AWS Builder Center
Building Recoup: Agents for Humans and How We Designed a Safe AWS Recovery Workflow with Strands Graph

Building Recoup: Agents for Humans and How We Designed a Safe AWS Recovery Workflow with Strands Graph

FinOps tools excel at finding waste; teams still struggle to close recovery safely. Recoup uses an 11-node Strands graph on Amazon Bedrock, with destructive power gated by deterministic Cedar policy and human approval, not LLM execution.

FinOps tools excel at finding waste; teams still struggle to close recovery safely. For the Agents for Humans hackathon we built Recoup, an autonomous cloud-spend recovery agent with an 11-node Strands graph on Amazon Bedrock, but keeps destructive power behind deterministic Cedar policy and human approval.

Graph

Recoup’s pipeline is deliberately split:
  • 5 agent nodes - e.g. incident correlation, evidence collection, eligibility reasoning, claim packaging, case monitoring
  • 6 deterministic nodes - normalization, SLA math, sanitization, Cedar policy gate, submission adapter, monitoring hooks
The LLM proposes; Cedar decides; humans approve at the boundary.
Flow:
normalize_event → incident_correlation [Strands] → evidence_collection → eligibility → claim_package [Strands] → risk_policy_gate [Cedar] → HITL → submission_adapter → case_monitor
See the canonical diagrams (Mermaid) in our repo: architecture/architecture.md  - stack, J-FULL lifecycle, and agent graph.

Why not “LLM executes”?

Financial remediation is high stakes. We enforce:
  • Tool allowlists and autonomy classes (GREEN / YELLOW / RED / BLACK)
  • Cedar default deny on writes
  • Explicit REQUIRE_APPROVAL for sensitive actions
  • Claim binding: claim_hash, amount, and state_version must match on approve (tamper → HTTP 409)
Code pointers:
  • Graph nodes: backend/src/recoup/graph/nodes.py
  • Cedar policy: infra/policy/recoup-policy.cedar

Try the live demo

No AWS keys required: https://pdkeexzwxr.us-east-1.awsapprunner.com/scan  → Demo Scan → Start Recovery on three services → approve / investigate / decline on opportunity detail → Recovery Ledger. Guest sessions: X-Demo-Session + sidebar Reset Demo Data.
Any opinions in this article are those of the individual author and may not reflect the opinions of AWS.
Enjoyed reading this content? Let the author know!

Your likes, comments, shares, and saves help creators reach more builders.

Loading recommendations

Loading article