Inspiration

Before writing any code, I read the hackathon's own framing — run autonomously, surface only for a real decision — and then went through as many public submissions as I could find. One pattern showed up everywhere: every agent had exactly one principal. Whatever the interrupt gated, it was always "should I proceed with this action for you."

Nobody had built something where the agent has to stay trusted by two people who don't trust each other. That's the actual shape of a common, unglamorous problem: ex-partners arranging childcare, roommates settling a last bill, a tenant and a landlord after a complaint. The two sides usually agree on the substance. What restarts the fight is that every message carries an accusation.

What it does

GoBetween sits between two people as the channel itself. Neither side ever sees what the other actually typed. A party writes exactly what they feel, insults included, and the agent refuses to pass it on as written. It shows the sender precisely what would arrive on the other side and what it stripped out, and only delivers once they approve.

How I built it

Built on the Strands Agents SDK. The mechanic lives inside one tool, deliver_message, which calls tool_context.interrupt() from inside the tool call itself. The interrupt isn't an approval checkpoint on an action — it's a refusal to deliver the user's own message until they've seen the mediated version. list_threads and get_thread just feed context to the model, which does the actual rewriting: instructed to keep every concrete demand (amount, deadline, request) and strip only what would restart the fight.

The UI is a two-panel Streamlit app: raw text on the left, what actually gets delivered on the right, so the gap between the two is visible at a glance.

Challenges I ran into

Most of the real challenges were infrastructure, not agent logic. My AWS account hit an account-level Bedrock restriction that Service Quotas doesn't even surface — the console showed normal per-model quotas (millions of tokens/minute in us-east-1), but every region and every model returned the same throttling error regardless. I switched to Google Gemini's free tier, which worked until I burned through its 20-requests-per-day cap mid-testing and had to fall back again. The model provider ended up fully pluggable behind one environment variable — Gemini, Anthropic, or Bedrock — a decision forced by infrastructure trouble that turned out to be good practice anyway.

What I learned

Strands' interrupt system is more general than the "should I proceed" pattern shown in the SDK's own docs. Nothing stops a tool from using it to withhold something instead of asking permission for it.

What's next

Letting the receiving party reply through the same mediation, so a full back-and-forth is mediated in both directions. Escalation awareness, so a thread gone unanswered for days can get a firmer register instead of an ever-softer one. A shared record both parties can consult, so neither can claim the other never said something.

Built With

Share this project:

Updates

Submission history