Canonical definitions, operational explanations, and technical mechanisms for category concepts.
The centralized system of record and control layer used to discover, identify, authorize, monitor, restrict, and revoke AI agents across their complete lifecycle.
An Agent Control Plane architected specifically for multi-tenant enterprise environments, enforcing consistent security, compliance, and lifecycle governance across business units, clouds, and vendor ecosystems.
An authoritative system of record that catalogs every AI agent within an organization, detailing its identity, business owner, purpose, risk tier, models, tools, and operational status.
The total population of AI agents created, operated, embedded, purchased, or permitted across an enterprise.
A standardized, portable record containing an AI agent's verified identity, purpose, owner, risk classification, capability manifest, model stack, tool bindings, and current authorization state.
A machine-readable inventory recording all models, prompts, tools, APIs, data sources, libraries, memory stores, and evaluators that compose an AI agent.
The framework for assigning, authenticating, federating, and managing unique machine identities for autonomous AI agents.
The exact subset of permissions and actions an AI agent is permitted to execute at a specific moment in time, calculated by combining static grants, runtime policies, environmental factors, approval states, and remaining budgets.
The specific set of external APIs, functions, database connections, and system utilities an AI agent is authorized to invoke.
The governance policies restricting which foundational LLMs, fine-tuned models, and inference endpoints an agent is permitted to call.
The data sources, vector stores, memory buffers, and knowledge bases an agent is authorized to search, retrieve, or assemble into its prompt context.
The policies and controls governing how authority, context, and budget are passed from one AI agent to another in multi-agent workflows.
The sequential sequence of agent-to-agent delegation steps originating from a human trigger or primary orchestrator down to terminal subagents.
The maximum allowable number of nested agent-to-agent delegation steps permitted in a workflow.
The automatic termination of authority across all child agents, delegated sub-tasks, active leases, and downstream sessions when a parent agent's access is suspended or revoked.
An emergency enterprise mechanism that immediately halts an agent's execution, revokes its authority leases, and blocks all tool calls across all runtimes.
A short-lived, cryptographically signed token granting an AI agent permission to perform specific actions for a bounded timeframe and scope.
An immutable record capturing the identity, context, policies evaluated, approval state, tool invocation, and outcome of a consequential action taken by an AI agent.
An unauthorized, unregistered, or unowned AI agent operating within an enterprise network without central security review or approval.
A visual and mathematical graph representing all relationships between human owners, agents, subagents, models, tool entitlements, data sources, and target systems.
A formal, binding declaration of the intended functional business objective and explicit operational scope assigned to an AI agent.
The security principle that an AI agent's permissions are restricted strictly to actions required to fulfill its explicitly declared and approved business purpose.
The total potential scope of systems, data stores, API capabilities, and financial impact that could be compromised if an agent behaves maliciously or erratically.