Flagship platform / Alpha Lyrae

VEGA

Autonomous network management, governed by evidence.

VEGA sits above an existing multi-vendor estate as an evidence, assurance, and governed-work plane. Operators state intent in plain language; VEGA compiles it into a task graph, gathers deterministic vendor evidence, runs until a human gate, and hands consequential change to an apply surface that demands a digest and clearance.

PROTOTYPE Working Build, Active Development
Named for Vega in the constellation Lyra: the same sky the product draws behind Composer, sign-in, and Settings.
Vendor surfaces
85+
Domain agents
126
Native tools
15
Native vendor engines
6

Thesis

Many consoles hold the truth. None of them owns the work.

Network security estates are run through many consoles: Panorama, SmartConsole, Catalyst Center, the Meraki dashboard, Aruba Central. Each holds part of the truth, and none of them is responsible for the work that crosses them.

VEGA does not replace those systems and is not a second orchestrator. It reads them, normalizes their evidence, and turns operator intent into governed work: a compiled graph that collects evidence, plans, stops for a human, and only then hands a change to a surface that proves what will be applied.

  1. PRINCIPLE 01

    Deterministic truth before AI opinion

    Models comment on evidence. They do not replace it. Vendor APIs and native tools produce the facts a plan is built on.

  2. PRINCIPLE 02

    Intent before vendor syntax

    Work is compiled from an objective, not pasted as raw CLI. The same intent can land on Palo Alto, Check Point, Cisco, Meraki, or Aruba.

  3. PRINCIPLE 03

    Human authority before autonomous execution

    Human-in-the-loop is a gate, not theatre. Approval unblocks the next node; it never applies configuration by itself.

  4. PRINCIPLE 04

    Evidence before trust

    An empty vendor link is a finding, not a bounce. The graph records that nothing was linked; it never invents devices.

  5. PRINCIPLE 05

    Fail closed

    Missing vendor links, missing clearance, and unsupported validation stay stopped. Required twin and test nodes fail closed when their runner is absent.

Governed work path

Intent compiles into a graph. The graph stops for a human.

Composer, Work Control, and Team Chat assign work through one task endpoint and compile the same graph. It auto-runs until it must wait, and approval unblocks the next node without ever applying configuration by itself.

  1. Operator intent

    A plain-language objective in Composer, a task on the Work Control board, or a mention in Team Chat. All three call the same task endpoint.

  2. Compile graph

    The objective compiles into a module DAG: evidence, plan, HITL, effect, verify, plus any skill, Ansible, or Terraform nodes it names.

  3. Gather evidence

    Native vendor engines collect inventory, health, sessions, and revisions. Sidecars load only if the graph names them.

  4. Human gate(human approval gate)

    The graph auto-runs until a skill prompt, HITL gate, completion, failure, or blocked handoff. Four-eyes nodes require a different actor and a note.

  5. Apply with clearance

    VegaAnsible check, VegaTerraform plan, or a vendor handoff. Apply requires the approved digest and the Work Control task id.

  6. Verify

    Observe on the vendor console or with the verify module. A task cannot be marked complete until its graph completed.

One orchestration plane

Three ways in. One runtime.

Source is audited but never picks a runner and never approves. There is no second MCP or apply path around the graph.

  • /composer

    Composer

    Pinned at the top of the rail. Classifies a plain-language objective and opens a task bound to the conversation. Asking how VEGA works cites the operators manual instead of opening work. With tools off, it collects no vendor evidence; with an unqualified intent, it names the gap rather than inventing a plan.

  • /agents/work

    Work Control

    The board from backlog to completed. Create, assign, update, and delete tasks; compile, advance, approve, and reject graph nodes; approval mode and tools toggle on the create form and drawer. Completion is blocked until the graph completes.

  • /agents/team-chat

    Team Chat

    Rooms where operators mention an agent by id or send without a mention for concierge auto-route. Estate work creates the same task and graph as Composer; a chat message never applies.

