Inspiration

Agents should not need a human for every step — but they also should not infer their own authority. Doorman explores that boundary for Strands agents:

CAPABILITY != AUTHORITY

A tool can exist without being authorized, an action can be authorized without having enough evidence, and a model saying “done” is not proof that an action executed.

What it does

Doorman is a small policy and evidence layer for Strands agents. Before a registered capability executes, it evaluates the requested action against explicit authority, evidence requirements, and human-approval policy.

The result is one of five typed decisions:

  • AUTO_EXECUTE — execute without interrupting a human
  • HUMAN_REQUIRED — pause for a specific human decision
  • DENIED — required authority is absent
  • NEEDS_EVIDENCE — required demonstrated evidence is absent
  • AMBIGUOUS — required action input is unclear

The bundled invoice demo makes each branch visible with four deterministic cases: a valid invoice auto-executes, an arithmetic error requires a human, a payment attempt is denied because finance.payment authority is absent, and a missing total is routed to NEEDS_EVIDENCE.

How it works

Doorman integrates with Strands through capability metadata, policy, an AuthorityContext, and lifecycle hooks. If no synchronous human callback is available, HUMAN_REQUIRED uses Strands' native interrupt/resume mechanism rather than inventing a second pause system.

The important separation is:

capability → authority → evidence → decision → execution → receipt

The model may propose an action, but deterministic policy decides whether that action may proceed.

Evidence

Each receipt records the policy decision, authority check, evidence snapshot, execution status, canonical result hash, and receipt integrity hash. verify_receipt() detects mutation of the recorded receipt.

This keeps execution evidence separate from model narrative: a model claiming that an action completed is not treated as execution proof.

Try it

py -m venv .venv
& ".venv\Scripts\python.exe" -m pip install -e ".[dev]"
& ".venv\Scripts\python.exe" -m pytest -q
& ".venv\Scripts\python.exe" "examples\invoice_agent\main.py" --auto

Receipts are written to examples/invoice_agent/receipts/latest.json.

Public source: https://github.com/DannyBaanks/doorman-sdk

Scope

Doorman enforces explicit policy for registered capabilities. It does not claim to be a complete sandbox, IAM system, or proof that a policy is sufficient. The repository includes the architecture, hackathon gate, claim audit, demo script, and pre-existing-work disclosure.

MIT licensed.

Built With

Share this project:

Updates

Submission history