Resources
AI Agent Security Glossary
Plain definitions for the terms used in our service and architecture pages.
Terms
Action control
A check on identity, resource and arguments before a tool executes an operation.
Adaptive testing
Testing in which earlier observed results inform later attempts; scope and attempt budgets must remain explicit.
Agent identity
The authenticated identity and permissions used by an agent or delegated workflow.
Approval binding
Connecting an approval to a specific action, target and arguments so altered requests require a new decision.
Attack success rate
Observed successful attempts divided by attempts under a defined test design; not a general probability of failure.
Control mapping
A link between a requirement, its implementation, evidence and remaining gaps.
Delegation
Granting a bounded task and permission scope to another agent or service.
Engineering evidence
Configuration, test and operating records supporting an implementation review.
Fail-closed
Rejecting or stopping a defined operation when its authorisation check cannot establish permission; failure and recovery behaviour need testing.
Gate readiness
Preparation for a specific review or acceptance process; it is not a guarantee that the reviewer will accept the system.
Independent assurance
Evaluation by a reviewer whose role and independence meet the applicable engagement requirements.
Least privilege
Limiting access to the actions, resources and duration required for an authorised task.
MCP
Model Context Protocol, a protocol for connecting applications to context and tools; implementation security still needs review.
Regression testing
Repeating agreed tests after a change to check whether relevant controls still behave as expected.
Retest criterion
The evidence and expected behaviour required to close a particular finding.
Shadow mode
Observing what a control would decide without using that decision to block the operation.
Trust boundary
A point where data or execution crosses between different authority or access scopes.
Start with a clear scope
Tell us which systems, actions and review requirements are in scope. We will discuss the work, responsibilities and deliverables before you commit.