MAQPNADocs

Guides

Task-oriented walkthroughs: write a policy, require approval, run an agent, use the kill switch.

Your first governed agent in 5 minutesStart a local MAQPNA, make an allowed and a denied tool call, hold one for approval, and read the session timeline and audit ledger.Run your own agent under maqpna dev runPoint a Python, TypeScript or Go agent at the local MAQPNA gateway with the SDK, handle denials and approvals, and report the session result.Use a framework templateStart from the LangGraph, OpenAI Agents SDK or Claude Agent SDK template, run it against the scripted model, then validate and deploy it to a cluster.Connect MCP servers and pin toolsPut your own MCP servers behind the MAQPNA gateway, locally and with the MCPServer resource, and pin tool definitions so a changed tool is hidden and denied.Write and test policiesWrite MAQPNA policies with rules that allow, deny or require approval, add Cedar where you need it, and prove them with maqpna policy test, eval and replay before they reach the gateway.Human approvalsHold risky tool calls for a person, decide them from the CLI, MAQPNA Desk or the console, and set up four-eyes approval, approver groups and user approval (CIBA).Protect data with DLP profilesConfigure MAQPNA's data loss prevention (DLP) profiles to deny or redact card numbers, IBANs, national IDs and secrets in tool arguments, tool results, prompts and completions.Taint and prompt-injection containmentLabel tools that return untrusted content, taint the sessions that read it, and deny or hold exfiltration-capable tools for those sessions until a person has reviewed them.Budgets and cost limitsPrice tool and model calls, cap spend per agent, namespace, user and session, and read spend with maqpna budgets, costs and session cost.Generate a compliance evidence packBuild a signed, auditor-ready evidence pack for the EU AI Act, DORA or ISO/IEC 42001 from the audit ledger, and verify one offline.Kill switch and revocationsStop an agent, session, user or token across the installation within about a second with maqpna kill, make the revocation durable with an AgentRevocation, and lift it after the incident.Audit ledger and evidenceRead the audit ledger, verify its hash chain and signed checkpoints, detect tampering, export evidence bundles and stream records to a SIEM or WORM storage.SessionsStart, list, inspect, control and delete sessions, read their timeline, logs, events and cost, and run commands in a session's sandbox.Multi-tenant setup for service providersHost agents for several customers on one installation, each as a tenant with its own namespaces, trust domain, signing key, audit ledger, admin login and quotas.LicensingInstall a MAQPNA licence, check its status and entitlements, and see how billable nodes are counted. A licence never blocks agent traffic.Usage metering and billingCount usage per tenant from the audit ledger and sessions, produce signed usage reports with a FOCUS cost export, verify them, and export pseudonymised reports for an air-gapped true-up.Sovereignty, confidential tiers and customer-held keysKeep agents, data and keys in your jurisdiction with a sovereignty policy, check manifests offline, run sessions in attested confidential VMs, and hold every signing key yourself.