Approval modes bind skill use, never vendor apply

ModeSkill useVendor apply
askPrompt before every use. Unknown capability is treated as privileged.HITL, digest, and task clearance still required
readonly-autoRead-like skill use may run; write and exec still prompt.Still gated
sessionReuse this session's grant for skill use.Still gated

Apply with clearance approval is not apply

SurfaceWhat it doesGate
VegaAnsibleRegisters playbooks and workbooks, runs check mode as evidence, records the check digest.
ansible.check, ansible.apply
Check digest plus task clearance
VegaTerraformBrownfield, import-first workspaces. Plans are evidence with a digest.
terraform.plan, terraform.apply
Plan digest plus task clearance; expired or unapproved plans refuse
Vendor consoleCommit, publish, install policy, or action batch, handed off on the graph.
pa.commit, pa.push, cp.publish, cp.install-policy, meraki.action-batch
Handoff behind HITL; never invented by Composer

Multi-vendor evidence

Five vendor estates, read natively.

Vendor truth stays on vendor systems. VEGA reads it through native Rust engines, compiles work against it, and fails closed when a link is empty. Inventory, policy, session, and hygiene pages are evidence surfaces, never a second Composer.

Scope

Panorama, PAN-OS firewalls, Prisma Access and Strata Cloud Manager

Commit, push, and upgrade need HITL and an apply surface. Reading a page is never a commit.

Native engine and evidence

  • vega-pa
  • evidence.pa.inventory
  • evidence.pa.health

Gated handoffs

  • pa.commit
  • pa.push

Command and inventory 6

  • Panorama Command Center

    HA pair health and operations overview for the management plane.

  • Panorama Inventory

    Managed firewall and fleet inventory.

  • Prisma / Strata Inventory

    Strata Cloud Manager and Prisma Access tenants.

  • Dominion

    Device-group hierarchy.

  • Health Monitor

    Device CPU, memory, and health.

  • SDSC Dashboard

    Software-defined security control coverage.

Policy engineering 8

  • Policy Browser

    Read the rulebase.

  • Policy Enumeration

    Exhaustive verification of every rule.

  • Policy Forge

    Policy engineering workspace: plan, never a silent push.

  • Policy Hygiene

    Unused and cleanup candidates.

  • Policy Density

    Rule density, complexity, and scope.

  • Hitmap 360

    Hit-count analytics.

  • Overlap Analysis

    Shadowing and redundancy.

  • Policy Drift

    Baseline versus observed policy.

Path, sessions, and change 8

  • Blast Radius

    Impact simulation for a change or rule. Does not revert configuration.

  • Session Oracle

    Session lookup.

  • NAT Path

    NAT translation path.

  • Route Sentry

    Routing, BGP, and OSPF evidence.

  • Timewarp

    Snapshots, schedules, and health trend. No restore without a gated path.

  • Troubleshoot

    Incident and expert diagnosis.

  • Request Engine

    Firewall access requests from a service desk, still never auto-applied.

  • PAN-OS Lifecycle

    Governed fleet upgrade campaigns (see below).

Logs 3

  • Syslog

    Device syslog.

  • Logr

    Traffic log analysis and rule-optimization evidence.

  • Prisma / Strata Syslog

    Cloud-managed logs.

PAN-OS lifecycle governance

Fleet upgrades as governed campaigns.

Nothing disruptive executes without independent human approval, and the server is authoritative.

  1. 01 Plan
  2. 02 Submit
  3. 03 Approve
  4. 04 Start
  5. 05 Wave by wave
Approval independence
The creator of a campaign cannot approve it. Agent-proposed campaigns always require a human approver.
Break glass
When the creator is the only operator, an administrator may break glass with a recorded justification and a second, distinct witness identity. Both identities enter the audit chain.
Waves and canaries
The approved wave order and canary membership is exactly what runs. The next wave waits for the previous to pass; a failed canary blocks the campaign.
Progression
Manual by default. Auto-progression is opt-in per campaign and never applies to HOLD or FAIL verdicts.
Windows and freezes
A bound maintenance window must be open to admit devices; an active freeze overrides everything in scope. Overrun policy controls admission near the close.
Server-authoritative
Closing the browser does not pause, advance, approve, or un-gate anything.
Tamper-evident audit
Every approval, progression, hold, and verdict is written to a hash-chained event journal, with an on-demand chain verification.

Native tooling

Fifteen engineering instruments, each with a hard boundary.

Every native tool is a VEGA console whose evidence can join a task graph. Each one also states what it will never do.

