Skip to main content

AccessManager

Struct AccessManager 

Source
pub struct AccessManager { /* private fields */ }
Expand description

Access Manager.

Manages agent permissions, enforces security boundaries, and maintains an audit log of all security-relevant actions.

§Usage

let mut access = AccessManager::new();

// Create permissions for a new agent
access.set_permissions(AgentPermissions::for_new_agent("code-agent"));

// Assign agent to a workspace
access.assign_workspace("code-agent", "project-alpha");

// Check permissions with sandbox enforcement
if access.can_access_path_in_workspace(&agent_id, "code-agent", "/workspace/file.rs", Some("project-alpha")) {
    // allow file access within workspace
}

// Check if agent can access a specific workspace
if access.can_access_workspace("code-agent", "project-alpha") {
    // allow workspace access
}

Access Manager — least-privilege security for agents.

Implementations§

Source§

impl AccessManager

Source

pub fn new() -> Self

Creates a new access manager.

Source

pub fn with_max_audit_entries(max_audit_entries: usize) -> Self

Creates a new access manager with custom settings.

§Arguments
  • max_audit_entries - Maximum audit log size (oldest entries are pruned)
Source

pub fn with_audit_log_path(self, path: PathBuf) -> Self

Configure an audit log file path for persistence.

Spawns a background tokio task that reads from a bounded channel and appends audit entries to the file. Uses a bounded channel of capacity 1000 to provide backpressure.

Source

pub fn can_use_tool(&mut self, agent_name: &str, tool: &str) -> bool

Checks if an agent is allowed to use a specific tool.

Logs the access decision to the audit log.

Source

pub fn can_access_path(&mut self, agent_name: &str, path: &str) -> bool

Checks if an agent is allowed to access a specific path.

Enforces both allowed_paths and denied_paths rules. A path is only allowed if it matches an allowed pattern AND does not match any denied pattern.

Logs the access decision to the audit log.

Source

pub fn can_access_network(&mut self, agent_name: &str) -> bool

Checks if an agent is allowed to make network requests.

Logs the access decision to the audit log.

Source

pub fn can_execute_for(&self, agent_name: &str, duration_secs: u64) -> bool

Checks if an agent can execute for the given duration (in seconds).

Returns true if unlimited (max_execution_time_secs = 0) or if the requested duration is within the limit.

Source

pub fn can_use_memory(&self, agent_name: &str, memory_mb: u64) -> bool

Checks if an agent can use the specified amount of memory (in MB).

Returns true if unlimited (max_memory_mb = 0) or if the requested memory is within the limit.

Source

pub fn can_fork(&self, agent_name: &str) -> bool

Checks if an agent can fork (spawn sub-agents).

Source

pub fn get_permissions(&self, agent_name: &str) -> Option<&AgentPermissions>

Gets the permission set for an agent.

Returns None if no permissions are defined for the agent.

Source

pub fn get_or_create_permissions( &mut self, agent_name: &str, ) -> &mut AgentPermissions

Gets the permission set for an agent, creating a default one if needed.

Useful for dynamically creating permissions on first access.

Source

pub fn set_permissions(&mut self, permissions: AgentPermissions)

Sets the permissions for an agent.

Overwrites any existing permissions for this agent.

Source

pub fn update_permissions( &mut self, agent_name: &str, update: PermissionUpdate, ) -> Result<()>

Updates permissions for an agent using a partial update.

Creates default permissions if the agent doesn’t exist. Only updates fields that are Some() in the update.

Source

pub fn remove_permissions(&mut self, agent_name: &str)

Removes permissions for an agent.

After removal, all access by this agent will be denied.

Source

pub fn list_agents(&self) -> Vec<String>

Lists all agents with defined permissions.

Source

pub fn audit_log(&self) -> &[AuditEntry]

Gets the full audit log.

Returns entries in chronological order (oldest first).

Source

pub fn audit_log_recent(&self, limit: usize) -> Vec<AuditEntry>

Gets recent audit log entries.

§Arguments
  • limit - Maximum number of entries to return (from the end)
Source

pub fn audit_log_for_agent(&self, agent_name: &str) -> Vec<AuditEntry>

Gets audit log entries for a specific agent.

Source

pub fn denied_actions(&self) -> Vec<&AuditEntry>

Searches audit log for denied actions.

