Agents and Permissions
The public crate exports AgentPermission and PermissionChecker.
Workflow and current contract
The public crate exports AgentPermission and PermissionChecker. PermissionChecker::new() takes no adapter, and grants are added with add_permission. The checker verifies the identity's DID/public-key binding before matching a grant; absence of a matching grant is denied.
Permission, AgentContext, and AgentRegistry exist in private implementation modules and are not all re-exported as usable crate-root imports. Do not copy a crate-root import for those types. Permission matching currently supports exact strings, *, and a simple trailing /* prefix rule; it is not a general glob engine. Application callers should use the filesystem's exposed access paths rather than assuming these internal types form a complete public policy SDK.
Source reference
cratedeclarations —local/agentfs/src/lib.rs.permissionsdeclarations —local/agentfs/src/permissions.rs.agentdeclarations —local/agentfs/src/agent.rs.fsdeclarations —local/agentfs/src/fs.rs.