  • VegaDNS

    Forward lookups across ten record types, multi-resolver comparison, reverse PTR, and propagation checks.

    NeverChange authoritative zones.

  • VegaSNMP

    Walk and get inspection for devices that expose SNMP.

    NeverWrite community strings into task outputs.

  • VegaProbe

    Ping, port checks, traceroute, and MTU-oriented reachability.

    NeverOpen a change window or apply ACL or NAT.

  • VegaBGP

    Route inspection, RPKI route-origin validation, and prefix-list dry-runs.

    NeverInject routes into a live RIB.

  • VegaFlow

    NetFlow and sFlow intake and inspection.

    NeverChange sampling on devices.

  • VegaPCAP

    Packet capture ingest and inspection.

    NeverStart a SPAN session without a separate gated action.

  • VegaPerf

    Bandwidth, iperf-style measurement, and QoS-oriented checks.

    NeverRe-mark DSCP on the estate.

  • VegaIPAM

    IP and subnet inventory held by VEGA.

    NeverBecome a second NetBox or Infoblox source of truth.

  • VegaCalc

    CIDR, mask, and host subnet math.

    NeverAllocate addresses on the estate.

  • VegaCert

    Certificate inventory, alerts, import, and export.

    NeverSilently replace device certificates.

  • VegaVault

    Stores references to secrets, with explicit lock and unlock.

    NeverWrite secret values into outputs, traces, or citations.

  • VegaWake

    Wake-on-LAN to a MAC or broadcast target.

    NeverAuthenticate as a vendor API.

  • VegaCVE

    Vendor advisory feeds joined to inventory: exposure, catalog, and refresh.

    NeverPatch devices. Findings only.

  • VegaNetmiko

    Read-only show commands over registered SSH connections across multi-vendor platforms.

    NeverExecute configuration commands.

  • Data Formulator

    Load a source, filter, aggregate, pivot, and preview a chart.

    NeverPush transformed data into vendor state.

Agent fabric

126 domain agents. Zero apply authority.

A 126-agent domain roster organized into guilds, with qualification levels (qualified, provisional, unqualified) and tiers. Every profile shows what the agent owns, its playbooks, capabilities, and system prompt. Operators can rate agents and request adjustments; a rating never skips HITL.

  • Agent roster

    Guilds, qualification, tiers, and full agent profiles.

  • Skills library

    Imported skills by origin, kind, and status. On the graph a skill is prompted for use by approval mode, then attached as context. Skills are never apply authority.

  • Task pipeline

    Live Work Control tasks overlaid on canonical and per-scenario DAGs, with origin counts across Composer, Team Chat, and Work Control.

  • Work log

    The audited record of source, compile, advance, and approval events.

  • Protocol

    AG-UI

    awaiting_approval is the HITL pause; approving a node is resume.

  • Protocol

    Agent-to-Agent (A2A)

    Documented binding onto the same task runtime.

  • Protocol

    Agent Client Protocol (ACP)

    Documented binding; no second task runtime.

MCP stance native engines, not child processes

Community MCP servers are catalogued as a reference and never launched: starting one or calling its tools returns 409. Estate work uses native Rust engines on the compiled graph, and vendor credentials stay in an encrypted connection registry instead of being injected into child processes.

  • Read mode hides write tools from tool listings
  • Optional JSONL audit of every call
  • TLS verification on by default
  • Safety test suite for the native apps

Native MCP apps for external clients

vega-mcp-panos
Replaces community PAN-OS and Strata SCM servers.
vega-mcp-meraki
Replaces the hosted Meraki two-tool pattern.
vega-mcp-cisco
Replaces Catalyst Center, FMC, and pyATS servers.
vega-mcp-aruba
Replaces Aruba Central and AOS-CX servers.
vega-mcp-fwrule
Offline firewall-rule analysis with no credentials.

Automation, assurance, integration

Callable modules on one graph, not extra runtimes.

  • Task Pipeline

    Advance, compile, approve, and reject the same graph Composer and Team Chat use.

  • Ansible

    Register playbooks, run check mode for a digest, approve the check record, apply only with clearance.

  • Terraform

    Brownfield, import-first workspaces; plan with a digest, apply only with clearance.