Source

pub fn rbac_manager(&self) -> &RbacManager

Returns a reference to the RBAC manager (for HitL approvals).

Source

pub fn rbac_manager_mut(&mut self) -> &mut RbacManager

Returns a mutable reference to the RBAC manager (for HitL approvals).

Source

pub fn register_workspace_path( &mut self, workspace_name: &str, workspace_path: PathBuf, )

Registers a workspace path.

This is used to report which paths belong to each workspace.

§Arguments
  • workspace_name - Name of the workspace
  • workspace_path - Absolute path to the workspace directory
Source

pub fn assign_workspace( &mut self, agent_name: &str, workspace_name: &str, ) -> bool

Assigns an agent to a specific workspace.

After assignment, the agent is sandboxed to that workspace.

§Arguments
  • agent_name - Name of the agent to assign
  • workspace_name - Name of the workspace to assign the agent to
§Returns

true if assignment succeeded, false if the workspace doesn’t exist

Source

pub fn get_workspace_for_agent(&self, agent_name: &str) -> Option<String>

Gets the workspace name that an agent is assigned to.

§Returns

Some(workspace_name) if assigned, None if the agent is not assigned to any workspace

Source

pub fn get_workspace_path(&self, workspace_name: &str) -> Option<&PathBuf>

Gets the path for a specific workspace.

§Returns

Some(path) if the workspace exists, None otherwise

Source

pub fn list_workspaces(&self) -> Vec<String>

Lists all registered workspaces.

Source

pub fn list_agents_in_workspace(&self, workspace_name: &str) -> Vec<String>

Lists all agents assigned to a specific workspace.

Source

pub fn can_access_workspace( &self, agent_name: &str, workspace_name: &str, ) -> bool

Checks if an agent can access a specific workspace.

An agent can access a workspace if it is assigned to it.

§Arguments
  • agent_name - Name of the agent
  • workspace_name - Name of the workspace to check
§Returns

true if the agent is assigned to the workspace, false otherwise

Source

pub fn is_path_in_workspace(&self, workspace_name: &str, path: &str) -> bool

Checks if a path is within a workspace’s directory.

This performs a canonical path comparison to ensure the path is a descendant of the workspace directory.

§Arguments
  • workspace_name - Name of the workspace
  • path - Path to check (absolute or relative)
§Returns

true if the path is within the workspace, false otherwise

Source

pub fn can_access_path_in_workspace( &mut self, agent_id: &AgentId, agent_name: &str, path: &str, workspace: Option<&str>, ) -> bool

Full sandbox check: RBAC → path allowed? → within workspace?

This is the main method for enforcing sandbox boundaries. It checks:

  1. RBAC - does the agent’s role allow the action?
  2. Path permissions - is the path in the agent’s allowed_paths?
  3. Workspace boundary - is the path within the assigned workspace?

If any check fails, the access is denied and logged as “sandbox violation” if the path would be valid but outside the workspace boundary.

§Arguments
  • agent_name - Name of the agent
  • path - Path to access
  • workspace - Workspace context (if agent is assigned to one)
§Returns

true if all checks pass, false otherwise Check whether an agent can access a path within its workspace.

Verifies RBAC permissions, path allow/deny lists, and workspace boundary.

§Arguments
  • agent_id - The agent’s unique identifier
  • agent_name - Human-readable agent name for permission lookup
  • path - The path to check access for
  • workspace - Optional explicit workspace name
Source

pub fn unassign_workspace(&mut self, agent_name: &str) -> Option<String>

Unassigns an agent from its workspace (if any).

The agent will no longer be sandboxed to any workspace.

Source

pub fn remove_workspace(&mut self, workspace_name: &str)

Removes a workspace and unassigns all agents from it.

All agents assigned to this workspace will have their assignments cleared.

Source

pub fn clear_audit_log(&mut self)

Clears the audit log.

Source

pub fn validate_permissions(&self, perms: &AgentPermissions) -> Vec<String>

Validates a permission set for correctness.

Returns a list of warnings about the permissions.

