Inspiration

AI agents are increasingly capable of recommending actions, but in physical operations the difficult question is not whether a model can suggest what to do. It is whether that suggestion should actually be allowed to become a real-world consequence.

GroundPatrol explores that boundary in coastal operations, where changing conditions such as people entering an operating area, access restrictions, habitat constraints, stale evidence or deteriorating weather can turn a reasonable action into one that should stop.

What it does

GroundPatrol is a governed coastal-operations agent for professional teams coordinating shoreline inspection and debris collection.

A Strands agent interprets the patrol objective and proposes a bounded action. GroundPatrol then separates reasoning from authority:

OBSERVE → FREEZE SNAPSHOT → PROPOSE → AUTHORISE → VERIFY → DISPATCH / ESCALATE → RECEIPT

The observed state is frozen into a content-addressed snapshot. Deterministic runtime controls evaluate the proposed action against freshness, access, habitat, people-presence, weather and action limits.

The gate returns one of four outcomes:

  • APPROVE
  • CONDITIONAL
  • DEFER
  • DENY

Only an approved and independently verified decision can create a collection work order.

The demo shows the same operational objective twice. With a clear operating envelope, GroundPatrol approves the bounded action and creates a work order. When a person enters the operating envelope, the system instead returns DEFER and refuses dispatch.

The important behaviour is not merely that the agent warns the operator. The execution boundary enforces the decision.

How I built it

GroundPatrol uses the Strands Agents SDK with Amazon Bedrock for the agentic reasoning loop.

The governance layer is implemented in deterministic Python rather than delegated back to the language model. Each decision is tied to the exact observed state through a content-addressed snapshot and recorded in a tamper-evident SHA-256 receipt.

A deterministic finalizer checks that the agent's claimed next action is consistent with the authorised decision. The dispatch adapter then independently verifies the receipt before creating an idempotent collection work order.

The operator experience is implemented in Streamlit, showing the agent outcome, decision receipt and work-order state side by side.

GroundPatrol also includes deterministic fixture scenarios for reproducible judging, optional live weather observations, automated tests, execution tracing and an Amazon Bedrock AgentCore Runtime entrypoint.

Challenges

The main challenge was designing an agent that remained useful when it was not allowed to act.

It is easy to build an agent that produces a recommendation. It is harder to ensure that changing evidence actually changes what the system is permitted to do, and that an unsafe or contradictory model response cannot bypass that restriction.

Another challenge was keeping the demo honest about its evidence. Access, habitat, people-presence and debris data are explicitly labelled synthetic inputs. Optional live weather observations do not cause synthetic operational facts to be presented as real sensor data.

What I learned

The project reinforced that reliable agentic systems need an explicit boundary between intelligence and authority.

For consequential workflows, model reasoning can remain flexible while action permissions are narrow, deterministic and independently verifiable.

The core principle became:

Model proposes. Governed control decides. Evaluator checks. Trace records.

What's next

A production version would replace the local work-order adapter with the coastal team's work-management or robotic dispatch system while preserving the same governed action boundary.

The same architecture can also generalise beyond coastal operations to inspection, maintenance, logistics and other professional environments where agents need to reason flexibly without silently granting themselves operational authority.

Built With

Share this project:

Updates

Submission history