MAQPNADocs

Glossary#

This glossary is generated from MAQPNA's terminology guide, the single source of truth for the nouns and verbs on every surface: the console, the CLI, MAQPNA Desk, the SDKs, the Helm chart and these docs. Use the term, not its synonyms: one idea, one word. Kubernetes kinds (AgentSession, ToolPolicy) are written in code formatting only when the resource itself is meant.

flowchart LR
    A["agent"] -- "runs as" --> S["session"]
    S -- "in a" --> SB["sandbox"]
    SB -- "at a" --> TT["trust tier"]
    S -- "has a" --> ID["session identity / token"]
    S -- "makes" --> GC["governed calls<br/>(tool, model, egress)"]
    GC -- "through the" --> G["gateway"]
    G -- "applies" --> P["policy → rule → action"]
    P -- "gives a" --> D["decision"]
    D -- "may need an" --> AP["approval"]
    D -- "written to the" --> L["audit ledger"]

Terms#

Term Definition UI label Don't use
action What a rule says to do with a matching call: allow, deny or require approval (require_approval in YAML). Allow, Deny, Require approval permit, block, reject, HITL, ask
agent An AI program that uses tools, described to MAQPNA by an Agent resource (image, trust tier, tools, policy, budget). The agent is the definition; it runs as sessions. Agent bot, assistant, AI worker, workload (in UI), app
agent-sandbox Only the name of the upstream Kubernetes project, kubernetes-sigs/agent-sandbox, that MAQPNA builds on. Always hyphenated and in code formatting or linked. — "agent sandbox" for a MAQPNA sandbox
approval A tool call that a rule held for a human decision, and that decision. An approval is pending, then approved, denied or expired. Approval confirmation, sign-off, review, HITL, human-in-the-loop (except in marketing explanations), request
approve / deny The two human decisions on an approval. Approving lets exactly that one call run. Approve, Deny accept/reject, allow/block, confirm/cancel
approver A person with the approver role for a namespace. Approvers cannot approve calls made on their own behalf. Approver reviewer, admin (unless they are one)
attestation Hardware proof that a tier-2 sandbox is a genuine confidential VM. Identities for tier-2 are issued only after it passes. Attestation, Attested verification (alone), remote proof
audit ledger The append-only, hash-chained record of every decision, approval, revocation and result. Can be shipped to WORM storage. Audit ledger (nav: Audit) audit log, audit trail, decision log, logs, history, journal
audit record One entry in the audit ledger. Record event, log line, entry (in UI)
break-glass An emergency action outside the normal path, such as the static admin token. Always hyphenated. Break-glass emergency, override, god mode
budget A spending limit for an agent, namespace, user or tenant over a day or a month. Set in Agent.spec.budget or a BudgetPolicy. Budget quota (that is a Kubernetes resource limit), cap, credits, allowance
checkpoint A signed statement of the ledger head at a point in time. Checkpoint snapshot, seal
CLI The maqpna command. Its lifecycle plugin is maqpna-install. CLI the client, maqpnactl
console The web UI served by the gateway (maqpna console). Its full name in titles is MAQPNA Console. Console dashboard, admin panel, portal, UI
cost The metered price of one call or session, in the configured currency. Cost price, charge, fee (fees are commercial)
decision What the gateway did with one call: allowed, denied, or held for approval. Every decision is written to the audit ledger with the policy and rule that made it. Allowed, Denied, Held for approval verdict, outcome, result (that is the session's result)
default deny No matching rule (or no policy) means the call is denied. Hyphenate before a noun: "default-deny egress". Default deny deny by default, implicit deny, fail open/closed (except for component failures)
desktop app The desktop app started by maqpna desk. Full name MAQPNA Desk. Desk client app, launcher
DLP Data loss prevention: the gateway's checks that find and block or redact sensitive data (keys, personal data) in arguments and results. Spell out on first mention on every page. DLP data filter, PII scanner, content filter
drift A tool definition that changed after it was pinned (a "rug pull"). Drifted tools are hidden and denied until reviewed. Drift mismatch, tamper, rug pull (except as the explanation)
edition A licensing package. The editions are Community, Team, Enterprise, Sovereign and Operator. Write "the Sovereign edition" in prose; the name alone on cards and buttons. Community, Team, Enterprise, Sovereign, Operator Sovereign Edition (capital E), plan, tier (tier means trust tier)
egress Network traffic leaving a sandbox. Sandboxes have default-deny egress; allowed egress goes through the gateway. Egress outbound, internet access
erasure Deleting everything a memory store holds about a user (GDPR Art. 17), with a signed erasure certificate. Erasure, Erase purge, wipe, forget, delete (in UI)
evidence bundle An exported, verifiable package of audit records (and related objects) for one session, period or system. Evidence bundle, Export evidence report, dump, archive
four-eyes approval An approval that needs two different approvers. Four-eyes quorum (in UI), dual control, two-man rule
gateway The MAQPNA component every tool, model and egress call passes through. It verifies identity, evaluates policy, checks DLP, budgets and taint, asks for approval and writes the audit record. First mention: "the MAQPNA gateway". Gateway proxy, tool-call gateway, MCP gateway, firewall, broker
governed call Any tool, model or egress call that passed through the gateway and got a decision. This is the metered unit. Governed call transaction, request, API call
identity broker The component that issues each session a short-lived, signed identity (SPIFFE-style) and token. Identity broker token service, auth server, STS, IdP
identity provider The customer's OIDC single sign-on system (Keycloak, Entra ID, Okta). Identity provider IdP (in UI), SSO server, auth provider
installation One running MAQPNA: the operator, gateway and identity broker in one cluster (or one maqpna dev stack on a laptop). Installation instance, deployment (for the whole thing), environment, tenant
jurisdiction The country or region whose law applies to an installation, as declared in the sovereignty policy (EU-DE). Jurisdiction region (unless it is a cloud region), locale, residency zone
kill switch The capability to stop an agent, session, user or token across the installation within about a second (maqpna kill). Kill switch panic button, emergency stop, killswitch (except the role name)
