---
title: "Code agent · Highflame Glossary"
description: "Autonomous software that reads code, runs commands, calls tools, and changes systems on a developer's behalf. Securing one means controlling what it can access while it runs, and proving afterward what it did."
doc_version: "0.1.0"
last_updated: "2026-08-07T04:48:55.536Z"
canonical: "https://www.highflame.com/glossary/code-agent"
---

[Home](/index.md)·[Glossary](/glossary.md)·Code agent

# Code agent

Autonomous software that reads code, runs commands, calls tools, and changes systems on a developer's behalf. Securing one means controlling what it can access while it runs, and proving afterward what it did.

Learn more: [Code agent security](/code-agents.md)

Part of [the Agent Control Fabric](/platform.md): Highflame's identity, policy, and enforcement substrate for AI agents.

[Book a demo](/contact.md) [All terms](/glossary.md)

## Keep exploring the glossary.

[

### Confused deputy

An attack where a low-privilege agent tricks a higher-privilege one into acting on its behalf. Scope attenuation prevents it: a sub-agent provably cannot exceed its parent's authority.

Read →](/glossary/confused-deputy.md)[

### Delegated authority

The model where an agent acts on behalf of a human or another agent, holding strictly less authority than the principal that authorized it, and provably distinct from that principal.

Read →](/glossary/delegated-authority.md)[

### Delegation depth

How many on-behalf-of hops a credential sits from its original human authorizer. Highflame enforces depth as a first-class policy primitive.

Read →](/glossary/delegation-depth.md)[

### DPoP

Demonstrating Proof-of-Possession (RFC 9449): binds a token to a proof key so a stolen token is inert without it.

Read →](/glossary/dpop.md)[

### Enterprise Managed Authorization (EMA)

An MCP extension that lets a company's identity provider decide, through corporate SSO, which MCP servers an agent may connect to. It governs admission, not what the agent does once inside.

Read →](/glossary/ema.md)[

### Guardrails

Inline detection and enforcement on an agent's prompts, tool calls, and responses: blocking unsafe actions in real time.

Read →](/glossary/guardrails.md)

## Sitemap

Full site map: [/sitemap.md](https://www.highflame.com/sitemap.md). Machine index: [/sitemap-index.xml](https://www.highflame.com/sitemap-index.xml).
