Glossary

The definitions below describe how terms are used in this handbook.

Term Meaning
ADR Architecture Decision Record: an append-only record of a consequential decision, its context, alternatives, evidence, consequences, and review triggers.
Agent A system in which a model can select or sequence actions toward an objective within defined tools, state, and limits.
Agent harness The application-owned runtime that constructs context, runs model loops, dispatches tools, maintains task state, verifies outcomes, and terminates execution.
AI gateway A shared entry point that authenticates model requests and applies routing, quotas, provider adaptation, telemetry, and related controls. It is a platform component, not the entire platform.
AI platform The shared technical and operational foundation through which an organization builds, deploys, evaluates, governs, and operates multiple AI-enabled applications.
Capability contract A logical model-access contract describing an approved task, data eligibility, schemas, quality baseline, service objectives, limits, features, and fallback behavior.
Compound AI system An application whose behavior emerges from a model combined with prompts, retrieval, tools, deterministic software, policy, state, and people.
Context The instructions, user input, evidence, tool definitions and results, history, memory, and task state supplied to a model call.
Control plane The platform layer that records desired state, policies, artifact versions, evaluations, budgets, and release decisions.
Evaluation A repeatable measurement of whether an AI system behaves acceptably on representative tasks, failure cases, and risk-relevant slices.
Hard gate A release criterion whose failure blocks promotion rather than contributing to a weighted score.
Idempotency key A stable identifier that lets a receiving system recognize repeated attempts to perform the same intended effect.
MCP Model Context Protocol: a protocol for discovering and invoking tools and contextual resources. Protocol compatibility does not establish trust or authorization.
Permission-aware retrieval Retrieval that filters candidates by likely access and authoritatively revalidates permission before content enters model context.
RAG Retrieval-augmented generation: constructing model context with evidence retrieved from external sources.
Release bundle An immutable manifest that pins the code, models, prompts, retrieval assets, tools, policies, evaluators, limits, evidence, and rollback target released together.
RPO Recovery point objective: the maximum tolerable amount of state loss measured in time or committed work.
RTO Recovery time objective: the target time for restoring an acceptable level of service after disruption.
Runtime plane The platform layer that handles live inference, retrieval, tool calls, policy enforcement, execution state, and telemetry. Also called the data plane.
SLO Service-level objective: a measurable target for user-visible quality, reliability, latency, or another service outcome.
Tool A typed capability through which a harness reads data or proposes, validates, and commits effects outside the model.
TTFT Time to first token: the delay between submitting a generation request and receiving the first streamed output token.
Verifier A deterministic check, domain rule, test, reconciliation query, or calibrated grader used to establish whether an outcome satisfies its contract.