local MAQPNA The laptop stack started by maqpna dev up: identity broker, gateway and a test MCP server, no Kubernetes. Local (dev) dev cluster, sandbox mode, playground
MAQPNA The product: the sovereign runtime for AI agents. Always in capitals in prose, headings and titles, including at the start of a sentence. Spoken "mak-pna". MAQPNA Maqpna, MaqPNA, maqpna (in prose), "the MAQPNA platform"
maqpna The CLI binary, package, Helm chart, image prefix, domain and URL paths. Lower case, always in code formatting. — MAQPNA (for the command)
Maqpna Only inside code identifiers that require Pascal case: MaqpnaClient, MaqpnaError, HTTP headers X-Maqpna-*, the Cedar namespace Maqpna::. Never in prose. — —
MCP server A server that offers tools over the Model Context Protocol. Kind: MCPServer. In gateway config they are upstreams; in prose and UI they are MCP servers. MCP server tool server, upstream (in UI), connector, plugin, integration
memory store Governed long-term memory for agents, scoped by agent and user. Kind: MemoryStore. Memory store vector store, knowledge base, cache
model call One request from a session to a model through the gateway's model route (/llm). Model call LLM request, completion, inference call
namespace A Kubernetes namespace. Teams and environments are namespaces; policies, agents and sessions are namespaced. Namespace project, space, workspace, environment
operator The MAQPNA Kubernetes controller (maqpna-operator) that turns Agent and AgentSession resources into sandboxes, tokens and network policies. In product docs "operator" always means this component. Operator controller (alone), manager, the data-center operator (write "service provider")
platform team The people who install and run MAQPNA in their organisation. — ops, admins (unless you mean the admin role), DevOps
policy A named set of rules for which agents may call which tools, and how. Kind: ToolPolicy. A policy has a default action and an ordered list of rules. Policy guardrail, ACL, permission set, rule set, ruleset
redact Replace sensitive data with a marker before it leaves the gateway. Redact, Redacted mask, scrub, sanitise
result What a session reported when it ended: Succeeded or Failed, with a summary. Result outcome, exit status
revocation One kill-switch entry: what is revoked, by whom, until when. Kind: AgentRevocation, or a break-glass entry at the gateway. Verb: revoke. Revocation, Revoke block, ban, disable, quarantine
role A permission set in the admin API: admin, approver, auditor, killswitch, optionally per namespace. Role permission, group (groups come from the identity provider)
rule One entry in a policy. It matches calls (server, tool, arguments, taint) and gives an action. Rule policy (for one entry), condition (a condition is part of a rule), filter
sandbox The isolated environment one session runs in: a gVisor container, a Firecracker microVM or a confidential VM, with default-deny networking. Created through the upstream agent-sandbox project. Sandbox container, pod (in UI copy), VM (unless the tier is a VM), agent sandbox (as a MAQPNA noun)
SDK The Python, TypeScript and Go libraries agents use to call tools through the gateway. SDK client library, agent kit
service provider A company that runs MAQPNA to host agents for its customers (a neocloud, colocation provider, telco or ISV). Buys the Operator edition. Service provider operator (that word is the component), reseller (in product copy)
session One run of an agent, from start to result, with its own sandbox, identity and token. Kind: AgentSession. Every governed call belongs to exactly one session. Session agent session (except on first mention), run (as a noun), instance, job, task, execution, conversation
session identity The signed identity of one session: agent, tier, namespace, user it acts for, scopes. Identity credentials, service account
signing key A key that signs identities, audit checkpoints or licences. The customer holds it (file, PKCS#11 HSM or KMS). Signing key master key, root key, secret
snapshot A saved session that can be resumed or forked. Kind: AgentSessionSnapshot. Snapshot checkpoint (that word belongs to the audit ledger)
sovereignty policy The cluster-wide rules on jurisdiction, registries, egress and attestation that every session is admitted against. Kind: SovereigntyPolicy. Sovereignty policy compliance policy, residency rules
spend Metered cost so far in a budget window. Spend usage (usage means metered units, see below), burn, consumption
taint A label on a session that has read untrusted content (for example a web page or a public issue). Rules can then deny, or require approval for, tools that could leak data. Taint, Tainted contamination, flag, mark, quarantine
tenant A customer of a service provider that runs MAQPNA for others (ISV, MSP, data-center operator), with its own namespaces, trust domain, signing key, ledger and quotas. Kind: Tenant. Tenant org, organisation, organization, workspace, account, customer (in UI)
third-party register The DORA Art. 28 list of ICT third-party providers (MCP servers, model routes) that agents used, built from the ledger. Third-party register vendor list, supplier report
timeline The ledger-ordered view of what one session did. Timeline history, trace (traces are OpenTelemetry), log
token The bearer form of a session identity, or an admin-API access token. Always say which: "session token", "access token". Session token, Access token key, secret, JWT (in UI)
tool A function an agent can call, offered by an MCP server. Written server.tool in UI (echo.delete_resource). Tool action (an action is the policy outcome), function, skill, capability
tool call One request from a session to a tool. Tool call invocation, request (in UI), action
tool pinning The gateway records a hash of each tool's definition. A pin is that hash. Pinned lock, fingerprint, allow-list (for this)
trust tier The isolation level a session runs at. tier-0 gVisor, tier-1 Kata + Firecracker microVM, tier-2 confidential VM with attestation. Kind: TrustTier. Always write the tier with its runtime on first mention: "tier-1 (microVM)". Trust tier isolation level, security level, runtime tier, plan, tier (alone, on first mention)
usage Metered units for billing: sandbox seconds, governed calls, model tokens, approvals. Usage consumption, metering data
user approval An approval by the person the agent acts for, on their own device (CIBA). User approval user confirmation, push confirmation, step-up
verify Recompute the hash chain and signatures to prove nothing was changed or removed. Verify validate (validate is for manifests), check
warm pool Pre-started sandboxes that make sessions start fast. Warm pool cache, standby pool

