agent.acl

agent.acl is the versioned runtime config for the model, provider, queue, storage, skill directories, and worker agent directories.

An SDK host may pass any .acl file explicitly with Agent.create("agent.acl"). The a3s code TUI discovers .a3s/config.acl from the workspace and then ~/.a3s/config.acl; it does not require a root agent.acl. The format is the same; discovery and scope differ.

Basic Config

ACL
default_model = "provider/model-id"
max_parallel_tasks = 4
auto_parallel = false
providers "provider" {
apiKey = env("PROVIDER_API_KEY")
baseUrl = env("PROVIDER_BASE_URL")
models "model-id" {
tool_call = true
limit = {
context = 128000
output = 4096
}
}
}

apiKey / api_key and baseUrl / base_url are accepted aliases. The runtime does not hard-code model names; default_model and session-level model overrides must match the provider/model-id values declared here.

Inject tokens through environment variables. Do not commit credentials. Once agent.acl lives in the repo, it is product behavior and should be reviewed like code.

Directory Discovery

ACL
skill_dirs = ["./.a3s/skills"]
agent_dirs = ["./.a3s/agents"]
project_doc_max_bytes = 32768
project_doc_fallback_filenames = ["TEAM_GUIDE.md"]
auto_delegation {
enabled = true
min_confidence = 0.72
max_tasks = 4
auto_parallel = false
}

skill_dirs points at reusable skills. agent_dirs points at worker/subagent definitions. project_doc_max_bytes bounds the combined root-to-workspace instruction chain; fallback filenames are checked after AGENTS.override.md and AGENTS.md. Automatic delegation decides whether the model may choose a worker; it does not remove parent-session permission policy, tool visibility, or verification requirements.

Session Storage

ACL
storage_backend = "file"
sessions_dir = ".a3s/sessions"

sessions_dir is the local file-session persistence path used when the session does not receive an explicit SDK sessionStore. storage_backend = "memory" keeps sessions ephemeral. storage_url is parsed as custom storage metadata, but it does not create a local FileSessionStore by itself.

Boundaries

  • Config decides what can be connected and how the runtime starts; it does not bypass permission gates.
  • Prefer workspace-relative paths.
  • Tune automatic delegation together with high-quality agents/ descriptions.
  • High-risk tools should still go through HITL or allow-lists.