Packages
nous
0.15.3
0.17.0
0.16.6
0.16.5
0.16.4
0.16.3
0.16.2
0.16.1
0.16.0
0.15.8
0.15.7
0.15.6
0.15.5
0.15.4
0.15.3
0.15.2
0.15.1
0.15.0
0.14.3
0.14.2
0.14.1
0.14.0
0.13.3
0.13.2
0.13.1
0.13.0
0.12.17
0.12.16
0.12.15
0.12.14
0.12.13
0.12.12
0.12.11
0.12.9
0.12.7
0.12.6
0.12.5
0.12.3
0.12.2
0.12.0
0.11.3
0.11.0
0.10.1
0.10.0
0.9.0
0.8.1
0.8.0
0.7.2
0.7.1
0.7.0
0.5.0
AI agent framework for Elixir with multi-provider LLM support
Current section
Files
Jump to
Current section
Files
lib/nous/permissions/policy.ex
defmodule Nous.Permissions.Policy do
@moduledoc """
Permission policy controlling tool access.
Defines which tools are denied, which require approval,
and the overall permission mode.
## Modes
* `:default` — read/search tools are open, write/execute tools require approval
* `:permissive` — all tools are open, none require approval
* `:strict` — all tools require approval; at the filter layer, ONLY tools
in `:allow_names` / `:allow_prefixes` are exposed (deny-by-default).
## Examples
# Custom policy that blocks bash and requires approval for write tools
%Nous.Permissions.Policy{
deny_names: MapSet.new(["bash"]),
approval_required: MapSet.new(["file_write", "file_edit"]),
mode: :default
}
# Strict + explicit allowlist
%Nous.Permissions.Policy{
mode: :strict,
allow_names: MapSet.new(["file_read", "search_web"])
}
"""
defstruct deny_names: MapSet.new(),
deny_prefixes: [],
allow_names: MapSet.new(),
allow_prefixes: [],
approval_required: MapSet.new(),
mode: :default
@type mode :: :default | :permissive | :strict
@type t :: %__MODULE__{
deny_names: MapSet.t(),
deny_prefixes: [String.t()],
allow_names: MapSet.t(),
allow_prefixes: [String.t()],
approval_required: MapSet.t(),
mode: mode()
}
end