Flagship platform / Alpha Lyrae
VEGA
Autonomous network management, governed by evidence.
VEGA sits above an existing multi-vendor estate as an evidence, assurance, and governed-work plane. Operators state intent in plain language; VEGA compiles it into a task graph, gathers deterministic vendor evidence, runs until a human gate, and hands consequential change to an apply surface that demands a digest and clearance.
- Vendor surfaces
- 85+
- Domain agents
- 126
- Native tools
- 15
- Native vendor engines
- 6
Thesis
Many consoles hold the truth. None of them owns the work.
Network security estates are run through many consoles: Panorama, SmartConsole, Catalyst Center, the Meraki dashboard, Aruba Central. Each holds part of the truth, and none of them is responsible for the work that crosses them.
VEGA does not replace those systems and is not a second orchestrator. It reads them, normalizes their evidence, and turns operator intent into governed work: a compiled graph that collects evidence, plans, stops for a human, and only then hands a change to a surface that proves what will be applied.
- PRINCIPLE 01
Deterministic truth before AI opinion
Models comment on evidence. They do not replace it. Vendor APIs and native tools produce the facts a plan is built on.
- PRINCIPLE 02
Intent before vendor syntax
Work is compiled from an objective, not pasted as raw CLI. The same intent can land on Palo Alto, Check Point, Cisco, Meraki, or Aruba.
- PRINCIPLE 03
Human authority before autonomous execution
Human-in-the-loop is a gate, not theatre. Approval unblocks the next node; it never applies configuration by itself.
- PRINCIPLE 04
Evidence before trust
An empty vendor link is a finding, not a bounce. The graph records that nothing was linked; it never invents devices.
- PRINCIPLE 05
Fail closed
Missing vendor links, missing clearance, and unsupported validation stay stopped. Required twin and test nodes fail closed when their runner is absent.
Governed work path
Intent compiles into a graph. The graph stops for a human.
Composer, Work Control, and Team Chat assign work through one task endpoint and compile the same graph. It auto-runs until it must wait, and approval unblocks the next node without ever applying configuration by itself.
-
Operator intent
A plain-language objective in Composer, a task on the Work Control board, or a mention in Team Chat. All three call the same task endpoint.
-
Compile graph
The objective compiles into a module DAG: evidence, plan, HITL, effect, verify, plus any skill, Ansible, or Terraform nodes it names.
-
Gather evidence
Native vendor engines collect inventory, health, sessions, and revisions. Sidecars load only if the graph names them.
-
Human gate(human approval gate)
The graph auto-runs until a skill prompt, HITL gate, completion, failure, or blocked handoff. Four-eyes nodes require a different actor and a note.
-
Apply with clearance
VegaAnsible check, VegaTerraform plan, or a vendor handoff. Apply requires the approved digest and the Work Control task id.
-
Verify
Observe on the vendor console or with the verify module. A task cannot be marked complete until its graph completed.
One orchestration plane
Three ways in. One runtime.
Source is audited but never picks a runner and never approves. There is no second MCP or apply path around the graph.
- /composer
Composer
Pinned at the top of the rail. Classifies a plain-language objective and opens a task bound to the conversation. Asking how VEGA works cites the operators manual instead of opening work. With tools off, it collects no vendor evidence; with an unqualified intent, it names the gap rather than inventing a plan.
- /agents/work
Work Control
The board from backlog to completed. Create, assign, update, and delete tasks; compile, advance, approve, and reject graph nodes; approval mode and tools toggle on the create form and drawer. Completion is blocked until the graph completes.
- /agents/team-chat
Team Chat
Rooms where operators mention an agent by id or send without a mention for concierge auto-route. Estate work creates the same task and graph as Composer; a chat message never applies.
