| action |
What a rule says to do with a matching call: allow, deny or require approval (require_approval in YAML). |
Allow, Deny, Require approval |
permit, block, reject, HITL, ask |
| agent |
An AI program that uses tools, described to MAQPNA by an Agent resource (image, trust tier, tools, policy, budget). The agent is the definition; it runs as sessions. |
Agent |
bot, assistant, AI worker, workload (in UI), app |
| agent-sandbox |
Only the name of the upstream Kubernetes project, kubernetes-sigs/agent-sandbox, that MAQPNA builds on. Always hyphenated and in code formatting or linked. |
— |
"agent sandbox" for a MAQPNA sandbox |
| approval |
A tool call that a rule held for a human decision, and that decision. An approval is pending, then approved, denied or expired. |
Approval |
confirmation, sign-off, review, HITL, human-in-the-loop (except in marketing explanations), request |
| approve / deny |
The two human decisions on an approval. Approving lets exactly that one call run. |
Approve, Deny |
accept/reject, allow/block, confirm/cancel |
| approver |
A person with the approver role for a namespace. Approvers cannot approve calls made on their own behalf. |
Approver |
reviewer, admin (unless they are one) |
| attestation |
Hardware proof that a tier-2 sandbox is a genuine confidential VM. Identities for tier-2 are issued only after it passes. |
Attestation, Attested |
verification (alone), remote proof |
| audit ledger |
The append-only, hash-chained record of every decision, approval, revocation and result. Can be shipped to WORM storage. |
Audit ledger (nav: Audit) |
audit log, audit trail, decision log, logs, history, journal |
| audit record |
One entry in the audit ledger. |
Record |
event, log line, entry (in UI) |
| break-glass |
An emergency action outside the normal path, such as the static admin token. Always hyphenated. |
Break-glass |
emergency, override, god mode |
| budget |
A spending limit for an agent, namespace, user or tenant over a day or a month. Set in Agent.spec.budget or a BudgetPolicy. |
Budget |
quota (that is a Kubernetes resource limit), cap, credits, allowance |
| checkpoint |
A signed statement of the ledger head at a point in time. |
Checkpoint |
snapshot, seal |
| CLI |
The maqpna command. Its lifecycle plugin is maqpna-install. |
CLI |
the client, maqpnactl |
| console |
The web UI served by the gateway (maqpna console). Its full name in titles is MAQPNA Console. |
Console |
dashboard, admin panel, portal, UI |
| cost |
The metered price of one call or session, in the configured currency. |
Cost |
price, charge, fee (fees are commercial) |
| decision |
What the gateway did with one call: allowed, denied, or held for approval. Every decision is written to the audit ledger with the policy and rule that made it. |
Allowed, Denied, Held for approval |
verdict, outcome, result (that is the session's result) |
| default deny |
No matching rule (or no policy) means the call is denied. Hyphenate before a noun: "default-deny egress". |
Default deny |
deny by default, implicit deny, fail open/closed (except for component failures) |
| desktop app |
The desktop app started by maqpna desk. Full name MAQPNA Desk. |
Desk |
client app, launcher |
| DLP |
Data loss prevention: the gateway's checks that find and block or redact sensitive data (keys, personal data) in arguments and results. Spell out on first mention on every page. |
DLP |
data filter, PII scanner, content filter |
| drift |
A tool definition that changed after it was pinned (a "rug pull"). Drifted tools are hidden and denied until reviewed. |
Drift |
mismatch, tamper, rug pull (except as the explanation) |
| edition |
A licensing package. The editions are Community, Team, Enterprise, Sovereign and Operator. Write "the Sovereign edition" in prose; the name alone on cards and buttons. |
Community, Team, Enterprise, Sovereign, Operator |
Sovereign Edition (capital E), plan, tier (tier means trust tier) |
| egress |
Network traffic leaving a sandbox. Sandboxes have default-deny egress; allowed egress goes through the gateway. |
Egress |
outbound, internet access |
| erasure |
Deleting everything a memory store holds about a user (GDPR Art. 17), with a signed erasure certificate. |
Erasure, Erase |
purge, wipe, forget, delete (in UI) |
| evidence bundle |
An exported, verifiable package of audit records (and related objects) for one session, period or system. |
