Inspiration
Small nonprofits often manage grant evidence across receipts, spreadsheets, signed rosters, service logs, and survey summaries. Preparing a report becomes a manual reconciliation task, while a plausible narrative alone cannot prove that every obligation was actually met.
We built ProofPack around a simple principle: evidence before assertion. An AI agent should reduce administrative work without inventing missing proof or silently approving an unsupported claim.
What it does
ProofPack turns grant obligations and source records into an audit-ready evidence package. It:
- maps each obligation to supporting records;
- validates dates, thresholds, record types, and verification status;
- identifies missing or unverified evidence;
- produces JSON, Markdown, HTML, and CSV outputs;
- creates a SHA-256 evidence manifest for integrity checking;
- sends only genuine blockers to a human decision inbox; and
- refuses to fabricate evidence or treat an absent record as proof.
The representative scenario contains two ready requirements, one requirement awaiting source verification, and one blocked by a missing survey summary. That blocked result is intentional and demonstrates ProofPack’s fail-closed behavior.
How we built it
ProofPack uses the Strands Agents SDK for planning and bounded tool use. The agent can inspect grant requirements, inspect evidence metadata, and invoke a deterministic Python validation engine.
The validator—not the language model—owns numeric comparisons, date checks, required-record coverage, and source-verification rules. Document contents are treated as data rather than agent instructions. This hybrid design preserves the flexibility of an agent while keeping compliance checks reproducible and testable.
The full agent path uses the Strands default Amazon Bedrock provider. A deterministic local pilot is also included so judges can reproduce the core workflow without cloud credentials.
OpenAI Codex was used as an AI coding assistant during the contest submission period. The application was created from scratch during that period, and no pre-existing application code was incorporated.
Challenges we ran into
The main challenge was deciding which work should belong to the agent and which work must remain deterministic. Allowing a model to freely infer compliance would make the output difficult to audit. Moving critical checks into code solved that problem while still allowing the agent to coordinate the workflow.
We also needed to make failure useful. Instead of producing a generic error when evidence is incomplete, ProofPack creates a clear decision record explaining exactly what requires human verification or what document is missing.
Accomplishments that we're proud of
- A working Strands tool loop with bounded responsibilities.
- Fail-closed handling of missing and unverified evidence.
- Four generated proof-pack formats plus an integrity manifest.
- Automated coverage of the representative workflow, metric validation, duplicate evidence IDs, generated outputs, and safety behavior.
- A public MIT-licensed repository with installation instructions, architecture documentation, and a reproducible pilot.
- A concise demo that shows both successful checks and intentional human escalation.
What we learned
Reliable agents do not need to automate every decision. They create the most value when they complete routine work independently, preserve a traceable evidence trail, and escalate only the decisions that genuinely require a person.
We also learned that a blocked result can be a successful product outcome when proceeding would create compliance risk.
What's next for ProofPack Agent
Next steps include connectors for common nonprofit record systems, configurable grant templates, controlled document storage, richer approval workflows, and an optional Amazon Bedrock AgentCore deployment. Human review will remain mandatory before any final submission.
ProofPack assists with evidence organization. It does not provide legal advice, certify compliance, or submit reports without human approval.
Log in or sign up for Devpost to join the conversation.