HiveKey
Glossary

The agent-security lexicon.

Plain-language definitions for the concepts behind governing AI agents — control plane, scope, guard, blast radius, MCP, and the rest of the vocabulary.

Access controlArchitectureAudit & complianceSecurity

Agent control plane

The layer in the path of every agent action that decides, enforces, and records what each agent can do.

Architecture

Attribution

Tracing every agent action back through the agent identity to the accountable human who owns it.

Audit & compliance

Blast radius

The total damage an agent could do if it's compromised, prompt-injected, or simply wrong.

Security

Guard

Your business rules, enforced before an agent's action runs — caps, allowlists, approval thresholds, freeze blocks.

Access control

Kill switch

One action that instantly revokes an agent's access across every tool and capability.

Security

Least privilege

Grant an agent the minimum capabilities its job requires, and nothing more — starting from zero.

Access control

Log / audit trail

The immutable, attributable record of every agent action — allowed and denied — recorded in the path as it happens.

Audit & compliance

MCP (Model Context Protocol)

An open standard for how agents discover and call tools — powerful, and easy to over-grant without governance.

Architecture

PDP (Policy Decision Point)

The 'brain' that decides whether an agent action is allowed — evaluating the request against the agent's scope and guard rules and returning allow, deny, or needs-approval.

Architecture

PEP (Policy Enforcement Point)

The component, in the path of every action, that enforces the policy decision — letting an action through, blocking it, or sending it for approval.

Architecture

RBAC (role-based access control)

Govern agents by job function — bundle capabilities into roles and assign them, instead of per-agent keys.

Access control

Scope

Least privilege for agents: the deliberate set of capabilities an agent is granted — and everything else is invisible.

Access control

SIEM (security information & event management)

The system your security team uses to collect, correlate, and alert on logs — including your agent audit trail.

Audit & compliance

Put every agent your company runs under one policy.

Watch HiveKey scope, guard, and block a live action on your own agents — 30 minutes, no slides, no commitment.