Evidence bundle, Export evidence |
report, dump, archive |
| four-eyes approval |
An approval that needs two different approvers. |
Four-eyes |
quorum (in UI), dual control, two-man rule |
| gateway |
The MAQPNA component every tool, model and egress call passes through. It verifies identity, evaluates policy, checks DLP, budgets and taint, asks for approval and writes the audit record. First mention: "the MAQPNA gateway". |
Gateway |
proxy, tool-call gateway, MCP gateway, firewall, broker |
| governed call |
Any tool, model or egress call that passed through the gateway and got a decision. This is the metered unit. |
Governed call |
transaction, request, API call |
| identity broker |
The component that issues each session a short-lived, signed identity (SPIFFE-style) and token. |
Identity broker |
token service, auth server, STS, IdP |
| identity provider |
The customer's OIDC single sign-on system (Keycloak, Entra ID, Okta). |
Identity provider |
IdP (in UI), SSO server, auth provider |
| installation |
One running MAQPNA: the operator, gateway and identity broker in one cluster (or one maqpna dev stack on a laptop). |
Installation |
instance, deployment (for the whole thing), environment, tenant |
| jurisdiction |
The country or region whose law applies to an installation, as declared in the sovereignty policy (EU-DE). |
Jurisdiction |
region (unless it is a cloud region), locale, residency zone |
| kill switch |
The capability to stop an agent, session, user or token across the installation within about a second (maqpna kill). |
Kill switch |
panic button, emergency stop, killswitch (except the role name) |
| local MAQPNA |
The laptop stack started by maqpna dev up: identity broker, gateway and a test MCP server, no Kubernetes. |
Local (dev) |
dev cluster, sandbox mode, playground |
| MAQPNA |
The product: the sovereign runtime for AI agents. Always in capitals in prose, headings and titles, including at the start of a sentence. Spoken "mak-pna". |
MAQPNA |
Maqpna, MaqPNA, maqpna (in prose), "the MAQPNA platform" |
maqpna |
The CLI binary, package, Helm chart, image prefix, domain and URL paths. Lower case, always in code formatting. |
— |
MAQPNA (for the command) |
Maqpna |
Only inside code identifiers that require Pascal case: MaqpnaClient, MaqpnaError, HTTP headers X-Maqpna-*, the Cedar namespace Maqpna::. Never in prose. |
— |
— |
| MCP server |
A server that offers tools over the Model Context Protocol. Kind: MCPServer. In gateway config they are upstreams; in prose and UI they are MCP servers. |
MCP server |
tool server, upstream (in UI), connector, plugin, integration |
| memory store |
Governed long-term memory for agents, scoped by agent and user. Kind: MemoryStore. |
Memory store |
vector store, knowledge base, cache |
| model call |
One request from a session to a model through the gateway's model route (/llm). |
Model call |
LLM request, completion, inference call |
| namespace |
A Kubernetes namespace. Teams and environments are namespaces; policies, agents and sessions are namespaced. |
Namespace |
project, space, workspace, environment |
| operator |
The MAQPNA Kubernetes controller (maqpna-operator) that turns Agent and AgentSession resources into sandboxes, tokens and network policies. In product docs "operator" always means this component. |
Operator |
controller (alone), manager, the data-center operator (write "service provider") |
| platform team |
The people who install and run MAQPNA in their organisation. |
— |
ops, admins (unless you mean the admin role), DevOps |
| policy |
A named set of rules for which agents may call which tools, and how. Kind: ToolPolicy. A policy has a default action and an ordered list of rules. |
Policy |
guardrail, ACL, permission set, rule set, ruleset |
| redact |
Replace sensitive data with a marker before it leaves the gateway. |
Redact, Redacted |
mask, scrub, sanitise |
| result |
What a session reported when it ended: Succeeded or Failed, with a summary. |
Result |
outcome, exit status |
| revocation |
One kill-switch entry: what is revoked, by whom, until when. Kind: AgentRevocation, or a break-glass entry at the gateway. Verb: revoke. |
Revocation, Revoke |
block, ban, disable, quarantine |
| role |
A permission set in the admin API: admin, approver, auditor, killswitch, optionally per namespace. |
Role |
