Inspiration

Standby Agent was inspired by a simple question: what should an AI agent be allowed to do when a person is temporarily unavailable?

Most personal assistants either only give advice or ask for too much trust. I wanted to explore a safer middle ground: an agent that can keep routine obligations moving, but still respects human authority for important decisions.

What it does

Standby Agent acts as a personal continuity agent for a seven-day absence window.

It can handle low-risk routine tasks such as rescheduling an appointment, pausing a delivery, or forwarding a school form to an authorized delegate. When an action has higher impact, such as cancelling a hotel reservation worth €684, the agent cannot execute it alone and requires explicit human approval.

It also blocks forbidden actions, such as bank transfers, and isolates untrusted external instructions so prompt-injection style messages cannot expand the agent's authority.

How I built it

The project is built with Strands Agents and uses Amazon Bedrock as the model provider for the demo. The backend is a Python FastAPI service that exposes the continuity state, policy decisions, and approval actions. The frontend is a React/Vite dashboard designed to show the agent's decisions clearly.

The core safety model is deterministic: every event is classified as AUTO, ASK, BLOCK, or SECURITY before the agent can act. The agent can execute only the tools that match the authorized policy decision.

What I learned

I learned how important it is to separate agent reasoning from authority. The language model can help interpret and recommend, but it should not decide its own permissions.

I also learned how to design a human-agent workflow where autonomy is useful without becoming unlimited. The most important part of the project is not that the agent acts, but that it knows when not to act.

Challenges

The biggest challenge was making the demo feel like a real product while keeping the safety boundaries easy to understand. I wanted the dashboard to show a clear transformation: routine tasks handled automatically, risky actions escalated, unsafe requests blocked, and value protected only after human approval.

Another challenge was integrating Strands with a local-first workflow while also supporting Amazon Bedrock for the hackathon demo.

Built With

Share this project:

Updates

Submission history