MAQPNADocs

Concepts

What MAQPNA is, what sovereignty means here, and the words these pages use.

What MAQPNA isMAQPNA is the sovereign runtime for AI agents: isolated sandboxes, short-lived identities, one governed gateway and a tamper-evident audit ledger, on your own infrastructure.What "sovereign" meansThe three layers of sovereignty in MAQPNA (jurisdictional, operational, technical), who is trusted, and where each control is enforced.Agents, sessions, sandboxes and trust tiersAn agent is a definition; a session is one run of it in its own sandbox, at a trust tier that decides how strongly it is isolated.Policies, rules and decisionsA policy is an ordered list of rules with a default action; the gateway combines every applicable policy, strictest wins, and records the decision with the policy and rule that made it.Approvals, four-eyes and user approvalA rule can hold a tool call for a human decision; approvers decide in the CLI, console, Desk or chat, with separation of duties, four-eyes quorum and optional confirmation by the user on their own device (CIBA).DLP and taintData loss prevention (DLP) finds secrets and personal data in traffic and redacts or blocks them; taint marks a session that has read untrusted content so rules can gate the tools that could leak data.Budgets, spend and usageBudgets cap what an agent, namespace, user or tenant may spend per session, day or month; the gateway meters the cost of every governed call and enforces the limits before the next one.Kill switch and revocationsThe kill switch stops an agent, session, user, token, namespace or everything across the installation within seconds; each entry is a revocation, and an unreadable revocation list denies every call.The audit ledgerThe audit ledger is an append-only, SHA-256 hash-chained record of every decision, with signed checkpoints, offline verification, evidence export and shipping to SIEM and write-once storage.TenantsA tenant is one customer of a service provider that runs MAQPNA for others, with its own namespaces, trust domain, signing key, audit ledger, WORM prefix, admin login and quotas.Identity and delegationEvery session gets a short-lived, signed identity that says which agent acts for which person with which scopes; derived tokens can only narrow it, and agent-to-agent calls carry the whole delegation chain.MCP servers, tool pinning and A2AAgents reach tools through Model Context Protocol (MCP) servers registered with the gateway, whose tool definitions are pinned by hash, and reach other agents through governed agent-to-agent (A2A) routes.Security model and threat modelWhat MAQPNA assumes, what it protects, where it enforces each control, how it maps to the OWASP Top 10 for Agentic Applications, and what it does not solve.How MAQPNA comparesWhy a plain container is the wrong home for an agent, how a MAQPNA sandbox differs, and why MAQPNA is a runtime that hosts agent frameworks rather than another framework.EditionsMAQPNA is packaged as the Community, Team, Enterprise, Sovereign and Operator editions; a licence switches paid features on, and no licence state ever blocks or degrades agent traffic.GlossaryEvery MAQPNA term with its definition, the label the console and CLI use, and the words not to use for it, from the terminology guide.