Title

AgentCover — Experimental Bounded-Autonomy Gate for CALL-E Phone Calls

One-line summary (tagline)

A demo safety layer that wraps every CALL-E phone call in least-privilege scope, a budget, and a kill switch — and shows the gating shape a real production agent should sit behind.

What it does

AgentCover CallGate is an experimental, in-memory demo of a bounded-autonomy gate in front of CALL-E phone calls. Every run_call intent is intercepted and run through a small, vendored enforcement layer before a call leaves:

  • Binding — the agent is tied to a human owner who is accountable.
  • Scope allowlist — only a known verb and known recipient fingerprints are permitted. Deny-by-default; fail-closed.
  • Budget — a hard dollar ceiling; over-budget calls are refused.
  • Approval — costly or critical calls can require a human sign-off.
  • Kill switch — one tap freezes all calls instantly.
  • In-memory decision log — every decision is recorded in memory for inspection. This is a teaching artifact, not immutable and not a system of record.
  • Demo evidence summary — insurance.report() summarizes what the demo did (claims_ready=False). It is a demo, not an insurance or claims product.

The demo shows a HIPAA appointment-reminder scheduler shape: a call to a known (masked) patient line is allowed and dispatched through the real CALL-E SDK offline; a call to an unlisted number is blocked before it dials; the kill switch freezes everything; and the in-memory log is summarized.

Scope of this demo: ✅ shows the gating shape; ✅ calls the real calle-ai SDK at runtime (offline via MockTransport); ✅ 7/7 tests pass. ❌ Not a production system of record. ❌ Not claims-ready. ❌ Not an insurance product.

How we built it

  • CALL-E SDK (calle-ai) — the gateway imports the official client and calls CalleClient.calls.create_and_wait(...) at runtime. In the default offline mode it injects an httpx.MockTransport under the real client, so the exact SDK request (idempotency header, recipients, result schema) is built and polled to a terminal state with zero network and no real call placed — the same honest verification pattern the repo's own kept and consent-gate apps use.
  • Vendored enforcement engine (agentcover_callgate/_engine.py) — a small, faithful subset of github.com/TheDub-lab/safety-protocol, vendored into the app so it runs from a clean checkout with no external path hacks. The audit trail and gating state are in-memory and experimental.
  • calle-ai, httpx, pytest — minimal deps; the demo and tests run offline.
  • Demo video — rendered from real gate output (PIL frames + ffmpeg), 1280×720, with voiceover. 47s.

Safety / correctness notes

  • Official-origin only. Live (credential-bearing) CALL-E requests are restricted to https://api.heycall-e.com; a custom or http:// base URL is rejected.
  • Strict E.164. Every live recipient is validated as strict E.164 (+ + 1–15 digits) before dispatch.
  • PHI discipline. Recipient numbers are masked in fixtures and SHA-256 fingerprinted at the scope boundary; they never enter logs in plaintext.

Challenges we ran into

  • Safety without friction. A gate that blocks everything is safe but useless. We landed on deny-by-default with an explicit allowlist of verbs + recipient fingerprints, so the common case (known line) flows and the dangerous case (unknown number) is stopped cold.
  • Proving the SDK is really called. Judges need runtime usage, not a reference. The MockTransport lets the real clie## Inspiration

Built With

Share this project:

Updates

posted an update —

hey y'all, Michael here quick update on the AgentCover CallGate submission for CALL-E: Your Code Is Calling

cleaned it up per review — it's now an honest experimental, in-memory demo of a bounded-autonomy gate in front of CALL-E calls (not the overclaimed "production / claims-ready" framing from earlier). what changed:

• runs from a clean checkout — vendored a minimal enforcement engine, no contributor-local path hacks • live calls restricted to the official https://api.heycall-e.com origin; strict E.164 validation on every live recipient • 7/7 tests pass, repo validator green, commits follow the naming conventions

it still calls the real calle-ai SDK at runtime (offline MockTransport, zero network, no billable call) — allow / block / kill-switch / in-memory log walkthrough.

Log in or sign up for Devpost to join the conversation.

Submission history