Inspiration: A first-time franchise buyer may risk years of savings while evaluating marketing brochures, disclosure documents, lender estimates, lease terms, emails, and verbal promises. Important contradictions can be buried across hundreds of pages, while professional reviews are often expensive and happen late in the process. I built SuperShield — The Human Decision Firewall to explore a different role for AI: not making the final decision, but performing the exhausting investigation that should happen before it. The guiding principle is simple: SuperShield performs the investigation. The human keeps the decision.
What it does: SuperShield is an agentic due-diligence system for first-time franchise buyers. Users select a curated synthetic case, define their financial constraints, and start an investigation. SuperShield then:
- Creates an investigation plan.
- Extracts claims with document and page citations.
- Identifies contradictions and unsupported statements.
- Calculates fees, required investment, financial runway, break-even scenarios, and downside exposure using deterministic tools.
- Detects missing evidence and refuses to invent conclusions.
- Generates precise follow-up questions.
- Pauses at a human-approval checkpoint.
- Selectively reruns affected tasks when new evidence is approved.
- Produces an auditable Decision Packet containing findings, risks, calculations, citations, unresolved questions, and recommended expert reviews. Its conclusions are deliberately limited to:
- READY_FOR_EXPERT_REVIEW
- MORE_EVIDENCE_REQUIRED
- MATERIAL_RISK_IDENTIFIED SuperShield never signs agreements, transfers money, purchases anything, or claims to replace a lawyer, accountant, or financial adviser.
How we built it: The investigation workflow is orchestrated using the Strands Agents SDK. A supervisor coordinates several focused responsibilities:
- An evidence workflow extracts claims and preserves provenance.
- A skeptic searches for contradictions and unsupported assumptions.
- Deterministic Python tools perform financial calculations instead of relying on language-model arithmetic.
- A validator enforces the rule: no evidence, no material conclusion.
- A human checkpoint prevents the workflow from continuing with new evidence without approval. The public demonstration contains 12 synthetic cases, including contradictory disclosures, omitted recurring fees, lease risks, missing information, and adversarial instructions hidden inside documents. Document content is always treated as untrusted data. The application uses:
- React, TypeScript, and Vite for the interface.
- A Python API for cases, runs, approvals, and decision packets.
- Server-Sent Events for the live investigation timeline.
- Strands Agents SDK for orchestration and tool use.
- Ollama with a quantized Qwen3 8B model for inference.
- Docker and Nginx for application packaging and routing.
- Caddy and Let’s Encrypt for browser-trusted HTTPS.
- Amazon EC2 for the live application.
- AWS CloudFormation for reproducible infrastructure.
- AWS Systems Manager for operations without exposing SSH.
- Amazon EventBridge and AWS Lambda for automatic teardown. The complete implementation, tests, fixtures, infrastructure, and documentation are available in the public repository.
Challenges we ran into: The largest design challenge was keeping the system helpful without letting it become an automated investment adviser. I addressed this with constrained outcomes, mandatory citations, deterministic calculations, explicit uncertainty, and human approval before consequential workflow transitions. Prompt injection was another important challenge. One synthetic document contains instructions attempting to override the agent. SuperShield treats those instructions as evidence content rather than trusted commands, so they cannot modify policies or authorize tools. Deployment also required adaptation. Amazon Bedrock access was temporarily unavailable because of account verification, so I separated model serving from agent orchestration and deployed Qwen3 through Ollama on Amazon EC2. This preserved the real Strands workflow instead of replacing it with a prerecorded simulation. CloudFront creation was blocked by the same account-verification limitation. I implemented trusted HTTPS directly on the EC2 deployment using Caddy, Let’s Encrypt, TLS-ALPN validation, HSTS, and a free sslip.io hostname. Finally, running an agentic workflow on a budget-limited CPU instance required careful model selection, container limits, streaming progress, and realistic expectations for investigation latency.
Accomplishments that we're proud of: I am proud that SuperShield is a working end-to-end agent system rather than a static prototype. The project includes:
- A publicly accessible HTTPS deployment.
- A real Strands multi-agent investigation workflow.
- Evidence-linked findings and deterministic financial analysis.
- Human approval and selective replanning.
- Twelve curated synthetic evaluation cases.
- Prompt-injection and unauthorized-action protections.
- A streamed, auditable run timeline.
- A public Apache-2.0 repository.
- Reproducible AWS infrastructure.
- Automated teardown to control cloud spending.
- A polished interface that requires no login for judging. Most importantly, SuperShield demonstrates that a capable AI system can create value by slowing a high-consequence decision down rather than rushing to produce a confident answer.
What we learned: I learned that trustworthy agents require much more than a strong model. The quality of the workflow depends on how evidence, tools, permissions, uncertainty, and human approval are structured. A fluent answer is not useful if the underlying claim cannot be traced to evidence. I also learned that calculations and language reasoning should be separated. Financial scenarios are calculated by deterministic code, while the model focuses on planning, interpretation, contradiction detection, and explanation. Separating orchestration from model serving made the system more resilient. When the intended managed model service was unavailable, the same agent architecture continued working with a locally hosted model on AWS. Finally, observability is part of the product experience. Showing the investigation plan, specialist progress, evidence, unresolved questions, and approval state gives users more confidence than presenting a single unexplained answer.
What's next for SuperShield — The Human Decision Firewall" The next version will add encrypted persistent case storage, authenticated workspaces, controlled document ingestion, richer location-risk analysis, multilingual decision packets, and secure collaboration with lawyers, accountants, and franchise advisers. I also plan to integrate Amazon Bedrock and Amazon Bedrock AgentCore when account access is available, expand the evaluation suite, benchmark multiple models, and add more evidence-source adapters. The broader goal is to make SuperShield useful wherever a person faces a high-consequence decision involving fragmented evidence, conflicting claims, and substantial personal risk. Live application: https://13.220.29.156.sslip.io/ Source code: https://github.com/alpha-kapex/SuperShield
Built With
- caddy
- cloudformation
- docker
- ec2
- eventbridge
- fastapi
- lambda
- nginx
- ollama
- python
- qwen3
- react
- strands
- typescript
- vite
Log in or sign up for Devpost to join the conversation.