Inspiration
What it does
Inspiration
AI agents are becoming capable of taking consequential actions, but capability is not the same as authority. Call-E started from a simple question: how does an agent prove it is actually allowed to do what it is about to do? We wanted authority to be explicit, bounded, inspectable and enforced at runtime rather than buried inside prompts or assumed from access.
What it does
Call-E is an authority-aware verification layer for agentic systems. Before an action proceeds, it evaluates the requested action against the authority available to the agent and produces a clear decision. Authorised actions can proceed; ambiguous or excessive actions are challenged or refused. The result includes evidence and a traceable explanation of why the decision was made.
How we built it
We built Call-E around a small, explicit authority model rather than relying on model judgement alone. The agent receives the proposed action and relevant authority context, evaluates the boundaries, and returns a structured verification result. The demo is designed to make that reasoning visible: request, authority, decision and evidence can all be inspected rather than disappearing inside an opaque agent loop.
Challenges we ran into
The hardest problem was distinguishing technical capability from legitimate authority. An agent may possess credentials or tools that technically allow an action while still lacking permission to use them for that purpose. We also had to keep the verification layer useful without turning it into a blanket blocker, and make refusals sufficiently precise that another agent or human can understand what needs to change.
Accomplishments that we're proud of
We built a working demonstration of runtime authority verification rather than another prompt-level safety instruction. Call-E makes boundaries operational: authority can be checked before execution, excessive requests can be stopped, and decisions remain explainable afterwards. We are particularly proud that the core idea is small enough to compose with larger agent architectures rather than requiring them to be redesigned around it.
What we learned
Agent safety is not only about whether an action is dangerous. It is also about who authorised it, for what purpose, within what scope, and whether that authority still applies at execution time. Making those questions explicit produces cleaner system boundaries and better evidence when something is refused or escalated.
What's next for Call-E
Next we would extend Call-E from the current demonstration into a reusable authority-verification service for multi-agent systems. That means richer delegated authority, expiry and revocation, chained provenance, policy adapters, stronger audit trails, and integrations that let agents verify authority immediately before consequential tool calls.
How we built it
Challenges we ran into
Accomplishments that we're proud of
What we learned
What's next for Call-E
Built With
- agentcore
- amazon
- amazon-web-services
- bedrock
- claude
- docker
- fastapi
- python
Log in or sign up for Devpost to join the conversation.