Resources

AI Agent Security Glossary

Plain definitions for the terms used in our service and architecture pages.

Terms

Action control

A check on identity, resource and arguments before a tool executes an operation.

Adaptive testing

Testing in which earlier observed results inform later attempts; scope and attempt budgets must remain explicit.

Agent identity

The authenticated identity and permissions used by an agent or delegated workflow.

Approval binding

Connecting an approval to a specific action, target and arguments so altered requests require a new decision.

Attack success rate

Observed successful attempts divided by attempts under a defined test design; not a general probability of failure.

Control mapping

A link between a requirement, its implementation, evidence and remaining gaps.

Delegation

Granting a bounded task and permission scope to another agent or service.

Engineering evidence

Configuration, test and operating records supporting an implementation review.

Fail-closed

Rejecting or stopping a defined operation when its authorisation check cannot establish permission; failure and recovery behaviour need testing.

Gate readiness

Preparation for a specific review or acceptance process; it is not a guarantee that the reviewer will accept the system.

Independent assurance

Evaluation by a reviewer whose role and independence meet the applicable engagement requirements.

Least privilege

Limiting access to the actions, resources and duration required for an authorised task.

MCP

Model Context Protocol, a protocol for connecting applications to context and tools; implementation security still needs review.

Regression testing

Repeating agreed tests after a change to check whether relevant controls still behave as expected.

Retest criterion

The evidence and expected behaviour required to close a particular finding.

Shadow mode

Observing what a control would decide without using that decision to block the operation.

Trust boundary

A point where data or execution crosses between different authority or access scopes.

Start with a clear scope

Tell us which systems, actions and review requirements are in scope. We will discuss the work, responsibilities and deliverables before you commit.