Straza / architecture overview

planes
Straza system architecture Agent harnesses feed straza, the client PEP kit, which talks to strazad. strazad holds the policy engine and inline classifier, the two-tier MCP gateway with its native straza app, session tokens, SCIM, the credential broker, the admin API, the approval service with its mobile approver API and push delivery, the audit sentinel, and the event spine, backed by Postgres or SQLite and NATS. Externally: midPoint over SCIM, an OIDC IdP, upstream MCP servers behind the gateway, and a phone running the mobile approver. Hover a node to light its data paths; toggle a plane to filter. snapshot pull checkin → token /mcp audit batch OIDC device flow · JWKS creds injected SCIM 2.0 changes approve gate /v1/approver/* outbox publish kill switch · /v1/push AGENT HARNESSES UPSTREAM · IGA · PHONE straza client PEP kit local PDP · fail closed ~/.straza strazad control + data plane · one static binary APPROVAL · mode: approve Claude Code Codex CLI Gemini / AntigravityGemini CLI python agentkit hookless CLI · execexec CLI enterprise IdP OIDC device flow · JWKS policy engine PolicySet → snapshot ed25519 · deny-overrides classifier indirection scan no model · deny on signal MCP gateway /mcp server PEP · rps limit two-tier catalog PDP per tools/call /mcp/<server> session tokens ed25519 · 300 s TTL attestation gate SCIM 2.0 server users · roles (Groups) active:false ⇒ revoke native: straza app approval_request … credential broker sealed secrets · OAuth inject-only admin API · console /v1/admin CRUD changes feed · enroll approval service pending · exemptions grants · console · Slack push delivery relay · FCM · APNs · … content-free {v,ref,kind} approver API /v1/approver/* enroll · pending · decide event spine outbox → JetStream relay · CloudEvents 1.0 store Postgres · SQLite no request-path reads NATS JetStream audit · events push subjects audit hash chain sha256(prev‖\n‖ce) verify sentinel durable consumer · judges sessions · alert-only MCP servers upstream apps oci·command·remote midPoint / IGA SCIM out → Straza LiveSync in ← feed mobile approver the phone push + decide ECDSA P-256
Hover or tab a component to light its data paths and read a fact. Toggle a plane (top right) to filter edges: identity, policy, approval, audit, MCP. Dashed arrows are asynchronous.
What this shows

Agent harnesses funnel through straza, the client PEP kit: its local PDP decides every tool call against an ed25519-signed snapshot, no server and no database on the path. Its mcp mode proxies to the strazad MCP gateway, where a two-tier catalog (a shared role catalog refined by a per-session policy overlay) hides tools the subject could never call and the built-in native straza app serves approval_request / status / await for tickets. The inline classifier scans classify-gated calls. The approval service drives mode:approve across console, Slack, and the mobile approver API (/v1/approver/*), which sends each request to the approver's phone as a content-free push notification (the hosted relay, FCM, APNs, WebPush or UnifiedPush). Identity arrives over SCIM 2.0 and an OIDC IdP; changes flow back to the IGA over the cursored changes feed. Every decision is audited asynchronously into a SHA-256 hash chain; the sentinel judges whole sessions off the same stream, failing open with an alarm. Kill-switch revocations push in under 2 seconds; credentials inject upstream, never reaching the agent.