  • Digital Twin

    Batfish reachability when the graph names it. A missing snapshot fails closed.

  • Test Automation

    pyATS and Genie when the graph names it. A missing testbed fails closed.

  • Event Automation

    Signals may open tasks. They must never bypass HITL.

  • Compliance & Drift

    NetBox, Infoblox, and vendor state as authorities, not a second inventory.

  • Automation paths

    Ansible, Terraform, REST, NETCONF, gNMI, and SSH catalogued as paths, not extra orchestrators.

  • Integration

    Platforms Catalog

    Vendor and platform matrix by domain and capability. Queue onboarding or a qualification sweep as a governed task.

  • Integration

    Capability Domains

    Firewall, network, SASE, IAM, security, and cloud.

  • Integration

    Qualification

    Tested, certified, preview, and unqualified tiers for every integration.

  • Integration

    Onboard a Vendor

    Manifest, adapter, and SDK path for new vendors. Still compile, then HITL.

  • Integration

    Diagrams

    Embedded draw.io, DrawDB, and Mermaid editors. A drawing is evidence, never clearance.

Identity and administration

Every account personal. Every mutation authorized.

Sign-in
Local accounts, LDAP, and OIDC authorization code with PKCE. Unknown identity-provider groups never become admin.
Sessions
Bearer sessions with per-session or per-user revocation.
Roles
Write-capable roles are required for every mutating API call; read-only accounts inspect but cannot change.
Administration
Admin-tagged accounts only: users, MFA posture, lockout, directory, audit export, maintenance mode, login banner, database maintenance, backup and recovery posture, ingress policy, platform certificates, and the vendor authority registry.
Personal workspace
Appearance, sidebar pins, recent items, and the handbook follow the signed-in user, not the browser profile.
Operators manual
A nineteen-chapter handbook served in Settings and searched by Composer when asked how VEGA works.

Security posture fail closed by default

  • API edge serves TLS on loopback by default
  • Empty vendor links, missing clearance, and missing runners fail closed
  • Four-eyes approvals require a different actor and a recorded note
  • Rejections require a recorded reason
  • Apply requires the approved digest and the Work Control task id
  • Admin status never bypasses apply HITL
  • Secrets stored as vault references, never written into task outputs
  • Capability sidecar fetch is SSRF-safe; browser sessions are read-only
  • Community MCP is never spawned; native engines only
  • Lifecycle decisions written to a hash-chained journal

What VEGA is not

  • A replacement for Panorama, SmartConsole, Catalyst Center, or the Meraki dashboard
  • A second orchestrator: Composer and Work Control are two views of the same task endpoint
  • Closed-loop vendor apply without operator clearance
  • A runtime for skills as apply authority
  • A silent skip of missing vendor links

Architecture

Rust at the edge, native engines underneath.

A Cargo workspace of native crates behind an Axum edge, a SvelteKit console with desktop bindings, and Python sidecars that load only when a compiled graph names them.

  1. Experience

    • SvelteKit
    • Vite
    • Static adapter
    • Tauri bindings

    Operator console with command palette, pins, recents, and per-user appearance: themes including sky-realism palettes, type, density, UI scale, motion, contrast, and transparency.

  2. Edge

    • Rust
    • Axum
    • TLS
    • SQLite

    vega-api serves same-origin REST and WebSocket, authenticates every gated call, and persists runtime state.

  3. Agents

    • vega-agents
    • vega-playbooks

    Compile, persist, run until gate, skill matching, and HITL. Auto-advance is capped and never auto-approves.

  4. Vendor engines

    • vega-pa
    • vega-cp
    • vega-meraki
    • vega-nxos
    • vega-aruba-cx
    • vega-aruba-central

    Evidence and bounded adapters. An empty link fails closed.

  5. Sidecars

    • vega-capability
    • vega-assurance
    • Python
    • Playwright
    • pyATS

    Ingest, SSRF-safe fetch, read-only browser extraction, and lab assurance. Loaded only when a compiled graph names them.

  6. Foundations

    • vega-tools
    • vega-crypto
    • VegaVault

    Native tools, cryptography, and secret references.

Next

Bring evidence and human authority to a multi-vendor estate.

VEGA is in active development as a working build. Conversations about fit, pilots, and architecture are welcome.