Skip to content

Restrict agent permissions

List what a role's agent may not do in restrictions.

Role(
    name="reviewer",
    instructions=prompt_file("prompts/review.md"),
    restrictions={Restriction.NO_FILE_WRITES, Restriction.NO_VCS_WRITES},
)
  • NO_FILE_WRITES - Takes away the agent's file-editing tools.
  • NO_VCS_WRITES - Takes away git commands that change the repository.
  • NO_SHELL - Takes away the agent's shell.
  • NO_NETWORK - Takes away the agent's network tools.

Restrictions limit the agent only. AGL's own work, like commit and Run.verify(), isn't limited. Nor is the function of a tool you give the agent, so a tool can do what a restriction takes away from the agent.

Reference

agl.sdk.Restriction

Bases: StrEnum

What an agent may not do.

NO_VCS_WRITES class-attribute instance-attribute

Takes away the agent's commits, branches, merges, fetches and pushes.

NO_FILE_WRITES class-attribute instance-attribute

Takes away the agent's file-editing tools.

NO_SHELL class-attribute instance-attribute

Takes away the agent's shell, and the other tools a backend runs commands through.

NO_NETWORK class-attribute instance-attribute

Takes away the agent's network tools.