Inspiration

When someone dies, the people who loved them inherit a second job on the worst week of their life. Not the grief. The admin. Certify the death, pick a mortuary and beat its clock, settle a hospital bill before the body is released. Then months of banks, insurers, pensions, the employer, the subscriptions nobody remembered he was paying.

One family I heard about spent four months just finding the accounts. Another got locked out of every login the day the person who ran the household died. Nobody tells you what comes first, what's urgent, or what can wait. It's worse across borders: he dies in Nairobi, the family wants him buried in the UK, and now repatriation sits on top of everything.

The tools that exist are built for the funeral home's business, or they're a single-country checklist. I wanted one for the person actually making the calls. The next of kin, not a lawyer.

What it does

Umash is one agent for the whole journey after a death, from the pronouncement to closing the last account a year later. It works quietly in the background and only interrupts you when there's a real decision to make.

Routine work like the registration letter, an employer notice, a subscription cancellation, gets drafted quietly and handed to you in one approval. It doesn't nag you thirty times. The weighty calls, settling the hospital bill to release the body, repatriate or bury locally, a benefits claim with a deadline, come one at a time with the tradeoffs laid out.

The plan adapts to where the death happened and where the person is laid to rest (Kenya, the UK, the US, and cross-border repatriation). When the family gives a tradition, it adapts again: a Muslim or Jewish case pulls the funeral to a roughly one-day window. And it never files, pays, or books anything itself. It drafts and waits. Restraint is the point.

How we built it

One agent, built with the Strands Agents SDK on Amazon Bedrock, backed by a deterministic policy layer in plain Python. The model handles ordering and tone. The decisions that matter, what phase a task is in, whether it's routine or weighty, escalate or batch, are code the model can't override.

The agent reaches that policy through six Strands tools. Jurisdictions and faith traditions are data, so adding a country or a tradition never touches the agent. An optional Bedrock Guardrail redacts the decedent's PII on top.

The core runs with no third-party dependencies and no AWS credentials, which is how 19 tests and the offline demo prove the behavior. The same agent deploys to Amazon Bedrock AgentCore, and there's a static web UI that mirrors the policy in the browser.

Challenges we ran into

The "zero-dependency core" claim had a hole. The offline demo imported the agent at the top level, which pulled Strands in, so CI crashed before the offline path could run. I made the import lazy and added a test that runs with the dependency absent.

AgentCore rejected my first container image because buildx attestations are on by default and produce a manifest list, not a single image. Disabling provenance and SBOM fixed it. Invoking the runtime over the CLI then failed with a 400, because the payload is a blob that expects base64, not raw JSON.

The hardest part wasn't infrastructure. It was restraint. Over-escalating every task that touches money or a deadline defeats the whole product, so the classifier is deliberately narrow. A deadline drives urgency ordering, not escalation.

Accomplishments that we're proud of

The safety story is architecture, not a promise in a prompt. Whether a task needs a grieving person's decision is decided in code, and the agent holds no tool that can file, pay, or send. A prompt injection's worst case is an awkward draft, never a drained account.

I also covered the part almost no tool touches: the aftercare tail, months later, of closing digital accounts, transferring the vehicle and property, and grief support for the living.

What we learned

A "zero-dependency core" claim needs a test that runs with the dependencies gone, or it's just a hope. Keeping the safety-critical logic out of the model isn't a limitation, it's the feature. It makes the behavior testable and hard to hijack.

And the hardest part of an autonomous agent is deciding what not to automate. For someone who's grieving, restraint is what earns trust.

What's next for Umash

More jurisdictions and traditions, all as data. Connecting the drafts to real, human-confirmed actions so a family can approve from one place, still never autonomous. Careful handling of real decedent PII for a live deployment. And a shared case, so relatives can carry the work together.

Built With

  • amazon-bedrock
  • amazon-bedrock-agentcore
  • amazon-bedrock-guardrails
  • boto3
  • github-actions
  • javascript
  • python
  • strands-agents-sdk
Share this project:

Updates

Submission history