Words to expand on first use#

Term Write instead, or expand as
HITL "human approval"
MCP "Model Context Protocol (MCP)" on first use; then "MCP"
A2A "agent-to-agent (A2A)" on first use
CoCo, SEV-SNP, TDX "confidential VM (AMD SEV-SNP or Intel TDX)"
SPIFFE / SVID "workload identity (SPIFFE)"
CIBA "user approval on their own device (CIBA)"
WORM "write-once storage (WORM)"
FOCUS "FOCUS, the FinOps cost-export format"
RTO / RPO spell out in UI: "recovery time", "data-loss window"
fail closed "if X is unavailable, calls are denied"
rug pull "a tool whose definition changed after it was pinned (drift)"
JWKS "the broker's public keys (JWKS)"

Kubernetes kinds and their plain names#

All kinds are in the API group maqpna.com/v1alpha1. See the CRD data model.

Kind Plain term Short name
Agent agent —
AgentSession session asess
AgentSessionSnapshot snapshot asnap
TrustTier trust tier tier
ToolPolicy policy tp
SovereigntyPolicy sovereignty policy sovpol
BudgetPolicy budget bp
MCPServer MCP server mcps
AgentRevocation revocation arev
A2APeer A2A peer a2ap
ConnectedAccount connected account conn
MemoryStore memory store mem
Tenant tenant tn

Status words#

Every surface shows these states with the same word and colour, and never relies on colour alone.

State Word
A call was allowed, a check passed, a chain verified Allowed / Passed / Verified
A call was denied, a check failed, a chain broken Denied / Failed / Broken
A call is waiting for a human Pending approval
Something works but is weaker than recommended Warning
Neutral facts, help, links to docs Info
Expired, cleared, not applicable Expired / Cleared / —