Library · Glossary

The glossary for people who read footnotes

Short, careful entries on the terms that matter in enterprise AI. Each one is dated, cited, and reviewed by a named editor before publication. We skip the terms a general-interest AI glossary already covers and focus on the ones that determine budget and risk.

  1. 01
    Protocol 6 min

    Model Context Protocol (MCP)

    The specification, the history, the three roles, and the fourth role that emerged in production.

    Read
  2. 02
    Protocol 5 min

    MCP Gateway

    The authorization- and observability-aware proxy every enterprise ends up building or buying.

    Read
  3. 03
    Architecture 6 min

    Agentic RAG

    Retrieval inside a plan. When it earns its seat and when it is a tax.

    Read
  4. 04
    Observability 5 min

    Agent observability

    The emerging category. What counts as observable, and what Datadog, Braintrust, and Phoenix are all chasing.

    Read
  5. 05
    Governance 7 min Published April 2026

    ISO/IEC 42001:2023

    The first certifiable AI management standard. Structure, annexes, certification process, and how it relates to NIST AI RMF.

    Read
  6. 06
    Governance 6 min Published April 2026

    NIST AI Risk Management Framework

    The four-function framework (GOVERN, MAP, MEASURE, MANAGE) US federal agencies and most enterprises reference by default.

    Read
  7. 07
    Governance 6 min Published April 2026

    Shadow AI

    What every mature governance program discovers at audit: unsanctioned AI tools, SaaS-embedded AI, team-built integrations. How to surface it.

    Read
  8. 08
    Governance 6 min Published April 2026

    Agent washing

    Gartner's term for products marketed as agentic that are workflow-with-natural-language-input. The five tells we use to screen demos.

    Read
  9. 09
    Governance 5 min Published April 2026

    Guardian agent

    The Gartner-coined category for AI systems that supervise other AI systems. Real, narrow, still forming in April 2026.

    Read
How this library works

Frequently asked

  1. What makes a term worth a glossary entry here?

    A term earns an entry when it is doing real work in enterprise procurement and is being used to mean two different things at once. MCP gateway, agentic RAG, agent washing and guardian agent all qualify: buyers meet them in vendor decks before anyone defines them. Terms that are stable and well-defined elsewhere do not need another restatement from us.

  2. How is this different from a vendor glossary?

    A vendor glossary defines a term so that the vendor's product is the answer. Each entry here starts from what the term means independent of any product, states what it is commonly confused with, and gives the checkable test that separates a real implementation from a claimed one. Where our own product falls inside a definition, the entry says so and flags it.

  3. How current are the definitions?

    Each entry carries an update date and cites the primary sources it rests on — protocol specifications, RFCs, standards bodies, and regulator publications rather than secondary coverage. Definitions in this space move: the Model Context Protocol authorization model changed materially across its 2025 and 2026 revisions, and entries touching it are dated accordingly.

  4. Can I cite these definitions in an internal document?

    Yes, and we would rather you cite the primary source underneath. Every entry links the specification, RFC, or standards publication its definition rests on. Quote the source for anything that will end up in a contract, an architecture decision record, or an audit workpaper; use our entry for the disambiguation and the buyer-facing test.