Agent governance
Controlling what an organization's agents are allowed to do and proving what they did: discover every agent, authorize each action against policy, and produce audit evidence. Distinct from AI governance's focus on model risk.
Learn more: Agent Governance
Part of the Agent Control Fabric: Highflame's identity, policy, and enforcement substrate for AI agents.
Keep exploring the glossary.
Agent identity
A verifiable, cryptographic credential issued to an agent that carries agent-shaped claims (owner, trust tier, framework, delegation depth) so every action traces back to a named human.
Read →AI observability
Capturing and querying everything an agent does at runtime, LLM calls, tool calls, file and network activity, tied to identity, so you can ask why something happened and who did it, not just read logs.
Read →Attribute-based access control (ABAC)
Authorization decisions keyed to attributes (the agent's claims, owner, trust tier, and delegation depth) rather than shared keys or static roles.
Read →Authorization
Deciding whether a given actor is allowed to take a given action. Distinct from authentication (proving who you are); authorization is what an agent may do.
Read →Blast radius
The set of systems and data a compromised agent or credential could reach. Identity-scoped access shrinks it; cascade revocation contains it.
Read →Breakout controls
Runtime controls that keep an agent aligned to its mission: containing, redirecting, or stopping it when it veers off course, before the action lands.
Read →