KnowFlow - Knowledge-to-Action Agent

"Don't just know. Do."

An enterprise AI agent that retrieves company knowledge, reasons over it, and acts - with human-in-the-loop safety.

The Great Agent Hackathon 2026 ·

  • Track 2: Platform Agent Skills & Knowledge

Inspiration

Enterprise "AI assistants" mostly stop at answering questions. A support agent still has to read the policy, open the CRM, check the order, decide eligibility, and manually perform the refund. The knowledge is there but the action is still human toil.

We wanted an agent that closes that gap safely: one that retrieves company knowledge, reasons over it, and actually does the work, while keeping a human in the loop for anything risky. Hence the tagline: "Don't just know. Do."


What it does

KnowFlow takes a natural-language support request and runs it through a full Knowledge-to-Action pipeline:

  1. Identifies the intent of the request
  2. Searches the company knowledge base for the relevant policy
  3. Retrieves customer / ticket / order context
  4. Reasons over policy + context to decide eligibility
  5. Selects a reusable skill and shows the planned action
  6. Pauses for human approval on sensitive actions
  7. Executes the action through an MCP-style tool layer
  8. Verifies the result actually took effect
  9. Updates the ticket and notifies the customer
  10. Records a complete audit trail

It ships with three live demo scenarios:

Scenario Type Behavior
Duplicate payment refund Sensitive Detects duplicate charge → qualifies → approval gate → refund
Account access change Sensitive Verified-contact rule → approval gate → access upgrade
Technical escalation Low-risk Finds the right specialist → auto-handoff (still audited)

How we built it

A Node.js / Express backend hosts three cleanly separated layers, plus a zero-build vanilla-JS enterprise dashboard.

  • Orchestrator - drives the pipeline, pauses for approval, handles fallbacks
  • Skills layer - 13 reusable, composable capabilities
  • MCP Tool Registry - the single gateway to enterprise capability, enforcing schema validation, scoped authorization, registered-tools-only execution, and the sensitivity/approval gate on every call
  • Mock data - customers, orders, tickets, policies, employees (roles→scopes)
  • Dashboard - polls run state and animates the workflow timeline, approval gateway, and audit trail

The key design decision: skills are thin wrappers over MCP tools. You can add a skill or swap a mock tool for a real Freshworks/Stripe API without touching the orchestrator.

Deployed on AWS. The app is containerized and shipped to AWS App Runner from an image in Amazon ECR, with credentials in AWS Secrets Manager and logs in CloudWatch - a single managed service with a public HTTPS endpoint, TLS, and autoscaling, at roughly $19/month. We priced the full production shape (ECS Fargate + ALB + ElastiCache Redis + DynamoDB) on the AWS Pricing Calculator before deploying, then chose App Runner as the lean, same-code path for the demo.


Challenges we ran into

  • Human-in-the-loop pause/resume. Designing the pipeline so it could stop mid-run and resume cleanly after approval or rejection without losing state or double-executing took the most care.
  • The security boundary. Ensuring secrets live only in the tool layer and never reach the model or browser, and that the agent physically cannot call an unregistered tool or execute a sensitive action without explicit approval.
  • Keeping skills thin over tools. Deliberate discipline so the mocks can later become real Freshworks/Stripe calls without touching the orchestrator.

Accomplishments that we're proud of

  • A genuinely working end-to-end agent, not a demo shell — every scenario runs intent → knowledge → context → decision → skill → approval → action → verify → audit, verified through both the API and the UI.
  • An MCP tool layer that enforces real security guarantees (schema validation, scoped authorization, sensitivity gating).
  • A dashboard that makes the agent's orchestration visually obvious - it clearly reads as an enterprise agent that acts, not a chat clone.

What we learned

The biggest leverage in an "agent that acts" isn't the model — it's the boundary around it. Putting validation, authorization, sensitivity, and approval in one registry meant safety came for free everywhere. We also learned that separating skills from tools is what makes the system extensible: add a skill or swap a mock for a real API without touching the orchestrator.


What's next for Knowledge-to-Action Agent

  • Replace the rule-based planner with an LLM that emits a tool plan validated against the same registry (structured tool-calling).
  • Expose the registry over the real MCP protocol so external agents can reuse the authorized, validated gateway.
  • Swap mock handlers for live Freshworks / Stripe / CRM integrations.
  • Scale the live AWS deployment from single-instance to stateless multi-instance by moving sessions to ElastiCache Redis and the audit log to DynamoDB.
  • Add a durable, tamper-evident audit store and persistent sessions.
  • Role-based approval routing (manager sign-off above thresholds — the rule already exists in refundRules.managerSignOffThreshold).
  • Streaming updates over WebSocket instead of polling.

Tech stack

  • Node.js ·
  • Express ·
  • MCP-style tool registry ·
  • vanilla JS dashboard ·
  • JSON mock data ·
  • zero build step ·
  • Docker ·
  • AWS App Runner ·
  • Amazon ECR ·
  • AWS Secrets Manager ·
  • Amazon CloudWatch.
Share this project:

Updates

Submission history