Skip to main content
Version: 3.0 (next)

What MaestroHub is

MaestroHub is the industrial context platform. It connects every machine and business system in your plant and turns their data into one governed language, so your people and AI can see the plant, understand it and act on it, inside your rules and on your own infrastructure.

It sits between your machines and everything that runs on them. Your PLCs, SCADA, historian and dashboards stay where they are; MaestroHub sits above them and gives the rest of the business one vocabulary for every line and every site.

Why it exists​

You bought the AI. It still cannot tell you what a stop cost, because all it sees is numbers: nothing gave your data one meaning, one map, or permission to act. Three things are missing, and each product fills one.

  • No meaning. Dozens of protocols, thousands of tags, and three systems that disagree about the same event. Every integration is a one-off.
  • No map. A value has no neighbours. Nothing says what feeds what, what controls what, or what stops if this stops.
  • No permission. Nobody lets an agent touch a line without knowing who it acts for, what it may do, and what it did.

Context Engine​

Live See the plant. Context Engine is the product these docs describe. It does four things, on every value:

What it doesRead more
Connect90+ connectors reach 120+ kinds of machines and systems: PLCs, CNCs and robots, SCADA and historians, MES and ERP such as SAP, databases, files, cloud and IoT services. 22 of them write back, under audit.Connect
Give it contextOne namespace for the plant: every value gets one address, a schema and unit, a quality verdict, and a record of where it came from.Unified Namespace
Move itVisual pipelines and functions transform and route data. Store and forward buffers on disk when a link drops, then replays.Orchestrate
Serve itMQTT and REST for systems, dashboards and alerts for people, and an MCP server for AI agents.Dashboards, MCP integration

Context Engine is sold in two editions, Foundation and Enterprise, on the same codebase with the same connectors. Enterprise adds advanced access control, multiple workspaces and multi-node Kubernetes. A free trial needs no licence key: it runs the Enterprise features for two hours at a time, with small caps on pipelines, connections and users. See Editions.

Knowledge Graph​

Coming soonnot part of 3.0 Understand it. Knowledge Graph will hold every thing in the plant and how it relates: what feeds what, what drives and controls what, what stops if this stops, and what the plant looked like on any past day. You will ask in plain words and get the answer back with the rows and the path that produced it. It is in development and testing, is not part of release 3.0, and has no pages in these docs yet.

Agents and App Studio​

Act on it. Two kinds of actor work on the platform, and both act as a named person.

  • Liveagent access AI agents. Point your own MCP client (Claude, Cursor, VS Code and others) at MaestroHub's MCP server. The agent sees exactly what the person whose token it uses may see, and every action is recorded. The MCP server is documented as beta. See MCP integration. Writes that an agent proposes inside a pipeline can wait for a person in the Approvals inbox.
  • Coming soonnot part of 3.0 The Maestro agent, inside the product, with the same tools and the same permissions as your own client.
  • Coming soonnot part of 3.0 App Studio. A domain expert describes the application they need, and it is built on everything MaestroHub already does (connectivity, pipelines, the namespace, governance), reading and writing data only inside the permissions of the person using it. See App Studio, which describes it as it is being built.

When an action goes back to the plant, it goes as a named person, checked first and recorded. It is a data path, not a control loop.

Governance on every path​

  • Access you can reason about. Role-based access, ownership, sharing and time-bound grants, for people and agents alike (custom roles and time-bound grants are in Enterprise). Single sign-on over OIDC, SAML and LDAP. See Identity and access.
  • An audit trail you can verify. Every change is recorded in a hash-chained trail, and an endpoint tells you whether the chain is intact. The boundary, stated first: the chain shows that what is there was not altered, reordered or thinned before the newest record. It cannot prove that the newest record is the last one written, and it does not resist someone with write access to the database who rewrites the tail.

Where it runs​

MaestroHub runs where your data is, and nothing leaves your network unless you send it. One codebase, five ways to run, with the same APIs and the same UI in each:

  1. A single binary at the edge, with its own database, message bus and MQTT broker built in
  2. A container
  3. A Siemens Industrial Edge app
  4. Kubernetes at site level, against PostgreSQL, TimescaleDB and EMQX
  5. A fleet hub with edge sites, where Fleet Manager keeps a registry of every MaestroHub instance, their licences, health and identity settings, and edge sites connect outbound only. Fleet Manager is optional: you need it only when you run more than one deployment.

See Architecture and System requirements.

What MaestroHub is not​

  • Not a SCADA or HMI. It reads from and writes to control systems; it is not one.
  • Not a control system. Writes are data-path operations under access control and audit, not a control loop, and not safety-rated.
  • Not a long-term historian or a data lake. History is an operational window by design, set per topic: one day by default, up to 32 days, in every edition. Long-term history goes to your system of record through connectors.
  • Not an MES. It is the data layer an MES sits on, or the layer that feeds it.
  • Not a cloud service. You run it on your own edge box, virtual machine or Kubernetes cluster.

Check it yourself​

Each of these takes minutes, in your own instance.

ClaimHow to check it
Data arrives, even when a destination goes downOpen Store & Forward, start How it works, take a destination offline in the outage simulator, drop a poison message, and watch the buffer absorb the outage, quarantine the bad message and drain. See store and forward.
A value is what it says it isOpen a computed topic in the Data Explorer and walk its lineage back to the register or the fetch that started it. See lineage.
The audit trail was not alteredCall GET /audit/integrity and read the verdict on the hash chain.