-
-
1. CareCanopy Overview: CareCanopy workspace for safe delegation in community rehabilitation.
-
2. Architecture: Bounded hybrid architecture: LLM reasoning, deterministic boundary controls, and qualified human clinical authority.
-
3. CLARIFY → ROUTINE: CareCanopy requests targeted clarification when the initial observation is too ambiguous to route safely.
-
4. Scope Boundary → ESCALATE: A request outside the delegated rehabilitation scope triggers escalation for qualified human review.
-
5. Independent PT Review: Independent PT review: 17/18 final routing agreement and 10/10 reviewer-escalation cases captured.
Inspiration
In 2017, with a background in physical therapy, I participated in a digital health project in Maheshkhali, Cox's Bazar, Bangladesh.
That experience left me with a question that stayed with me:
When specialist capacity is limited, what can be safely delegated — and what must return to a qualified professional?
CareCanopy grew from that question.
The project does not assume that more AI autonomy is always better. Instead, it explores how an AI agent can help extend specialist reach while preserving clear clinical boundaries.
The Bangladesh experience is personal project context from 2017 and is not presented as a representation of current conditions or as a CareCanopy deployment site.
What it does
CareCanopy is a bounded AI agent for task-shared community rehabilitation follow-up.
It is designed for situations where a qualified rehabilitation professional has already assessed the patient and approved a rehabilitation plan, while trained frontline workers support routine follow-up.
CareCanopy routes each follow-up into one of three pathways:
- ROUTINE — the task remains within delegated scope and can continue under the existing specialist-approved plan.
- CLARIFY — the report is too ambiguous to route safely, so the agent asks for the minimum missing observation that could change the decision.
- ESCALATE — the case requires qualified human review because of a clinical concern or because the requested action exceeds delegated scope.
The core principle is:
Handle the routine. Clarify the uncertain. Escalate the clinical.
CareCanopy also supports proactive workflow initiation. Amazon EventBridge Scheduler can create an overdue rehabilitation follow-up task before a frontline worker manually creates one.
The system deliberately separates interpretation from authority.
The language model may interpret an observation and propose a route, but selected hard safety and scope boundaries are enforced outside the model, and qualified humans retain clinical authority.
How we built it
I built CareCanopy as a solo MVP using a deliberately bounded hybrid architecture.
Agent reasoning
The Strands Agents SDK orchestrates structured routing reasoning using Amazon Bedrock.
The model receives a frontline rehabilitation observation and returns a structured proposal such as:
- ROUTINE
- CLARIFY
- ESCALATE
It can also identify the minimum missing information required for a clarification step.
Deterministic boundary controls
After LLM reasoning, Python-based deterministic controls enforce selected high-confidence safety and authority boundaries.
Examples include:
- requests to progress exercise type, intensity, load, or frequency,
- medication decisions,
- new diagnosis,
- bypassing required specialist review,
- falsifying observations,
- and selected urgent medical triggers.
This means the LLM cannot independently authorise actions outside the delegated scope.
Workflow state
Amazon DynamoDB stores workflow state, review status, clarification history, escalation information, and audit data.
Proactive workflow
Amazon EventBridge Scheduler is used to create an overdue follow-up task automatically.
EventBridge does not generate clinical observations or diagnose deterioration. It simply initiates the workflow; the frontline worker still provides the clinical observation.
Human authority
The current Strands agent intentionally has no state-changing clinical tools.
The model may interpret and propose, but it does not grant itself clinical authority.
State-changing workflow actions occur only after the selected boundary controls, and cases requiring professional judgement are routed back to a qualified human.
A production extension could externalise authorisation using Amazon Bedrock AgentCore Gateway and Policy.
Prototype interface
The workflow is demonstrated through a Streamlit interface.
The current prototype is run locally, with complete source code and reproducibility instructions available in the public GitHub repository.
Challenges we ran into
The hardest problem was not making the agent more autonomous.
It was deciding where autonomy should stop.
A rehabilitation follow-up can contain ambiguity, incomplete descriptions, requests that exceed delegated scope, and observations that may require professional review.
Using only an LLM would make the workflow flexible, but would place too much authority in probabilistic reasoning.
Using only deterministic rules would make natural-language interpretation brittle.
CareCanopy therefore combines the two:
LLM reasoning for ambiguity + deterministic controls for selected hard boundaries + qualified human clinical authority.
Another challenge was evaluating the system without modifying it after seeing external clinical labels.
To reduce that risk, I finalised the protocol, froze the agent in Git, executed the benchmark, and tagged the frozen outputs before external physical-therapist labels were compared with the system.
One implementation limitation also became visible during evaluation: lexical deterministic rules can themselves be brittle. That reinforced an important lesson — deterministic does not automatically mean correct. The boundary layer must also be carefully designed, tested, and audited.
Accomplishments that we're proud of
The CareCanopy core MVP was built in a three-day solo development sprint.
During that sprint, the project moved from a delegation and safety protocol to a working AWS agent workflow with:
- Strands-based structured reasoning,
- Amazon Bedrock interpretation,
- clarification and re-routing,
- selected deterministic safety boundaries,
- DynamoDB workflow persistence,
- proactive EventBridge task creation,
- a Streamlit interface,
- frozen synthetic benchmarking,
- adversarial boundary probes,
- and independent external physical-therapist review.
The frozen benchmark contains 18 synthetic cases.
Results:
- 18/18 benchmark cases executed successfully
- 0 runtime errors
- 5/5 selected deterministic boundary probes passed
- 17/18 final ROUTINE-vs-ESCALATE decisions agreed with one independent physical therapist
- CareCanopy captured 10/10 cases that the reviewer judged should be escalated
The single coarse disagreement was a case the reviewer judged ROUTINE that CareCanopy escalated.
These results are prototype evaluation on synthetic cases, not prospective clinical validation and not evidence of real-world clinical effectiveness.
What we learned
The most important lesson was that healthcare-agent design is not only about what an AI system can do.
It is also about defining:
what it is allowed to do, what it should ask, and when it must return control to a qualified human.
I also learned that clarification can be an important agent action in its own right.
An ambiguous report does not always require an immediate guess or an immediate escalation. Sometimes the safest and most efficient action is to request one targeted observation and then re-route the same case.
The evaluation process also reinforced the importance of freezing system behaviour before reviewing external labels. That makes disagreements more informative because they reveal limitations rather than inviting post-hoc tuning.
Finally, the project showed that deterministic safeguards should not be treated as infallible. They provide useful boundaries, but they also require explicit testing and transparent failure analysis.
What's next for CareCanopy
The next step is not to give the model more clinical autonomy.
It is to strengthen the boundary around appropriate delegation.
Future work would include:
- evaluation with multiple independent clinicians,
- broader rehabilitation scenarios,
- prospective workflow testing,
- stronger authentication and authorisation,
- integration with locally approved clinical systems,
- configurable jurisdiction- and institution-specific delegation policies,
- external policy enforcement through Amazon Bedrock AgentCore Gateway and Policy,
- and evaluation of whether the workflow can reduce unnecessary specialist workload without increasing missed escalations.
The long-term goal is:
More specialist reach without unsafe clinical autonomy.
CareCanopy is designed to help frontline workers handle appropriate routine follow-up while preserving scarce specialist attention for the cases that truly require professional judgement.
Built With
- agents
- amazon-web-services
- bedrock
- boto3
- dynamodb
- eventbridge
- healthcare
- pydantic
- python
- strands
- streamlit
Log in or sign up for Devpost to join the conversation.