Trait Implementations§

Source§

impl Clone for AccessManager

Source§

fn clone(&self) -> AccessManager

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl Debug for AccessManager

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl Default for AccessManager

Source§

fn default() -> Self

Returns the “default value” for a type. Read more

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> Conv for T

Source§

fn conv<T>(self) -> T
where Self: Into<T>,

Converts self into T using Into<T>. Read more
Source§

impl<T> DynClone for T
where T: Clone,

Source§

fn __clone_box(&self, _: Private) -> *mut ()

Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T> Instrument for T

Source§

fn instrument(self, span: Span) -> Instrumented<Self>

Instruments this type with the provided Span, returning an Instrumented wrapper. Read more
Source§

fn in_current_span(self) -> Instrumented<Self>

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> IntoEither for T

Source§

fn into_either(self, into_left: bool) -> Either<Self, Self>

Converts self into a Left variant of Either<Self, Self> if into_left is true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
where F: FnOnce(&Self) -> bool,

Converts self into a Left variant of Either<Self, Self> if into_left(&self) returns true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

impl<T> Pipe for T
where T: ?Sized,

Source§

fn pipe<R>(self, func: impl FnOnce(Self) -> R) -> R
where Self: Sized,

Pipes by value. This is generally the method you want to use. Read more
Source§

fn pipe_ref<'a, R>(&'a self, func: impl FnOnce(&'a Self) -> R) -> R
where R: 'a,

Borrows self and passes that borrow into the pipe function. Read more
Source§

fn pipe_ref_mut<'a, R>(&'a mut self, func: impl FnOnce(&'a mut Self) -> R) -> R
where R: 'a,

Mutably borrows self and passes that borrow into the pipe function. Read more
Source§

fn pipe_borrow<'a, B, R>(&'a self, func: impl FnOnce(&'a B) -> R) -> R
where Self: Borrow<B>, B: 'a + ?Sized, R: 'a,

Borrows self, then passes self.borrow() into the pipe function. Read more
Source§

fn pipe_borrow_mut<'a, B, R>( &'a mut self, func: impl FnOnce(&'a mut B) -> R, ) -> R
where Self: BorrowMut<B>, B: 'a + ?Sized, R: 'a,

Mutably borrows self, then passes self.borrow_mut() into the pipe function. Read more
Source§

fn pipe_as_ref<'a, U, R>(&'a self, func: impl FnOnce(&'a U) -> R) -> R
where Self: AsRef<U>, U: 'a + ?Sized, R: 'a,

Borrows self, then passes self.as_ref() into the pipe function.
Source§

fn pipe_as_mut<'a, U, R>(&'a mut self, func: impl FnOnce(&'a mut U) -> R) -> R
where Self: AsMut<U>, U: 'a + ?Sized, R: 'a,

Mutably borrows self, then passes self.as_mut() into the pipe function.
Source§

fn pipe_deref<'a, T, R>(&'a self, func: impl FnOnce(&'a T) -> R) -> R
where Self: Deref<Target = T>, T: 'a + ?Sized, R: 'a,

Borrows self, then passes self.deref() into the pipe function.
Source§

fn pipe_deref_mut<'a, T, R>( &'a mut self, func: impl FnOnce(&'a mut T) -> R, ) -> R
where Self: DerefMut<Target = T> + Deref, T: 'a + ?Sized, R: 'a,

Mutably borrows self, then passes self.deref_mut() into the pipe function.
Source§

impl<T> Pointable for T

Source§

const ALIGN: usize

The alignment of pointer.
Source§

type Init = T

The type for initializers.
Source§

unsafe fn init(init: <T as Pointable>::Init) -> usize

Initializes a with the given initializer. Read more
Source§

unsafe fn deref<'a>(ptr: usize) -> &'a T

Dereferences the given pointer. Read more
Source§

unsafe fn deref_mut<'a>(ptr: usize) -> &'a mut T

Mutably dereferences the given pointer. Read more
Source§

unsafe fn drop(ptr: usize)

Drops the object pointed to by the given pointer. Read more
Source§

impl<T> PolicyExt for T
where T: ?Sized,

Source§

fn and<P, B, E>(self, other: P) -> And<T, P>
where T: Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow only if self and other return Action::Follow. Read more
Source§

fn or<P, B, E>(self, other: P) -> Or<T, P>
where T: Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow if either self or other returns Action::Follow. Read more
Source§

impl<R, P> ReadPrimitive<R> for P
where R: Read + ReadEndian<P>, P: Default,

Source§

fn read_from_little_endian(read: &mut R) -> Result<Self, Error>

Read this value from the supplied reader. Same as ReadEndian::read_from_little_endian().
Source§

fn read_from_big_endian(read: &mut R) -> Result<Self, Error>

Read this value from the supplied reader. Same as ReadEndian::read_from_big_endian().
Source§

fn read_from_native_endian(read: &mut R) -> Result<Self, Error>

Read this value from the supplied reader. Same as ReadEndian::read_from_native_endian().
Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T> Tap for T

