Build log: from spike to submitted
The project started with one question: can an agent handle a full production workflow while proving it never changed the shop without human approval?
The spike. Real Strands tools, a BeforeToolCallEvent interrupt, and a SQLite audit chain. Rejection left revision 1 with zero writes; approval applied the exact reviewed hash once. Then the hard part: making that approval survive process death. A fresh process restores the session, re-verifies the checkpoint, and submits the official interruptResponse.
The judged provider. Both paths ran live on Amazon Bedrock with Nova Lite. The same scenario produces the same canonical proposal hash across deterministic, Bedrock, and Ollama backends, because deterministic code owns every shop fact and the model only extracts.
The demo. A localhost judge-facing interface showing the tool trail, the proposal, the interrupt, and the audit chain. Deterministic model, no credentials needed.
Deployment. The same workflow deployed to Bedrock AgentCore Runtime behind start and decide invocations, with committed evidence of rejection and approval in separate runtime processes.
Submitted. Video, architecture, testing instructions, and three builder.aws posts are all public.
114 tests, current main CI green, Apache-2.0. The repo has the full evidence trail.
Log in or sign up for Devpost to join the conversation.