Approval modes bind skill use, never vendor apply
| Mode | Skill use | Vendor apply |
|---|---|---|
| ask | Prompt before every use. Unknown capability is treated as privileged. | HITL, digest, and task clearance still required |
| readonly-auto | Read-like skill use may run; write and exec still prompt. | Still gated |
| session | Reuse this session's grant for skill use. | Still gated |
Apply with clearance approval is not apply
| Surface | What it does | Gate |
|---|---|---|
| VegaAnsible | Registers playbooks and workbooks, runs check mode as evidence, records the check digest. ansible.check, ansible.apply | Check digest plus task clearance |
| VegaTerraform | Brownfield, import-first workspaces. Plans are evidence with a digest. terraform.plan, terraform.apply | Plan digest plus task clearance; expired or unapproved plans refuse |
| Vendor console | Commit, publish, install policy, or action batch, handed off on the graph. pa.commit, pa.push, cp.publish, cp.install-policy, meraki.action-batch | Handoff behind HITL; never invented by Composer |
Multi-vendor evidence
Five vendor estates, read natively.
Vendor truth stays on vendor systems. VEGA reads it through native Rust engines, compiles work against it, and fails closed when a link is empty. Inventory, policy, session, and hygiene pages are evidence surfaces, never a second Composer.
Command and inventory 6
Panorama Command Center
HA pair health and operations overview for the management plane.
Panorama Inventory
Managed firewall and fleet inventory.
Prisma / Strata Inventory
Strata Cloud Manager and Prisma Access tenants.
Dominion
Device-group hierarchy.
Health Monitor
Device CPU, memory, and health.
SDSC Dashboard
Software-defined security control coverage.
Policy engineering 8
Policy Browser
Read the rulebase.
Policy Enumeration
Exhaustive verification of every rule.
Policy Forge
Policy engineering workspace: plan, never a silent push.
Policy Hygiene
Unused and cleanup candidates.
Policy Density
Rule density, complexity, and scope.
Hitmap 360
Hit-count analytics.
Overlap Analysis
Shadowing and redundancy.
Policy Drift
Baseline versus observed policy.
Path, sessions, and change 8
Blast Radius
Impact simulation for a change or rule. Does not revert configuration.
Session Oracle
Session lookup.
NAT Path
NAT translation path.
Route Sentry
Routing, BGP, and OSPF evidence.
Timewarp
Snapshots, schedules, and health trend. No restore without a gated path.
Troubleshoot
Incident and expert diagnosis.
Request Engine
Firewall access requests from a service desk, still never auto-applied.
PAN-OS Lifecycle
Governed fleet upgrade campaigns (see below).
Logs 3
Syslog
Device syslog.
Logr
Traffic log analysis and rule-optimization evidence.
Prisma / Strata Syslog
Cloud-managed logs.
PAN-OS lifecycle governance
Fleet upgrades as governed campaigns.
Nothing disruptive executes without independent human approval, and the server is authoritative.
- 01 Plan
- 02 Submit
- 03 Approve
- 04 Start
- 05 Wave by wave
- Approval independence
- The creator of a campaign cannot approve it. Agent-proposed campaigns always require a human approver.
- Break glass
- When the creator is the only operator, an administrator may break glass with a recorded justification and a second, distinct witness identity. Both identities enter the audit chain.
- Waves and canaries
- The approved wave order and canary membership is exactly what runs. The next wave waits for the previous to pass; a failed canary blocks the campaign.
- Progression
- Manual by default. Auto-progression is opt-in per campaign and never applies to HOLD or FAIL verdicts.
- Windows and freezes
- A bound maintenance window must be open to admit devices; an active freeze overrides everything in scope. Overrun policy controls admission near the close.
- Server-authoritative
- Closing the browser does not pause, advance, approve, or un-gate anything.
- Tamper-evident audit
- Every approval, progression, hold, and verdict is written to a hash-chained event journal, with an on-demand chain verification.
Native tooling
Fifteen engineering instruments, each with a hard boundary.
Every native tool is a VEGA console whose evidence can join a task graph. Each one also states what it will never do.
VegaDNS
Forward lookups across ten record types, multi-resolver comparison, reverse PTR, and propagation checks.
