binding, dependency graphs, fail-closed verification, selective invalidation/recovery, and proof receipts. This AWS competition repository, vendor-onboarding graph, Authority Cut mechanism, Strands orchestration, evaluation, AgentCore adapter, public banking judge service, and sanitized BANK-ECP bridge implementation were created during the submission period. No source file from EvidenceBound Core, Recovery Mesh, Verified Memory, DataHub Gate, or SignalReview was copied into this project.

Explicit limitations

Authority Cut does not claim legal authorization, regulatory certification, correctness of every regulatory interpretation, safe compensation in arbitrary external systems, authenticated production end-user identity, generalized productivity improvement, formal BANK-ECP model superiority, or a solution to alignment/corrigibility in general.

Built With

  • amazon-bedrock-agentcore
  • fastapi
  • github-actions
  • pydantic
  • python
  • strands-agents-sdk
  • vercel
Share this project:

Updates

Submission history