The Agent Control Specification (ACS) is a stateless, deterministic policy decision runtime for agent security, built on the agent-hooks control contract.
The layering:
- agent-hooks defines the control contract: eight interception
points, the
AgentContextpayload, the three-verdict model (allow/deny/transform, with warnings and liftable denies), host obligations, composition, and the conformance test kit. - ACS (this repository) is a conformant interceptor: a host framework emits interception points through an agent-hooks emitter, and ACS evaluates the bound policy — manifest binding, Cedar / Rego / custom dispatchers, annotators, information-flow labels — and returns an agent-hooks verdict.
- Hosts and frameworks integrate agent-hooks once and gain ACS (or any other interceptor) without bespoke glue.
ACS decisions are pure: same manifest, same context, same annotations →
same verdict. Escalation is expressed natively as a liftable deny
(deny + approval); warnings ride on allow. The engine performs no
transform application, no approval resolution, and no record keeping —
those are host obligations defined by agent-hooks.
| Path | Contents |
|---|---|
engine/ |
Rust evaluation core (agent-control-spec crate): manifest, dispatchers, annotators, policy-output normalization, the AcsInterceptor |
sdk/ffi/ |
C ABI over the engine (agent-control-spec-ffi), which the .NET binding calls |
sdk/python/ |
Python binding: agent_control_spec package wrapping the engine as an agent_hooks interceptor |
sdk/node/ |
Node binding: @responsibleai/agent-control-spec |
sdk/dotnet/ |
.NET binding: ResponsibleAI.AgentControlSpec |
generator/ |
Optional acs-policy-gen authoring tool. Produces draft manifests and Rego from prose, with parser checks and ACS validation |
spec/ |
The ACS specification (policy plane) and schemas |
policy/ |
Cedar and Rego policy libraries |
fixtures/ |
Evaluation fixtures |
docs/EXTRACTION.md |
Provenance map from the previous tree |
Rust builds require Rust 1.89 or newer. See manifest parsing for YAML typing rules, host-controlled parsing budgets and parser dependency details.
Python: SDK quickstart and composing ACS controls through Agent Hooks.
Node: npm install @responsibleai/agent-control-spec@alpha, see the
Node wrapper. Keep the @alpha tag while the
package is pre-release: npm's latest tag can lag the newest
pre-release, so a plain npm install may fetch an older build.
Current version: 0.4.0-alpha.4, an alpha of the re-based runtime. It
depends on agent-hooks 0.1.0-alpha.5.