NeverChange authoritative zones.
VegaSNMP
Walk and get inspection for devices that expose SNMP.
NeverWrite community strings into task outputs.
VegaProbe
Ping, port checks, traceroute, and MTU-oriented reachability.
NeverOpen a change window or apply ACL or NAT.
VegaBGP
Route inspection, RPKI route-origin validation, and prefix-list dry-runs.
NeverInject routes into a live RIB.
VegaFlow
NetFlow and sFlow intake and inspection.
NeverChange sampling on devices.
VegaPCAP
Packet capture ingest and inspection.
NeverStart a SPAN session without a separate gated action.
VegaPerf
Bandwidth, iperf-style measurement, and QoS-oriented checks.
NeverRe-mark DSCP on the estate.
VegaIPAM
IP and subnet inventory held by VEGA.
NeverBecome a second NetBox or Infoblox source of truth.
VegaCalc
CIDR, mask, and host subnet math.
NeverAllocate addresses on the estate.
VegaCert
Certificate inventory, alerts, import, and export.
NeverSilently replace device certificates.
VegaVault
Stores references to secrets, with explicit lock and unlock.
NeverWrite secret values into outputs, traces, or citations.
VegaWake
Wake-on-LAN to a MAC or broadcast target.
NeverAuthenticate as a vendor API.
VegaCVE
Vendor advisory feeds joined to inventory: exposure, catalog, and refresh.
NeverPatch devices. Findings only.
VegaNetmiko
Read-only show commands over registered SSH connections across multi-vendor platforms.
NeverExecute configuration commands.
Data Formulator
Load a source, filter, aggregate, pivot, and preview a chart.
NeverPush transformed data into vendor state.
Agent fabric
126 domain agents. Zero apply authority.
A 126-agent domain roster organized into guilds, with qualification levels (qualified, provisional, unqualified) and tiers. Every profile shows what the agent owns, its playbooks, capabilities, and system prompt. Operators can rate agents and request adjustments; a rating never skips HITL.
Agent roster
Guilds, qualification, tiers, and full agent profiles.
Skills library
Imported skills by origin, kind, and status. On the graph a skill is prompted for use by approval mode, then attached as context. Skills are never apply authority.
Task pipeline
Live Work Control tasks overlaid on canonical and per-scenario DAGs, with origin counts across Composer, Team Chat, and Work Control.
Work log
The audited record of source, compile, advance, and approval events.
- Protocol
AG-UI
awaiting_approval is the HITL pause; approving a node is resume.
- Protocol
Agent-to-Agent (A2A)
Documented binding onto the same task runtime.
- Protocol
Agent Client Protocol (ACP)
Documented binding; no second task runtime.
MCP stance native engines, not child processes
Community MCP servers are catalogued as a reference and never launched: starting one or calling its tools returns 409. Estate work uses native Rust engines on the compiled graph, and vendor credentials stay in an encrypted connection registry instead of being injected into child processes.
- Read mode hides write tools from tool listings
- Optional JSONL audit of every call
- TLS verification on by default
- Safety test suite for the native apps
Native MCP apps for external clients
- vega-mcp-panos
- Replaces community PAN-OS and Strata SCM servers.
- vega-mcp-meraki
- Replaces the hosted Meraki two-tool pattern.
- vega-mcp-cisco
- Replaces Catalyst Center, FMC, and pyATS servers.
- vega-mcp-aruba
- Replaces Aruba Central and AOS-CX servers.
- vega-mcp-fwrule
- Offline firewall-rule analysis with no credentials.
Automation, assurance, integration
Callable modules on one graph, not extra runtimes.
Task Pipeline
Advance, compile, approve, and reject the same graph Composer and Team Chat use.
Ansible
Register playbooks, run check mode for a digest, approve the check record, apply only with clearance.
Terraform
Brownfield, import-first workspaces; plan with a digest, apply only with clearance.
Digital Twin
Batfish reachability when the graph names it. A missing snapshot fails closed.
Test Automation
pyATS and Genie when the graph names it. A missing testbed fails closed.
Event Automation
Signals may open tasks. They must never bypass HITL.
Compliance & Drift
NetBox, Infoblox, and vendor state as authorities, not a second inventory.
Automation paths
Ansible, Terraform, REST, NETCONF, gNMI, and SSH catalogued as paths, not extra orchestrators.
- Integration
Platforms Catalog
Vendor and platform matrix by domain and capability. Queue onboarding or a qualification sweep as a governed task.
- Integration
Capability Domains
Firewall, network, SASE, IAM, security, and cloud.
- Integration
Qualification
Tested, certified, preview, and unqualified tiers for every integration.
- Integration
Onboard a Vendor
Manifest, adapter, and SDK path for new vendors. Still compile, then HITL.
- Integration
Diagrams
Embedded draw.io, DrawDB, and Mermaid editors. A drawing is evidence, never clearance.
Identity and administration
Every account personal. Every mutation authorized.
- Sign-in
- Local accounts, LDAP, and OIDC authorization code with PKCE. Unknown identity-provider groups never become admin.
- Sessions
- Bearer sessions with per-session or per-user revocation.
- Roles
- Write-capable roles are required for every mutating API call; read-only accounts inspect but cannot change.
- Administration
- Admin-tagged accounts only: users, MFA posture, lockout, directory, audit export, maintenance mode, login banner, database maintenance, backup and recovery posture, ingress policy, platform certificates, and the vendor authority registry.
- Personal workspace
- Appearance, sidebar pins, recent items, and the handbook follow the signed-in user, not the browser profile.
- Operators manual
- A nineteen-chapter handbook served in Settings and searched by Composer when asked how VEGA works.
Security posture fail closed by default
- API edge serves TLS on loopback by default
- Empty vendor links, missing clearance, and missing runners fail closed
- Four-eyes approvals require a different actor and a recorded note
- Rejections require a recorded reason
- Apply requires the approved digest and the Work Control task id
- Admin status never bypasses apply HITL
- Secrets stored as vault references, never written into task outputs
- Capability sidecar fetch is SSRF-safe; browser sessions are read-only
- Community MCP is never spawned; native engines only
- Lifecycle decisions written to a hash-chained journal
What VEGA is not
- A replacement for Panorama, SmartConsole, Catalyst Center, or the Meraki dashboard
- A second orchestrator: Composer and Work Control are two views of the same task endpoint
- Closed-loop vendor apply without operator clearance
- A runtime for skills as apply authority
- A silent skip of missing vendor links
Architecture
Rust at the edge, native engines underneath.
A Cargo workspace of native crates behind an Axum edge, a SvelteKit console with desktop bindings, and Python sidecars that load only when a compiled graph names them.
Experience
- SvelteKit
- Vite
- Static adapter
- Tauri bindings
Operator console with command palette, pins, recents, and per-user appearance: themes including sky-realism palettes, type, density, UI scale, motion, contrast, and transparency.
Edge
- Rust
- Axum
- TLS
- SQLite
vega-api serves same-origin REST and WebSocket, authenticates every gated call, and persists runtime state.
Agents
- vega-agents
- vega-playbooks
Compile, persist, run until gate, skill matching, and HITL. Auto-advance is capped and never auto-approves.
Vendor engines
- vega-pa
- vega-cp
- vega-meraki
- vega-nxos
- vega-aruba-cx
- vega-aruba-central
Evidence and bounded adapters. An empty link fails closed.
Sidecars
- vega-capability
- vega-assurance
- Python
- Playwright
- pyATS
Ingest, SSRF-safe fetch, read-only browser extraction, and lab assurance. Loaded only when a compiled graph names them.
Foundations
- vega-tools
- vega-crypto
- VegaVault
Native tools, cryptography, and secret references.
Next
Bring evidence and human authority to a multi-vendor estate.
VEGA is in active development as a working build. Conversations about fit, pilots, and architecture are welcome.