Glossary
The Know Your Agent vocabulary, in plain language.
Oathera draws lines that others blur. This glossary gathers every term in one place and groups it by maturity, so what runs today is never confused with what is coming or what is on the roadmap. Each term has its own anchor, so a definition anywhere on the site can link straight to it.
Running Available today
Every term in this group describes something Oathera runs today. You can count on these as capabilities you have right now.
Know Your Agent
The category Oathera defines: giving every AI agent a provable identity, an accountable sponsor, and an operational boundary enforced on every request. Know Your Agent is the category, not a product name.
Sponsor
The person or organizational unit that is accountable for an agent and answers for what it does. The sponsor travels with the identity and shows up on every log line and boundary decision.
Oathera says sponsor, not the generic “owner.” A sponsor is accountable for the agent; it is a distinct idea from the principal who signs in to approve it.
Principal
The person who signed in through the IdP and completed the enrollment approval for an agent. A principal is not the same as a sponsor: the principal performs the approval, while the sponsor is who the agent answers to.
Anchor key
The one Ed25519 key an agent holds, generated inside your environment and never exported. One agent has exactly one anchor key.
Oathera says anchor key rather than the generic cryptographic term, because the key is the stable root of the agent's identity, not a secret to be passed around.
Thumbprint
The compact, verifiable value derived from an agent's anchor key. The thumbprint is the agent's identity: present the thumbprint and prove you hold the matching anchor key, and you have proven which agent you are.
Identity token
A short-lifetime credential — measured in minutes — issued by the identity service and bound to an agent's anchor key and its host. On its own it is useless to a thief, who has neither the anchor key nor the host.
Oathera says identity token rather than naming it by its transport or lifetime; what matters is what it is bound to, not how long it lasts.
Session key
The signing key an agent uses for a working session, held alongside the identity token. Where a definition needs to name the thing doing the signing during a session, it is the session key.
Operation proof / Proof of possession
A single-use RFC 9421 HTTP Message Signature carried on each call, over that exact method, path and body. Because it proves possession of the signing key for that one request, a request cannot be replayed or altered.
Host binding
The tie between an agent's identity and the host it was enrolled on. An agent that appears on a new host is revoked; that new host enrolls a new agent.
Oathera says host throughout, not a forced synonym; incidental technical phrases such as “virtual machine” are left as they are.
Host digest
The compact record of the host that the Identity MCP captures at enrollment, so the identity can be tied to that host. It is a digest of the host, not a claim that the host has been independently attested.
Enrollment
The process by which an agent gets its identity: the Identity MCP creates the anchor key, records a host digest, and the agent is registered against a sponsor.
Enrollment approval
The step where a principal signs in and approves an agent's enrollment once. Nothing runs on an unapproved identity. The credential service issues a verifiable credential recording who approved what.
Operational boundary
The envelope that defines what an agent may do: which tenants, systems, data classes and operations are in scope, and which are explicitly never in scope. The boundary travels inside the identity, so it follows the agent everywhere it acts.
Boundary decision
The signed allow or deny returned when the Gateway MCP evaluates a request against the operational boundary, using Open Policy Agent (OPA) as policy input. The operational boundary is the envelope; the boundary decision is the signed outcome for one request.
Control plane
The Oathera services that handle enrollment, policy, revocation and telemetry. The control plane is where identities are managed; it is distinct from the enforcement plane that acts beside your agent.
Enforcement plane
The two MCPs — the Identity MCP and the Gateway MCP — that run beside your agent and enforce identity and the operational boundary on every request.
Oathera pairs the control plane with the enforcement plane; it does not use the term some vendors use for the layer that carries traffic.
Identity MCP
The component that runs beside an agent, creates and holds its anchor key, records a host digest at enrollment, and signs on the agent's behalf.
Oathera says Identity MCP — one name for this component everywhere — not a generic “helper.”
Gateway MCP
The component that verifies an agent's identity token and operation proof, requests the boundary decision, and lets a request through only when it is allowed.
Oathera says Gateway MCP — one name everywhere — not a generic “gateway” label.
Identity service
The control-plane service that issues identity tokens bound to an agent's anchor key and host, and maintains the agent register.
Technical name: AIS.
Credential service
The control-plane service that issues verifiable credentials recording who approved what, so an approval can be verified later.
Technical name: VCI.
Runtime check-in
The regular contact between an agent's enforcement plane and the control plane that keeps a short-lifetime identity token renewed. When renewal stops, access ends within one token lifetime.
Revocation on deprovision
When a sponsoring principal is deprovisioned, the identity service stops issuing identity tokens to that principal's agents and bumps the revocation epoch, so access ends within one short token lifetime — without a redeploy.
Content trust
Labels on the trust of content flowing through an agent's tools, so an agent can tell what came from a trusted source and what did not before it acts on it.
Federation
Issuing identity in a form another system already accepts, so agents join trust domains you already run. Today Oathera federates with Microsoft Entra.
