Title
AgentCover — Experimental Bounded-Autonomy Gate for CALL-E Phone Calls
One-line summary (tagline)
A demo safety layer that wraps every CALL-E phone call in least-privilege scope, a budget, and a kill switch — and shows the gating shape a real production agent should sit behind.
What it does
AgentCover CallGate is an experimental, in-memory demo of a bounded-autonomy gate in front of CALL-E phone calls. Every run_call intent is intercepted and run through a small, vendored enforcement layer before a call leaves:
- Binding — the agent is tied to a human owner who is accountable.
- Scope allowlist — only a known verb and known recipient fingerprints are permitted. Deny-by-default; fail-closed.
- Budget — a hard dollar ceiling; over-budget calls are refused.
- Approval — costly or critical calls can require a human sign-off.
- Kill switch — one tap freezes all calls instantly.
- In-memory decision log — every decision is recorded in memory for inspection. This is a teaching artifact, not immutable and not a system of record.
- Demo evidence summary —
insurance.report()summarizes what the demo did (claims_ready=False). It is a demo, not an insurance or claims product.
The demo shows a HIPAA appointment-reminder scheduler shape: a call to a known (masked) patient line is allowed and dispatched through the real CALL-E SDK offline; a call to an unlisted number is blocked before it dials; the kill switch freezes everything; and the in-memory log is summarized.
Scope of this demo: ✅ shows the gating shape; ✅ calls the real calle-ai SDK at runtime (offline via MockTransport); ✅ 7/7 tests pass. ❌ Not a production system of record. ❌ Not claims-ready. ❌ Not an insurance product.
How we built it
- CALL-E SDK (
calle-ai) — the gateway imports the official client and callsCalleClient.calls.create_and_wait(...)at runtime. In the default offline mode it injects anhttpx.MockTransportunder the real client, so the exact SDK request (idempotency header, recipients, result schema) is built and polled to a terminal state with zero network and no real call placed — the same honest verification pattern the repo's ownkeptandconsent-gateapps use. - Vendored enforcement engine (
agentcover_callgate/_engine.py) — a small, faithful subset of github.com/TheDub-lab/safety-protocol, vendored into the app so it runs from a clean checkout with no external path hacks. The audit trail and gating state are in-memory and experimental. - calle-ai, httpx, pytest — minimal deps; the demo and tests run offline.
- Demo video — rendered from real gate output (PIL frames + ffmpeg), 1280×720, with voiceover. 47s.
Safety / correctness notes
- Official-origin only. Live (credential-bearing) CALL-E requests are restricted to
https://api.heycall-e.com; a custom orhttp://base URL is rejected. - Strict E.164. Every live recipient is validated as strict E.164 (
++ 1–15 digits) before dispatch. - PHI discipline. Recipient numbers are masked in fixtures and SHA-256 fingerprinted at the scope boundary; they never enter logs in plaintext.
Challenges we ran into
- Safety without friction. A gate that blocks everything is safe but useless. We landed on deny-by-default with an explicit allowlist of verbs + recipient fingerprints, so the common case (known line) flows and the dangerous case (unknown number) is stopped cold.
- Proving the SDK is really called. Judges need runtime usage, not a reference. The MockTransport lets the real clie## Inspiration
Built With
- httpx
- pytest
- python
Log in or sign up for Devpost to join the conversation.