Savr - Agents for Humans An autonomous procurement employee that watches your SaaS stack, negotiates renewals inside your policy, and never contacts a vendor without your approval.

Inspiration Every startup leaks money quietly. There's no procurement team, no leverage, no process - just a spreadsheet someone updates when things break. Renewals auto-renew at higher prices. Loom and Veed do the same job and nobody notices. Seats sit empty and get paid for anyway.

I wanted to build the thing we wished we had: an agent that does the work while the human keeps the authority. Not one that quietly acts for you - the opposite. One that flags a problem with evidence, proposes a fix with actual numbers, negotiates only after you approve, and refuses to apply a negotiation that didn't work.

What it does Every run, Savr looks across the whole stack and asks one question about each subscription: is anything leaking? Four signals trigger a flag - a renewal coming up, seats sitting unused, two tools doing the same job, or a price creeping up. If any of them fire, the tool gets flagged.

Most flags are handled automatically - keeping a tool as is, downgrading a plan, cancelling something unused. But the two that matter most always come to you: renegotiating a contract, or switching to a cheaper option. Those need a human to approve first.

Only after you approve does the Negotiator go to work - in strict rounds (i.e 5), with the budget locked in code so it can never promise more than the policy allows.

The demo's numbers aren't a screenshot - they're asserted by an automated end-to-end test. Fourteen subscriptions at $47,400 a year. Notion renegotiated from $10,800 down to $9,840. A Loom overlap switched cleanly. $5,760 a year saved, every single run.

How I built it The brief was clear: the Strands Agents SDK must orchestrate every agent path - never a fallback. That constraint turned into the design.

One Strands agent with two modes - a Guardian that evaluates the stack, and a Negotiator that engages vendors.

Six custom tools give it hands: checking renewals, benchmarking prices, searching alternatives, sending negotiation messages, parsing vendor replies, and checking policy. A guardrail hook runs before any tool call to enforce the blacklist and the price bounds. And every output is validated with a schema - typed, structured, never guessed from free text.

I built a model seam instead of hardcoding one brain: a deterministic in-process model runs the demo so the story is identical every time a judge clicks play, and Amazon Bedrock with Claude Sonnet 4.6 is wired for live runs through the exact same code path. React and Vite power the dashboard, an Express API streams live Guardian progress over SSE, and memory persists to local JSON - with DynamoDB marked as the clear production path.

Challenges I faced The hardest part wasn't the agent - it was access. I pinned the model, granted a least-privilege IAM policy, and still hit "Operation not allowed" on every model available, Anthropic and Amazon alike. I tested IAM credentials and the new Bedrock API-key bearer flow end to end; the account's model access is gated at the account level, and no code could route around it. So I did the honest thing: the demo runs deterministically on the same Strands pipeline, and the live Bedrock path is wired, tested, and documented honestly as gated.

The second challenge was making the demo trustworthy. A demo that can't be re-run in front of someone isn't a demo. Keeping the model injectable meant Strands stayed authentic and the numbers stayed repeatable.

But the real problem I was solving the whole time is trust. An agent that calls vendors on its own is terrifying. So the human gate is the product - the AI proposes, the code validates, and you decide.

What I learned Compromise on the model, never on the orchestrator. Guardrails belong in code, not in prompts. And the most trustworthy autonomous system is the one that knows exactly where its authority ends.

What's next Running this properly on AWS - Bedrock live, EventBridge scheduling, DynamoDB memory, real vendor APIs, and Cognito auth. The seams are all in place. Making it real means integrations, not a rewrite.

The full architecture story lives here on AWS Builder: Agents for Humans: Let an AI Negotiate Your SaaS Renewals While You Sleep - https://builder.aws.com/content/3JHJ8vJOBj1i1b0hmT56AqQ1Mas/agents-for-humans-let-an-ai-negotiate-your-saas-renewals-while-you-sleep

The video demo is here: https://www.youtube.com/watch?v=6kZa1fRCWls

Built With

Share this project:

Updates

Submission history