MAQPNA

Telecom operators

Network-operations agents with a human gate on change.

An agent that can read alarms can save your NOC hours. One that can push config to the core network needs limits. MAQPNA lets agents diagnose freely, holds changes for an engineer and keeps every action on record.

The problem

Why NOC teams keep agents read-only

The blast radius of a wrong change is the whole network.

  1. Production changes

    A misconfigured change can take down service for millions of subscribers.

  2. Blast radius

    An agent with broad credentials can reach far more than the task needs.

  3. Change control

    Changes must follow the change process, with an engineer accountable for each.

  4. Subscriber data

    Subscriber identifiers and locations must not leak into prompts or logs.

How MAQPNA solves it

Diagnose freely, change carefully

  • Approval on change

    Rules hold config pushes, restarts and scaling for an engineer, and record who approved.

  • Per-tool, per-argument policy

    Allow reads everywhere; deny writes to production namespaces; rate-limit everything.

  • Isolation per session

    Sandboxes with default-deny NetworkPolicy contain what a session can reach.

  • Kill switch

    maqpna kill stops an agent across the installation within about a second.

  • DLP

    Redact subscriber identifiers before they reach a model or leave the gateway.

  • Policy testing

    Replay real traffic against a new policy and run policy test suites before rollout.

Architecture sketch

A network-operations agent in the NOC

The agent reads telemetry and tickets freely. Any change to network elements is held for an engineer, and production writes outside the change window are denied.

Operator network · NOC cluster · your keys

Sandboxes

tier-0 (gVisor) or tier-1 (microVM)

  • noc-triage
  • capacity-planner
  • ran-optimiser

MAQPNA gateway

identity · policy · DLP · budgets · approval · audit

  • Allowedoss.get_alarmsread-only-tools
  • Held for approvalnetconf.deploy_configdestructive-needs-human
  • Deniednetconf.patch prod-coreproduction-writes-blocked

Your systems

  • MCPOSS and alarms
  • MCPNETCONF adapter
  • MCPticketing
Hash-chained audit ledger · alerts and SIEM export
Illustrative. Agent, tool and rule names are examples; you write your own policies.

Evidence and oversight

Evidence for resilience and security reviews

Mapping only. MAQPNA gives you technical controls and evidence; it does not make a system compliant, and we hold no certifications.

  • NIS2: access control, logging and incident-response evidence for agent actions.
  • Change control: each change records the session, the rule, the approver and the result.
  • EU AI Act Art. 12 and 14: record-keeping and human oversight controls.
  • Honest scope: MAQPNA does not judge whether a change is correct; your engineers do.

Give your NOC a safe agent.

Tell us which operations you want to automate. We will map them to read, approve and deny rules.

curl -fsSL https://maqpna.com/install.sh | sh

No Kubernetes, GPU or API key needed to try it. Every download is checked against its SHA-256 and cosign signature.