Inspiration
Agents should not need a human for every step — but they also should not infer their own authority. Doorman explores that boundary for Strands agents:
CAPABILITY != AUTHORITY
A tool can exist without being authorized, an action can be authorized without having enough evidence, and a model saying “done” is not proof that an action executed.
What it does
Doorman is a small policy and evidence layer for Strands agents. Before a registered capability executes, it evaluates the requested action against explicit authority, evidence requirements, and human-approval policy.
The result is one of five typed decisions:
- AUTO_EXECUTE — execute without interrupting a human
- HUMAN_REQUIRED — pause for a specific human decision
- DENIED — required authority is absent
- NEEDS_EVIDENCE — required demonstrated evidence is absent
- AMBIGUOUS — required action input is unclear
The bundled invoice demo makes each branch visible with four deterministic cases: a valid invoice auto-executes, an arithmetic error requires a human, a payment attempt is denied because finance.payment authority is absent, and a missing total is routed to NEEDS_EVIDENCE.
How it works
Doorman integrates with Strands through capability metadata, policy, an AuthorityContext, and lifecycle hooks. If no synchronous human callback is available, HUMAN_REQUIRED uses Strands' native interrupt/resume mechanism rather than inventing a second pause system.
The important separation is:
capability → authority → evidence → decision → execution → receipt
The model may propose an action, but deterministic policy decides whether that action may proceed.
Evidence
Each receipt records the policy decision, authority check, evidence snapshot, execution status, canonical result hash, and receipt integrity hash. verify_receipt() detects mutation of the recorded receipt.
This keeps execution evidence separate from model narrative: a model claiming that an action completed is not treated as execution proof.
Try it
py -m venv .venv
& ".venv\Scripts\python.exe" -m pip install -e ".[dev]"
& ".venv\Scripts\python.exe" -m pytest -q
& ".venv\Scripts\python.exe" "examples\invoice_agent\main.py" --auto
Receipts are written to examples/invoice_agent/receipts/latest.json.
Public source: https://github.com/DannyBaanks/doorman-sdk
Scope
Doorman enforces explicit policy for registered capabilities. It does not claim to be a complete sandbox, IAM system, or proof that a policy is sufficient. The repository includes the architecture, hackathon gate, claim audit, demo script, and pre-existing-work disclosure.
MIT licensed.
Log in or sign up for Devpost to join the conversation.