-
-
Many agents. One production surface. Human authority stays outside the model.
-
Governed agentic commerce: propose, review, approve, apply, verify — with policy and audit at every step.
-
AI can act across commerce workflows, but CommerceGov controls what is allowed to reach production.
-
External change detected: AWS Authority Companion flags AUTHORITY_AT_RISK and returns it to human Review.
Inspiration
AI agents are becoming capable enough to participate in real production workflows. They can understand intent, inspect context, reason about risk, generate changes, and call tools.
But capability creates a separate question:
Capability is not authority.
A model may be capable of changing production. That does not mean it should be allowed to decide whether that change is authorized.
CommerceGov Authority Agent is built around one principle:
Probabilistic capability should operate under deterministic authority.
The agent can reason, propose changes, assess risk, and recommend actions. Production authority remains outside the model.
What it does
CommerceGov Authority Agent is an AI agent built with the Strands Agents SDK and Amazon Bedrock, connected to CommerceGov's production-authority control plane.
It demonstrates a governed lifecycle for AI-driven commerce changes:
Agent intent → Proposal → Deterministic policy → Human authority → Controlled execution → Production verification
Each stage is intentionally separate.
Capability ≠ Authority ≠ Applied ≠ Verified.
An agent can create a valid proposal without gaining permission to approve it. Human approval does not automatically execute the change. Execution is not considered complete until CommerceGov reads production back and verifies the resulting state.
How it works
The demo starts with a real Shopify product governed by CommerceGov.
A request is sent to an AWS-hosted Strands agent using Amazon Bedrock. The agent interprets the request and creates a CommerceGov proposal for the target shop and product.
The proposal appears in CommerceGov Review.
At this point, the agent has demonstrated capability — not authority.
A second request intentionally violates deterministic shop policy. CommerceGov evaluates the requested mutation and denies it before production execution. Nothing is written to Shopify.
We then ask the agent to approve its own valid proposal. It cannot.
The authorized human reviews and explicitly approves the proposal.
PROPOSE ≠ APPROVE
After approval, execution is still a separate authority transition.
APPROVED ≠ APPLIED
Only after explicit human authorization does CommerceGov's controlled worker execute the exact approved mutation against Shopify.
Finally, CommerceGov reads the product back from Shopify and compares production state with the authorized change.
APPLIED ≠ VERIFIED
The resulting lifecycle is:
PROPOSE → POLICY → HUMAN APPROVE → HUMAN-AUTHORIZED APPLY → READBACK → VERIFY
Detecting changes outside the governed path
CommerceGov also demonstrates what happens when production changes outside the approved workflow.
The same product is edited directly in Shopify. CommerceGov receives the production event and detects the divergence.
The AWS Authority Companion evaluates the change and can surface an authority-risk state such as:
AUTHORITY_AT_RISK HUMAN_AUTHORITY_REQUIRED AUTONOMOUS_PROCESSING: STOP
The companion explains the detected risk and recommends what should be reviewed next, but it does not grant itself production authority.
This allows CommerceGov to govern both intended agent actions and production changes that bypass the governed path.
Architecture
The AWS implementation separates probabilistic reasoning from deterministic authority.
It uses:
- Strands Agents SDK for agent orchestration
- Amazon Bedrock for model reasoning
- AWS Lambda for the agent runtime
- Amazon API Gateway for agent endpoints
- Amazon DynamoDB for run state and supporting evidence
- CommerceGov Authority Kernel for deterministic policy and authority decisions
- CommerceGov Review Workspace for human review and authorization
- Shopify as the production commerce system
The model is inside the reasoning path, but outside the final production-authority boundary.
Why this matters
As agents become more capable, giving them more tools is easy.
The harder questions are:
Which actions may they propose? Which actions may continue? Which require deterministic policy? Which require human authority? Who may authorize production execution? How do we prove what was proposed, approved, applied, and verified?
CommerceGov treats these as authority-system problems rather than model-behavior problems.
The most dangerous agent may not be an incapable agent. It may be a highly capable agent that successfully executes the wrong production action.
What makes it different
CommerceGov does not treat human-in-the-loop as a single approval button.
Authority is represented as explicit state transitions:
Capability → Proposal → Policy eligibility → Human authority → Execution → Production mutation → Verification
Each transition can stop independently and produce evidence.
The agent cannot collapse those stages into one autonomous production action.
What we learned
Operational AI safety cannot depend only on asking a model to behave safely.
Models are valuable because they are probabilistic and flexible. Production authority requires different properties: deterministic constraints, explicit state, identity, role boundaries, policy evaluation, controlled execution, and verification.
CommerceGov separates those responsibilities.
The model reasons. The authority system determines what may progress. The human provides production authority where required.
What's next
The current implementation demonstrates this authority boundary on a real Shopify workflow.
The next step is to extend the same model across additional mutation classes, stores, agents, and commerce systems.
The long-term objective is a production-authority control plane where multiple AI systems can operate through one governed boundary without each agent receiving unrestricted credentials or independent production authority.
Capability is not authority.
Probabilistic capability operates under deterministic authority.
Built With
- 2.0
- 4.6
- agents
- amazon
- amazon-web-services
- api
- bedrock
- claude
- commercegov
- dynamodb
- gateway
- iam
- lambda
- manager
- oauth
- pkce
- python
- rest
- sdk
- secrets
- shopify
- sonnet
- strands

Log in or sign up for Devpost to join the conversation.