Agent-specific configuration to store on the user's acl (e.g. clockin_enforced, or an external system's user id). Fully replaces any existing value for this location's acl row — it does not merge, so a partial write clears the keys it omits. Read the current value from GET /users and merge client-side to preserve keys you do not own. Omit the field to leave the stored config untouched; pass {} to clear it.