permission, group (groups come from the identity provider) |
| rule |
One entry in a policy. It matches calls (server, tool, arguments, taint) and gives an action. |
Rule |
policy (for one entry), condition (a condition is part of a rule), filter |
| sandbox |
The isolated environment one session runs in: a gVisor container, a Firecracker microVM or a confidential VM, with default-deny networking. Created through the upstream agent-sandbox project. |
Sandbox |
container, pod (in UI copy), VM (unless the tier is a VM), agent sandbox (as a MAQPNA noun) |
| SDK |
The Python, TypeScript and Go libraries agents use to call tools through the gateway. |
SDK |
client library, agent kit |
| service provider |
A company that runs MAQPNA to host agents for its customers (a neocloud, colocation provider, telco or ISV). Buys the Operator edition. |
Service provider |
operator (that word is the component), reseller (in product copy) |
| session |
One run of an agent, from start to result, with its own sandbox, identity and token. Kind: AgentSession. Every governed call belongs to exactly one session. |
Session |
agent session (except on first mention), run (as a noun), instance, job, task, execution, conversation |
| session identity |
The signed identity of one session: agent, tier, namespace, user it acts for, scopes. |
Identity |
credentials, service account |
| signing key |
A key that signs identities, audit checkpoints or licences. The customer holds it (file, PKCS#11 HSM or KMS). |
Signing key |
master key, root key, secret |
| snapshot |
A saved session that can be resumed or forked. Kind: AgentSessionSnapshot. |
Snapshot |
checkpoint (that word belongs to the audit ledger) |
| sovereignty policy |
The cluster-wide rules on jurisdiction, registries, egress and attestation that every session is admitted against. Kind: SovereigntyPolicy. |
Sovereignty policy |
compliance policy, residency rules |
| spend |
Metered cost so far in a budget window. |
Spend |
usage (usage means metered units, see below), burn, consumption |
| taint |
A label on a session that has read untrusted content (for example a web page or a public issue). Rules can then deny, or require approval for, tools that could leak data. |
Taint, Tainted |
contamination, flag, mark, quarantine |
| tenant |
A customer of a service provider that runs MAQPNA for others (ISV, MSP, data-center operator), with its own namespaces, trust domain, signing key, ledger and quotas. Kind: Tenant. |
Tenant |
org, organisation, organization, workspace, account, customer (in UI) |
| third-party register |
The DORA Art. 28 list of ICT third-party providers (MCP servers, model routes) that agents used, built from the ledger. |
Third-party register |
vendor list, supplier report |
| timeline |
The ledger-ordered view of what one session did. |
Timeline |
history, trace (traces are OpenTelemetry), log |
| token |
The bearer form of a session identity, or an admin-API access token. Always say which: "session token", "access token". |
Session token, Access token |
key, secret, JWT (in UI) |
| tool |
A function an agent can call, offered by an MCP server. Written server.tool in UI (echo.delete_resource). |
Tool |
action (an action is the policy outcome), function, skill, capability |
| tool call |
One request from a session to a tool. |
Tool call |
invocation, request (in UI), action |
| tool pinning |
The gateway records a hash of each tool's definition. A pin is that hash. |
Pinned |
lock, fingerprint, allow-list (for this) |
| trust tier |
The isolation level a session runs at. tier-0 gVisor, tier-1 Kata + Firecracker microVM, tier-2 confidential VM with attestation. Kind: TrustTier. Always write the tier with its runtime on first mention: "tier-1 (microVM)". |
Trust tier |
isolation level, security level, runtime tier, plan, tier (alone, on first mention) |
| usage |
Metered units for billing: sandbox seconds, governed calls, model tokens, approvals. |
Usage |
consumption, metering data |
| user approval |
An approval by the person the agent acts for, on their own device (CIBA). |
User approval |
user confirmation, push confirmation, step-up |
| verify |
Recompute the hash chain and signatures to prove nothing was changed or removed. |
Verify |
validate (validate is for manifests), check |
| warm pool |
Pre-started sandboxes that make sessions start fast. |
Warm pool |
cache, standby pool |