Inspiration
Hotel shift handovers are full of copied notes, unresolved maintenance items, guest requests, and exceptions with no clear owner. A summary can make the list shorter, but it does not make the next shift safer. HandoverGuard converts operational noise into accountable work while preserving human authority over safety, compensation, payments, and guest contact.
What it does
HandoverGuard sends a synthetic bilingual hotel shift through a visible AWS execution pipeline. Amazon Nova Lite extracts canonical issues; deterministic policy creates routine internal work while safety, financial, compensation, and guest-contact actions become genuine AWS Step Functions approval waits. A judge can approve or reject them in the public console and watch the managed-service trace update.
The scenario demonstrates five raw notes:
- two Arabic and English reports of the same electrical burning smell, merged into one canonical safety incident;
- a towel request, converted into a safe internal task;
- a SAR 250 room charge, held for financial approval;
- a prompt-injection instruction that is ignored and never becomes an action.
Approval does not silently contact a guest, move money, or close an incident. It creates an owned follow-up task. Rejection leaves the proposed action blocked.
How we built it
- Amazon CloudFront serves the public judge console over HTTPS.
- Amazon API Gateway validates synthetic submissions, applies throttling, and allocates run IDs.
- Amazon S3, EventBridge, and SQS preserve raw input, create managed events, and isolate retries through a dead-letter queue.
- Amazon Bedrock AgentCore Runtime hosts the Python supervisor built with Strands Agents SDK.
- Amazon Bedrock Guardrails inspects input before Amazon Nova Lite performs bilingual, schema-validated extraction and deduplication.
- AgentCore Gateway exposes only narrow MCP tools backed by AWS Lambda. There is no send, charge, refund, resolve, or guest-contact tool.
- Lambda policy independently decides autonomous versus human work, so the model cannot grant itself authority.
- Amazon DynamoDB stores idempotent run state with point-in-time recovery.
- AWS Step Functions callback tokens and Amazon SNS implement genuine human approval waits.
- Amazon S3 evidence packets and CloudWatch/X-Ray preserve proof, latency, and operational telemetry.
- AWS CDK and CloudFormation reproduce the complete 60-plus-resource deployment.
All demonstration data is synthetic. No real guest, employee, or property data is used.
Challenges
The central challenge was making human oversight an enforceable system property rather than a prompt promise. HandoverGuard treats the model as a reasoner, while narrow AWS tools enforce approval gates, idempotency, deduplication, and audit recording.
The first real AgentCore run exposed an incomplete model/tool loop, and a later public run exposed bilingual duplication. We fixed both as server-enforced invariants rather than hiding them with prompt wording. The console now shows service-level evidence, latency, policy decisions, approval waits, and zero external actions.
Accomplishments
- A real AWS-native vertical slice is publicly deployed and testable.
- Five raw bilingual notes become three canonical issues.
- One routine internal task proceeds without unnecessary interruption.
- Compensation and safety actions cannot bypass human approval.
- Prompt injection produces no action.
- Approval and rejection are idempotent and auditable.
- Every state-changing event participates in a verified hash chain.
- Nine adversarial policy probes pass with zero external actions.
- Twenty-five automated tests pass alongside Ruff, strict mypy, TypeScript, CDK synthesis, packaging, and live browser verification.
- The live proof uses AgentCore Runtime, AgentCore Gateway, Bedrock Guardrails, Nova Lite, Step Functions, DynamoDB, S3, EventBridge, SQS, SNS, API Gateway, CloudFront, Lambda, and CloudWatch/X-Ray.
What we learned
Useful human-centered agents need two complementary layers: probabilistic reasoning for interpreting operational context and deterministic policy for authority, side effects, and evidence. Keeping those layers separate makes an agent easier to trust, test, and operate.
What is next
- property-system adapters behind the existing approval boundary;
- role-based approval routing and escalation timers;
- multilingual handovers for international hotel teams;
- signed evidence exports for compliance review;
- operational evaluation across more synthetic shift scenarios.
Built With
- amazon-api-gateway
- amazon-bedrock
- amazon-cloudfront
- amazon-dynamodb
- amazon-eventbridge
- amazon-nova
- amazon-sns
- amazon-sqs
- amazon-web-services
- aws-cdk
- aws-lambda
- aws-step-functions
- bedrock-agentcore
- python
- strands-agents
- typescript

Log in or sign up for Devpost to join the conversation.