Inspiration
Capability is not authority.
AI agents are becoming capable of taking increasingly consequential actions: spending money, calling services, interacting with infrastructure, and acting on behalf of people and organizations.
But an agent being capable of an action does not mean it should be authorized to perform it.
That is the problem UCII Guardian addresses.
What is UCII Guardian?
UCII Guardian is a human-governed authority layer for autonomous AI agents, built with the AWS Strands Agents SDK.
Guardian separates six concepts that are too often collapsed together:
Capability ≠ Identity ≠ Authority ≠ Human Policy ≠ Approval ≠ Execution
The language model can reason about and propose an action, but it is not the source of authority. Before consequential execution, Guardian independently evaluates the agent's verified identity, delegated authority, human-defined policy, and—when necessary—an explicit human decision.
The result is a simple principle:
The AI proposes. The authority system decides whether it may act.
The demonstration
Our demo uses a financial spending policy because the consequences are immediately understandable.
A human grants a cryptographically verified Guardian standing authority and sets a $111.02 budget limit.
Guardian then receives several requests:
- A $35 request is within the human-defined policy boundary and can execute autonomously.
- A $150 request exceeds that boundary, so Guardian stops and asks the human. The human chooses Approve Once, allowing only that exceptional request without increasing the standing budget.
- A $175 request also exceeds the boundary. This time the human chooses Deny, and execution is blocked.
- The human then revokes Guardian's delegated authority.
- A subsequent consequential request triggers a fresh authority evaluation and is blocked.
Most importantly, Guardian's cryptographic identity remains verified after revocation.
Same Guardian. Same verified identity. Different authority state — different execution outcome.
Revoking what an agent may do does not require destroying who the agent is.
Judge/Test Mode
Guardian also includes a resettable Judge/Test Mode so the bounded-authority lifecycle can be evaluated repeatedly without modifying production UCII delegated authority.
Important: the demonstration is intentionally scope-bounded. Guardian is not an unrestricted shopping agent. For this hackathon demonstration, delegated authority covers the guardian.purchase.office_supply operation. Being below the Budget Range does not create permission to purchase arbitrary goods or services. Autonomous execution requires both valid delegated operation scope and compliance with the human-controlled policy.
This is deliberate: a $35 office-supply purchase and a $35 arbitrary payment are not equivalent merely because they have the same price. An out-of-scope request is therefore refused by design.
Judge/Test Mode isolates grant, revoke, and reset authority state for repeatable evaluation while keeping Guardian's cryptographic identity verification real. Interactive replay requires a provisioned Guardian identity/custody environment because private signing material is intentionally not distributed in the public repository.
The public repository README contains the exact canonical Judge/Test replay sequence and tests that independently verify the Judge/Test and production isolation boundaries.
Why this matters
Today's autonomous-agent systems increasingly need more than prompt instructions such as "don't spend more than X" or "ask before doing Y."
Those instructions are useful for reasoning, but they should not be the final security boundary for consequential actions.
Guardian makes human intent structurally enforceable outside the language model.
A human can:
- delegate bounded standing authority;
- define a policy boundary;
- approve one exceptional action without silently expanding future authority;
- deny an action;
- revoke delegated authority independently of identity; and
- require fresh authority evaluation before protected execution.
This pattern can extend beyond financial controls to other consequential autonomous operations where identity, delegated authority, policy, approval, and execution need to remain separate.
How we built it
Guardian is a new hackathon project built in Python around the AWS Strands Agents SDK.
Strands provides the agent reasoning layer and request interpretation. Guardian then passes proposed consequential actions through explicit enforcement boundaries rather than allowing model output itself to become authorization.
Guardian integrates with UCII (Universal Cryptographic Identity Infrastructure) for cryptographic identity and authority infrastructure. UCII is pre-existing infrastructure; Guardian itself was built for the Agents for Humans Hackathon, and that prior-work boundary is explicitly documented in the public repository.
The architecture keeps several domains intentionally separate:
- Agent reasoning — AWS Strands Agents
- Cryptographic identity — independently verifiable agent identity
- Delegated authority — what that identity is currently permitted to do
- Human policy — bounded rules such as the spending limit
- Human exception handling — Approve Once or Deny
- Protected execution — execution requires valid authority/approval evidence
- Provenance — records why an action executed or was refused
A particularly important design invariant is that the LLM never grants itself authority.
Challenges
The hardest part was not making the agent more capable. It was making authority precise.
We had to preserve distinctions that become critical once AI agents can cause real-world effects:
- authentication is not authorization;
- authorization is not payment authority;
- approval is not standing permission;
- execution is not evidence of legitimate authority;
- revoking authority is not revoking identity;
- and a previous authorization must not become stale permission for a future action.
That led us to require fresh authority evaluation for consequential operations and to make one-time human exceptions exactly that: one-time exceptions, not invisible expansions of autonomous privilege.
What we learned
The most important lesson was that safer autonomous systems are not created only by improving what models understand.
They also require infrastructure that determines what models are actually allowed to do.
As agents become more capable, the question changes from:
"Can this AI perform the task?"
to:
"Who authorized this agent, for what action, under which policy, for how long, and can that authority be revoked?"
UCII Guardian is our answer to that question.
What's next
Guardian demonstrates a reusable authority architecture for autonomous agents: verified identity, bounded delegation, human policy, explicit exceptions, revocation, fresh authority checks, protected execution, and provenance.
Our goal is an autonomous future in which agents can become more useful without requiring humans to surrender control.
Capability is not authority.
Built With
- ai-agents
- authorization
- aws-strands-agents
- cryptographic-identity
- human-in-the-loop
- post-quantum-cryptography
- python
- strands-agents-sdk
- ucii
Log in or sign up for Devpost to join the conversation.