Hey OMA3,
AI agents are beginning to operate inside real business systems, and recent failures show the risk when they act alone.
In July 2025, a Replit agent deleted SaaStr’s production database. In April 2026, an agent used by PocketOS deleted its production database while trying to resolve an unrelated issue.
Both incidents exposed the same weakness: one agent, holding one credential, could take a high-impact action without independent approval.
Introducing MPAS
MPAS, or Multi-Party Action Security, is OMA3’s new defense against this class of failure.
MPAS brings banking-style approvals to API calls and AI agents. Agents retain autonomy, but consequential actions require independently verifiable authorization—from other agents or humans—before they execute.
The concept is already familiar. GitHub pull requests may require approval before code is merged. Bank transfers may need a second authorized signer. Safe.global transactions can require several owners to approve them before funds move.
MPAS brings these approval protections to any software application through a common, open protocol.
An AI agent can initiate a payment, production deployment, or database change just as it does today. However, when an organization pre-designates an action as sensitive, MPAS requires authorized maintainers to approve the exact request before it proceeds. Routine actions continue automatically.
This is a major new direction for OMA3. MPAS is the first non-Web3 protocol governed by OMA3 and our first initiative focused directly on AI.
The first implementation targets the Model Context Protocol, or MCP, one of the most widely used ways for AI agents to connect to external tools and business systems. MCP enables an agent to take action; MPAS adds an independent approval layer around the actions that matter most.
Learn more about MPAS on GitHub
A working MPAS MVP is already being used in software development, and we plan to expand its use within OMA3. It is publicly available as an experimental alpha.
MPAS is not yet battle-tested or independently audited. We invite the OMA3 community to try it and share feedback on GitHub.
OMATrust Is Built into MPAS
OMATrust is a critical part of MPAS’s security model. MPAS uses plugins for extensibility, and OMATrust helps users verify the source and security of those plugins.
We hope MPAS becomes one of the main demand drivers for OMATrust and OMAChain. You can read more about OMATrust’s capabilities, other use cases such as x402, and previous announcements in our July newsletter.
The OMA Offering on Republic
The OMA token offering remains live on Republic. OMA is the native token of OMAChain and helps support the work we do.
View the OMA Offering on Republic
OMA3 is conducting a securities offering on the Republic platform. The offering is being conducted pursuant to Rule 506(c) of Regulation D and is available only to eligible accredited investors. This communication is for informational purposes only and does not constitute an offer to sell or a solicitation of an offer to buy securities, except through the Republic platform. Any investment decision should be made only after reviewing the full offering materials available on Republic. Investing involves risk, including possible loss of principal.
MPAS marks a new chapter for OMA3, extending our work from verifiable trust into practical safeguards for AI agents and the systems they increasingly control.
Thank you for being part of the OMA3 community.
Warm regards,
team