Inspiration
I'm a fractional COO and CHRO. The firms I work with — small consultancies, design studios, nonprofits — don't have an office manager. The owner is the office manager, usually at 11pm.
It's never one task. It's the loop: close out the calendar, type invoices, chase the ones that didn't get paid, sort the bank feed, approve and pay bills, decide whether an inbound email is a client or spam, and remember that the insurance renews Friday. Eight to twelve hours a week, and every piece interrupts the work the owner is actually paid to do.
I had already written an "automated office" operating standard for my clients — calendar structure, booking rules, invoice triggers, a reminder ladder, approval limits. The hackathon was the push to make that standard run.
What it does
Quiet Office is an autonomous back office that runs overnight and talks to the owner only when a real decision is needed.
Every night, a Strands Graph runs six specialist agents in a fixed order: Scheduler → Receivables clerk → Bookkeeper → Payables clerk → Compliance clerk → Digest writer, with a Receptionist handling inbound calls, emails, and chats. Between them they send reminders, close completed events, turn completed work into invoices, run a four-step collections ladder, categorize the bank feed, match deposits to invoices, pay known vendors under $500, route inbound messages, and watch renewal and filing dates 30 days out.
What the rules can't decide on their own goes to one decision inbox with fixed options: pay this first-time vendor $1,450? · this client is 47 days late — payment plan, pause, or write off? · which category is "Blue Heron Supply"? · this guest missed two bookings — pause them? The owner resolves each with one tap, and the office applies the effect.
The result for the owner is one morning message: what happened, and what needs you. Nothing else.
How we built it
Strands Agents SDK end to end. Six specialist
Agents, each with a narrow set of@toolfunctions (25 tools across seven modules) and a plain-language job description.Agents-as-tools. An Office manager agent wraps each specialist as a tool for ad-hoc requests ("book Ava a working session Thursday at 2pm") and owns the decision inbox.
Strands Graph for the nightly close.
GraphBuilderwires the specialists in dependency order so the handoffs are explicit: completed events → invoices → bank matching → payment run → compliance check → digest.Strands hooks as guardrails.
ApprovalGatesubscribes toBeforeToolCallEventand cancels any money-moving tool call unless a human has approved the bill. Because the check runs outside the model, the agent cannot reason its way past it.AuditTraillogs every tool call onAfterToolCallEvent.Policy as configuration. Every number the agents act on — booking window, buffers, daily caps, Net-15 terms, reminder days, the $500 auto-pay limit, category rules, alert thresholds — lives in one file,
rules.py. Onboarding a new client means changing settings, not prompts.Claude on Amazon Bedrock as the default model, swappable to the Anthropic API or a local Ollama model. An Amazon Bedrock AgentCore Runtime entrypoint accepts
{"action": "daily"}so EventBridge Scheduler can run the office unattended.A JSON systems-of-record layer stands in for Google Calendar, Cal.com, QuickBooks Online, the bank feed, and the CRM, so the whole loop runs end to end in the demo. Each table maps one-to-one to a real adapter.
Eight pytest tests, including one that proves the hook blocks an unapproved payment from inside the agent event loop.
Challenges we ran into
Deciding what the agent should not do. The first instinct was to let the model categorize every transaction and pay every bill. The right design turned out to be the opposite: deterministic rules handle the 80% with certainty, and the model's job is orchestration, summarizing, and knowing when to stop and ask. That reframing is what turned "an AI that helps with admin" into "an office you can leave running."
Making safety structural rather than hoped-for. Early on, the payment guardrail was a line in the system prompt. Moving it into a BeforeToolCallEvent hook was the turning point — it became something the agent physically cannot bypass, and something I could write a test for.
Building without a coding background. I'm an operator, not an engineer. I designed the office as an operating standard first — calendars, booking types, invoice triggers, the reminder ladder, approval limits — and then had the code built to that standard, with AI-assisted development. The tests were how I verified the code did what the standard said.
Accomplishments we're proud of
A complete office loop — book → hold → invoice → remind → collect → categorize → pay → close — that runs in one Graph call and ends in a digest a real owner would read. And a guardrail that a test proves the agent cannot talk its way past.
What we learned
Strands makes "autonomous but safe" a property of the architecture rather than of the prompt: hooks for hard limits, Graph for deterministic order, agents-as-tools for delegation. And the decision-inbox pattern — one queue, typed decisions, fixed options, an audit trail — generalizes to almost any back-office domain.
What's next
Real adapters (Google Calendar, Cal.com webhooks, QuickBooks Online, Plaid, Bill.com), a voice front door on Amazon Connect, AgentCore Memory for per-client preferences, and a one-page owner dashboard. Then deployment to the consulting clients the standard was written for.
Built With
- agents-as-tools
- amazon-bedrock
- amazon-bedrock-agentcore
- amazon-web-services
- boto3
- claude
- multi-agent
- pytest
- python
- strands-agents
- strands-graph
Log in or sign up for Devpost to join the conversation.