NHI attributes
The non-human-identity attributes an agent reports about itself, which feed its risk tier. Oathera is explicit that these are self-reported, not independently proofed.
Risk tier
A rating from 1 to 4 for how dangerous an agent's reach is, where 1 is the most dangerous and 4 the least. Risk tier is the only Oathera term that uses that word.
Resource server
A system an agent calls — an API or service that holds the data or performs the operation the agent is reaching for.
Protected core
The signed native library at the heart of the enforcement plane, used where the specific signed component is meant rather than a resource server in general.
IdP
Your own identity provider — the OIDC provider where a principal signs in. Oathera relies on your IdP for human identity. The IdP that ships with Oathera is a demo IdP, for demonstration only.
Capability
A specific action an agent is permitted to take within its operational boundary.
Privileged capability
A capability with higher reach or risk. Identity tokens for privileged capabilities are issued with a shorter lifetime.
Audience
The intended recipient an identity token is issued for, so a token meant for one resource server is not accepted by another.
Anchor rotation
Replacing an agent's anchor key with a new one while preserving a verifiable link to the identity, so a key can be refreshed without re-establishing who the agent is.
Gateway assertion
The signed statement the Gateway MCP emits about a verified request and its boundary decision, forming part of the audit record.
Evidence source
Who vouches for something — the party supplying a signal about an agent or identity. Kept distinct from the assurance level, which is how far that evidence lets you trust it.
Assurance level
How far a piece of evidence lets you trust an identity. Kept distinct from the evidence source: one names who vouches, the other names how far to trust.
Tenant
An isolated customer space within Oathera. An agent's operational boundary names which tenants are in scope.
MCP bundle
The package you install beside your own agent: the Identity MCP and the Gateway MCP together.
Bring your own agent (BYOA)
Running your existing agent with Oathera by installing the MCP bundle next to it, rather than rebuilding the agent on a new framework.
Admin API
The programmatic interface for managing identities, boundaries and revocation in the control plane.
Clearance 0 (Basic)
The baseline clearance every enrolled agent has today. Higher clearances (Verified, High) are on the roadmap and are not available now.
Sovereign (deployment)
Used only to describe a deployment: self-hosted or in-country. Sovereign refers to where Oathera runs, never to a clearance and never as a tagline.
Coming Not yet available
These capabilities are being built and are not available today. They are listed here so the vocabulary is clear; nothing in this group is live yet.
Enrollment review
An additional admin sign-off on top of enrollment approval, so a second administrator reviews an agent before it is activated.
Task context
Scoping an agent's authority to the specific task it was handed, so a boundary decision can take that task into account.
Delegation
One agent passing a scoped slice of its authority to another, with the chain recorded and verifiable.
Operation approval
A human-in-the-loop checkpoint on an individual operation before it is allowed to run. Distinct from enrollment approval, which happens once at enrollment.
Signed revocation snapshots (risk tier boundary-decision optimization)
Signed revocation snapshots and a risk tier optimization that let the Gateway MCP reach a boundary decision faster. The boundary decision itself runs today; this optimization does not.
On the roadmap Roadmap
Longer-term directions, named here only so the vocabulary is clear. These are not available and not committed to a release, and Oathera does not present them as capabilities you can use. Consistent with ADR 0001, Oathera does not proof humans; any identity assurance would rely on your own IdP and proofing sources.
Verified sponsor
A sponsor whose identity has been established to stronger assurance through your IdP and proofing sources. Per ADR 0001, Oathera does not proof people itself, so this stays on the roadmap.
Proofing source
An external party that establishes a human's identity. Oathera would rely on your proofing sources rather than proof people itself (ADR 0001).
Clearance 1 (Verified) and Clearance 2 (High)
Clearances above Basic, computed from evidence through your IdP and proofing sources. Both are on the roadmap; today every agent is Clearance 0 (Basic).
Known organization
An organization recognized with baseline assurance. A roadmap label, not an available capability.
Verified organization
An organization established to stronger assurance through proofing sources. A roadmap label, not an available capability.
Handover
Transferring responsibility for an agent from one sponsor to another, with the change recorded. On the roadmap.
Departure detection
Surfacing agents whose sponsor has left, so they can be reassigned or retired. On the roadmap.
Agent class
Grouping agents into classes so a boundary and policy can be expressed once and applied across the class. On the roadmap.
Trust score
A computed score summarizing how far an agent can be trusted. On the roadmap.
Agent identity wallet
A wallet that carries an agent's credentials and presents them where needed. On the roadmap.
Attested host
A host whose integrity has been attested, used in the roadmap Clearance 2 context (ADR 0003). Today the Identity MCP records a host digest at enrollment; full host attestation is on the roadmap.
Plan
A packaging of Oathera for a customer, which may be measured in sponsor seats. Defined here for vocabulary only; Oathera does not publish pricing on the site.