Source§

fn tap(self, func: impl FnOnce(&Self)) -> Self

Immutable access to a value. Read more
Source§

fn tap_mut(self, func: impl FnOnce(&mut Self)) -> Self

Mutable access to a value. Read more
Source§

fn tap_borrow<B>(self, func: impl FnOnce(&B)) -> Self
where Self: Borrow<B>, B: ?Sized,

Immutable access to the Borrow<B> of a value. Read more
Source§

fn tap_borrow_mut<B>(self, func: impl FnOnce(&mut B)) -> Self
where Self: BorrowMut<B>, B: ?Sized,

Mutable access to the BorrowMut<B> of a value. Read more
Source§

fn tap_ref<R>(self, func: impl FnOnce(&R)) -> Self
where Self: AsRef<R>, R: ?Sized,

Immutable access to the AsRef<R> view of a value. Read more
Source§

fn tap_ref_mut<R>(self, func: impl FnOnce(&mut R)) -> Self
where Self: AsMut<R>, R: ?Sized,

Mutable access to the AsMut<R> view of a value. Read more
Source§

fn tap_deref<T>(self, func: impl FnOnce(&T)) -> Self
where Self: Deref<Target = T>, T: ?Sized,

Immutable access to the Deref::Target of a value. Read more
Source§

fn tap_deref_mut<T>(self, func: impl FnOnce(&mut T)) -> Self
where Self: DerefMut<Target = T> + Deref, T: ?Sized,

Mutable access to the Deref::Target of a value. Read more
Source§

fn tap_dbg(self, func: impl FnOnce(&Self)) -> Self

Calls .tap() only in debug builds, and is erased in release builds.
Source§

fn tap_mut_dbg(self, func: impl FnOnce(&mut Self)) -> Self

Calls .tap_mut() only in debug builds, and is erased in release builds.
Source§

fn tap_borrow_dbg<B>(self, func: impl FnOnce(&B)) -> Self
where Self: Borrow<B>, B: ?Sized,

Calls .tap_borrow() only in debug builds, and is erased in release builds.
Source§

fn tap_borrow_mut_dbg<B>(self, func: impl FnOnce(&mut B)) -> Self
where Self: BorrowMut<B>, B: ?Sized,

Calls .tap_borrow_mut() only in debug builds, and is erased in release builds.
Source§

fn tap_ref_dbg<R>(self, func: impl FnOnce(&R)) -> Self
where Self: AsRef<R>, R: ?Sized,

Calls .tap_ref() only in debug builds, and is erased in release builds.
Source§

fn tap_ref_mut_dbg<R>(self, func: impl FnOnce(&mut R)) -> Self
where Self: AsMut<R>, R: ?Sized,

Calls .tap_ref_mut() only in debug builds, and is erased in release builds.
Source§

fn tap_deref_dbg<T>(self, func: impl FnOnce(&T)) -> Self
where Self: Deref<Target = T>, T: ?Sized,

Calls .tap_deref() only in debug builds, and is erased in release builds.
Source§

fn tap_deref_mut_dbg<T>(self, func: impl FnOnce(&mut T)) -> Self
where Self: DerefMut<Target = T> + Deref, T: ?Sized,

Calls .tap_deref_mut() only in debug builds, and is erased in release builds.
Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T> TryConv for T

Source§

fn try_conv<T>(self) -> Result<T, Self::Error>
where Self: TryInto<T>,

Attempts to convert self into T using TryInto<T>. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = Infallible

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<V, T> VZip<V> for T
where V: MultiLane<T>,

Source§

fn vzip(self) -> V

Source§

impl<T> WithSubscriber for T

Source§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self>
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

fn with_current_subscriber(self) -> WithDispatch<Self>

Attaches the current default Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

impl<T> ErasedDestructor for T
where T: 'static,

Source§

impl<T> MaybeSendSync for T