Glossary
The words Quard and its dashboard use, in alphabetical order.
| Term | Meaning |
|---|---|
| Action guard | A guard on tools that change something, such as payments, emails or deploys. It checks the arguments and their labels against rules. See Guards. |
| Agent | An AI program that calls a model and tools to do work. Each agent has a name, such as billing, and versions. |
| Agent key | The secret the SDK uses to reach Quard, and the only Quard secret an agent needs. Created and revoked in Settings. It is shown once, when you create it. |
| Agent version | The model, instructions and tools an agent ran with. Recorded once per version, so an incident ties to the version that caused it. |
| Allow | A guard decision that lets a call run. |
| Always approve | An answer that lets later calls from the same agent to the same tool, with exactly the same arguments, run without asking until someone revokes it. Also called a grant. |
| Approval | A person’s answer to a call that waits: approve once, always approve or deny. See Approvals. |
| Approval guard | A guard that always asks a person before its tool runs. |
| Approve once | An answer that runs one call, with exactly the arguments shown, one time. |
| Ask | A guard decision that pauses a call until a person answers. |
| Block | A guard decision that stops a call. The tool never runs, and the agent gets a refusal. |
| Block rate | The share of guard decisions that blocked a call. |
| Carrier | The run id, parent step id and label reference that travel with a message between processes. See Multi-agent. |
| Chunk | A piece of public content, up to 4,000 characters, that the detector labels in one request. |
| Context label | The least trusted and most sensitive label among everything the model read before it asked for a call. See Labels and trust. |
| Damage | The harmful call at the end of an incident’s path, or the tool call whose content a guard flagged when no call was blocked. |
| Delegation | One agent handing work to another. A delegated agent can only use the tools its parent granted. |
| Deny | An answer that stops a waiting call. The agent gets a refusal. |
| Detector | An AI model that labels public content, such as invoice or phishing. It only makes things stricter. Quard’s detector is off until set up, then acts by default. |
| Egress guard | A guard on tools that send data out. It keeps internal data away from destinations that are not allowed. |
| Entry point | Where untrusted content first came into an incident’s path. |
| Fan-out | How many helper agents one agent starts in a run. One of the run limits. |
| Flag | A mark on content, such as instructions or detector:payment_fraud. Values from flagged content never count as coming from their origin. |
| Fleet | All your agents together. |
| Fleet check | A check that blocks a new recipient, IBAN or domain everywhere once a fifth separate run uses it within 24 hours. See Quarantine. |
| Grant | A standing always-approve answer. Grants are listed, and revoked, on the Approvals page. |
| Guard | A check that wraps a tool and decides whether each call may run. See Guards. |
| Guard decision | The result of a guard, with its rule and reason: allow, ask or block for a call, and pass, flag, strip or block for content a source tool returned. |
| Handoff | An agent passing a task or a message to another agent. |
| Hash key | The key that IBANs and emails are hashed with. Each project has its own, made from the server’s QUARD_HASH_KEY. The SDK gets it with its agent key. |
| Incident | A record that Quard opens for a run when a guard blocks a call or flags content, also in observe mode, with its path, verdict and replay. See Incidents. |
| Influence path | Every step from the entry point to a call, shown on an approval request. |
| Influenced | A call whose context label is untrusted, because the model had read untrusted content before asking for it. |
| Label | Where a piece of content came from (its origin), with its trust and sensitivity. See Labels and trust. |
| Label reference | A key to the labels a sender stored for a message. The receiving side looks the labels up with it. |
| Limit guard | A guard that caps calls, amounts and cost per run, agent or day. |
| Limited replay | A replay that can’t run: its request was not recorded, the suspect content is not a tool result, or no harmful call came. See When replay is limited. |
| Loop | Handoffs back and forth between the same two agents. One of the run limits. |
| Mask | The short form of a sensitive value shown in the dashboard, such as DE89…3000. |
| Model-generated | A value that appeared nowhere earlier in the run. See Value tracing. |
| Observe mode | A rule mode that records what the rule would have done but lets the call run. |
| Origin | The tool, domain, sender, server or agent that let content in, such as web:supplier-portal.example. |
| Origin override | A change, made in code, to the default trust or sensitivity of one origin. Settings lists the overrides your runs report. |
| Paid, not delivered | An x402 payment that settled while the paid response was an error. See Payments (x402). |
| Quarantine | The values the fleet check blocked everywhere. A value leaves it when someone marks it as known. |
| Redaction | Removing secrets, and replacing sensitive values with keyed hashes and masks, before anything is stored or sent to the detector. |
| Refusal | The message an agent reads instead of a tool’s result when a call is blocked or denied. |
| Replay | Rerunning an incident’s turning-point model call with and without the suspect content, to test the cause. It runs when someone starts it on the incident page. See Replay. |
| Root-cause finder | The part of Quard that traces an incident’s path, writes its verdict and runs replay. |
| Rules hash | A short fingerprint of an app’s active rules, recorded with every guard decision. |
| Run | One task from start to finish, across every agent that worked on it. See Runs. |
| Run graph | Who delegated to whom in one run. |
| Run limits | Caps per run on delegation depth, fan-out, loops, model calls and cost. See Run limits. |
| Sensitivity | Whether content is internal or public. |
| Shared memory | A store that agents read and write, wrapped so its items keep their labels. See Shared memory. |
| Source guard | A guard on tools that bring content in. It labels and scans their output. |
| Stand-in | A made-up value in the same format as a masked one, such as an IBAN with a valid checksum, that replay sends in its place. |
| Step | One thing that happened in a run: a model call, a tool call or a guard decision. |
| Strip | Removing part of the content before the agent reads it: suspect lines for the source guard’s rules, or a whole chunk for the detector. |
| Trust | Whether content is trusted or untrusted. |
| Turning point | The model call that decided to act on untrusted content. |
| Untrusted | Content from an origin Quard does not trust by default, such as web pages and outside email. |
| Value tracing | Finding every place an argument’s value appeared earlier in the run. See Value tracing. |
| Verdict | An incident’s finding: its category and the guard that was missing. |
| Watching | New values the fleet check is counting toward its limit. |
| Would block, would ask | What a rule in observe mode would have done. |
| x402 guard | A guard on an x402 payment client. It checks each payment before it is signed. See Payments (x402). |
Last updated on