Weave documentation
Agentfs

Agents and Permissions

The public crate exports AgentPermission and PermissionChecker.

Workflow and current contract

The public crate exports AgentPermission and PermissionChecker. PermissionChecker::new() takes no adapter, and grants are added with add_permission. The checker verifies the identity's DID/public-key binding before matching a grant; absence of a matching grant is denied.

Permission, AgentContext, and AgentRegistry exist in private implementation modules and are not all re-exported as usable crate-root imports. Do not copy a crate-root import for those types. Permission matching currently supports exact strings, *, and a simple trailing /* prefix rule; it is not a general glob engine. Application callers should use the filesystem's exposed access paths rather than assuming these internal types form a complete public policy SDK.

Source reference

On this page