Skip to main content
NamPost
Back
NamPost sandbox documentation
Docs
NamPost as scheme operator

NamPost as scheme operator

What NamPost ICT provisions, enforces, and supervises—not a passive API host.

The NamPost Innovation Sandbox is operated by NamPost ICT under the NPIF. Participants innovate; NamPost runs the trust fabric.

Operator responsibilities

  1. Provision — K8s operator (§4.11), air-gapped namespaces (§4.12), sandbox-type profiles.
  2. Synthetic data — Personas and DQ gates (§7.2, §7.7); no live MoF files (X-02).
  3. API & identity — Kong, JWT, step-up 2FA on every PIS; Keycloak + consent SLA.
  4. Fees — Tariff engine (§4.10) and DQ-03 drift monitoring.
  5. Observation Deck — Regulator dashboard, directives, audit export (§10.5.15, §13.4).
  6. Monitoring — PSD-12-aligned alerts and DR drills (§12.7).
  7. Lifecycle — LangGraph intake-to-exit (§6).
  8. Marketplace & hackathons — §3.7, §11.8.

NPIF controls (examples)

  • NPIF-CTL-INT-01 — single intake
  • NPIF-CTL-RTG-01 — BoN vs NAMFISA routing
  • NPIF-CTL-2FA-01 — PIS step-up
  • NPIF-CTL-SYN-01 — synthetic-only
  • NPIF-CTL-MOD-01 — module allowlist

Full matrix: NAMPOST_SANDBOX.md §8.0.

What NamPost does not do

  • Live grant files, production PANs, automatic licences, or ownership of your code.

Public overview: /how-it-works#scheme-operator.
Regulators: /regulator/observation.