Vendor / operator
The vendor’s application, workflow engine, MCP client, A2A client, or optional operator-side agent creates the request.
Legation separates vendor orchestration, routing, and customer enforcement into explicit trust boundaries. The customer’s Embassy is where workloads are verified, authorized, executed, observed, and stopped.
The vendor’s application, workflow engine, MCP client, A2A client, or optional operator-side agent creates the request.
The hub authenticates, routes, queues, coordinates, and observes fleet connectivity without becoming the customer’s local execution environment.
The Embassy verifies the workload and request, enforces treaty and mandate rules, invokes local services, produces evidence, and controls what may return.
The vendor application identifies the customer Embassy and target workload: an MCP service, an A2A agent, or a native service.
Legation binds the request to workload identity, authorization context, anti-replay state, and policy metadata.
The hub forwards the sealed request over the outbound-established secure link and correlates the response path.
The Embassy verifies identity, treaty, mandate, cargo, and policy before local execution is allowed.
An approved agent, MCP server, or other service works next to customer data and systems.
The Embassy governs the output, records evidence, and returns only the permitted result.
| Mode | Operator side | Customer side | Best for |
|---|---|---|---|
| Known tool call | Application or MCP client | MCP server (in-VPC) | Known tool calls and deterministic operations |
| A2A delegation | Application or operator-side agent | Agent → MCP server | Goals, reasoning, planning, multi-step work |
| Native service | Application SDK / API | Customer service | Traditional software operations without agents |
Customer-sensitive data is processed inside the customer boundary. The customer-side workload returns a governed projection, decision, structure, or result rather than unrestricted source data.
The Embassy is designed to retain local policy enforcement during degraded hub connectivity. Queued work, replay boundaries, regional routing, and explicit fail-closed behavior prevent a control-plane outage from silently turning into unrestricted execution.
Latency and health-based routing can move Embassy connections to a surviving region.
The customer-side enforcement boundary continues applying local policy rather than defaulting open.
Customer-controlled stop and recall mechanisms provide an explicit path to halt approved cargo.
| Layer | Representative components | Purpose |
|---|---|---|
| Envelope | Seal, Manifest, Enclave | Package, describe, verify, and govern approved cargo |
| Conduit | Ingress, Link, MCP | Transport requests and protocol operations across boundaries |
| Control plane | C2, Serve, Console | Coordinate Embassies, dispatch work, and operate fleets |
| Trust spine | Identity, Crypto, PQ Crypto, Custody, Transparency | Identity, key protection, proof, and cryptographic integrity |
| Proof | Compliance, Observability, CLI | Evidence, telemetry, validation, and operational workflows |