Skip to content

Repository files navigation

Agent Control Specification

The Agent Control Specification (ACS) is a stateless, deterministic policy decision runtime for agent security, built on the agent-hooks control contract.

The layering:

  • agent-hooks defines the control contract: eight interception points, the AgentContext payload, the three-verdict model (allow / deny / transform, with warnings and liftable denies), host obligations, composition, and the conformance test kit.
  • ACS (this repository) is a conformant interceptor: a host framework emits interception points through an agent-hooks emitter, and ACS evaluates the bound policy — manifest binding, Cedar / Rego / custom dispatchers, annotators, information-flow labels — and returns an agent-hooks verdict.
  • Hosts and frameworks integrate agent-hooks once and gain ACS (or any other interceptor) without bespoke glue.

ACS decisions are pure: same manifest, same context, same annotations → same verdict. Escalation is expressed natively as a liftable deny (deny + approval); warnings ride on allow. The engine performs no transform application, no approval resolution, and no record keeping — those are host obligations defined by agent-hooks.

Layout

Path Contents
engine/ Rust evaluation core (agent-control-spec crate): manifest, dispatchers, annotators, policy-output normalization, the AcsInterceptor
sdk/ffi/ C ABI over the engine (agent-control-spec-ffi), which the .NET binding calls
sdk/python/ Python binding: agent_control_spec package wrapping the engine as an agent_hooks interceptor
sdk/node/ Node binding: @responsibleai/agent-control-spec
sdk/dotnet/ .NET binding: ResponsibleAI.AgentControlSpec
generator/ Optional acs-policy-gen authoring tool. Produces draft manifests and Rego from prose, with parser checks and ACS validation
spec/ The ACS specification (policy plane) and schemas
policy/ Cedar and Rego policy libraries
fixtures/ Evaluation fixtures
docs/EXTRACTION.md Provenance map from the previous tree

Status

Rust builds require Rust 1.89 or newer. See manifest parsing for YAML typing rules, host-controlled parsing budgets and parser dependency details.

Python: SDK quickstart and composing ACS controls through Agent Hooks.

Node: npm install @responsibleai/agent-control-spec@alpha, see the Node wrapper. Keep the @alpha tag while the package is pre-release: npm's latest tag can lag the newest pre-release, so a plain npm install may fetch an older build.

Current version: 0.4.0-alpha.4, an alpha of the re-based runtime. It depends on agent-hooks 0.1.0-alpha.5.

About

Policy decision runtime for agent security, built on the agent-hooks control contract.

Topics

Resources

Stars

4 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages