Documentation · Glossary
The language
of the platform.
The words Fiducia OS uses, defined once so they carry consistent meaning across the product, the documentation, and every finding.
Fiducia OS
Fiducia's platform for AgentOps and governance for agentic enterprises. Its governing question is whether an autonomous action stayed within enterprise authority, risk appetite, and regulatory obligation. Three products carry it: Provenance, Runtime, and Assurance.
Assurance
The production product and the governed environment it runs in: the solution experience, AgentOS, the Core Platform, and the connectors. It performs agentic, independent assurance for the second line, with a read-only persona for the third.
Provenance
The product that answers what exists and whether it can be trusted with autonomy: registry, full-spectrum lineage, discovery, and shadow-authority detection. In development.
Runtime
The product that governs the action: a policy decision point returning allow, allow-with-conditions, step-up, escalate, or deny, with full derivation, enforced at the point of action. In development.
Governance Graph
The live, queryable asset-control-authority model unifying assets, controls, identities, vendors, obligations, services, and delegations. The ontology backbone all three products read and write.
Authority & Policy Compiler
The transformation from regulation and internal charter into executable control: obligations and appetite clauses decomposed, synthesized into rules, tested or attested, and released as versioned configuration under human approval.
Decision & Evidence Ledger
The append-only, lineage-traced record of every material action and decision: who, why, what, with what, under what authority, what happened, and who verified it.
Integration Fabric
The connectivity layer federating GRC, ITSM and CMDB, policy repositories, regulatory feeds, risk tooling, identity, cloud, observability, and agent platforms. More than twenty native connectors, API-first, read-only, continuous sync.
Delegated authority
A modelled grant from an accountable human or policy to an actor, carrying purpose, limits, permitted actions, counterparties and data, monetary threshold, jurisdiction, duration, escalation condition, approver, and control requirements.
Shadow AI autonomy
The risk of agents accessing data, deciding, or acting beyond authorized scope; the threat the access control architecture is built to prevent.
Shadow authority
The measurable instance of that risk: an action for which no valid delegation path existed in the Governance Graph at that timestamp. Detected as a graph query, not inferred from behavior.
Derivation
The chain attached to an outcome: the rule applied, the control it implements, the appetite clause behind it, and the obligation behind that, at the policy version in force.
PDP / PEP
Policy decision point and policy enforcement point: the separation between where a verdict is computed and where it is applied. A Runtime capability, in development.
Core Platform
The data subsystem: AI-native data foundation, unified semantic layer, context and lineage engine, and governance lakehouse.
AgentOS
The governed agent runtime: agentic workflows, guardrails and HITL gates, LLM-as-Judge validation, ContextOS memory, cataloging, and observability.
ContextOS
The persistent memory layer: episodic, semantic, and procedural memory over the Governance Graph.
Otto
Assurance's natural-language governance assistant; citation-backed answers with persistent conversation context.
2LoD / 3LoD
Second and third lines of defense: independent risk oversight and challenge (2nd), and internal audit (3rd).
ITRM
IT risk management, the domain Assurance serves.
Independent challenge
The second line's mandate to prove controls operate, independently of the teams operating them.
Governance lakehouse
The structured-plus-unstructured store for governance entities, evidence, decision traces, and the ledger.
Finding pipeline
Agent, then LLM-as-Judge, then multi-agent consensus, then human-in-the-loop, then the append-only, lineage-traced ledger.
LLM-as-Judge
A separate LLM instance that evaluates primary agent outputs against calibrated, versioned rubrics. It validates; it never generates findings.
Multi-agent consensus
Independent agents assessing the same control-evidence pair; convergence is required to proceed, disagreement escalates.
HITL gate
A mandatory human decision point. Critical and high findings, low scores, remediation actions, authority exceptions, and consensus disagreements cannot pass without one.
Decision trace
The machine-readable record of an AI decision: input context, reasoning path, authority derivation, raw output, judge evaluation, and human modification.
Hierarchical tree index
The retrieval structure that preserves document hierarchy as root, branch, and leaf nodes, enabling structure-aware, multi-hop retrieval.
Programmatic Tool Calling (PTC)
Sandboxed orchestration scripts that keep raw tool responses out of model context, delivering an 88 to 92% input-token reduction.
RBAC / ABAC
Role-based access control (the six personas) layered with attribute-based access control: real-time evaluation of user, resource, action, and environment attributes on every request.
Inherent / residual risk
Exposure as if controls were absent, versus exposure with controls as implemented and evidenced. The delta is each control's measured effect.
Evidence pack
A framework-mapped, fully sourced bundle of citations, gaps, and test results, the independent challenge deliverable.
Full-population testing
Testing every asset and control instance rather than a sample; the replacement for sampled assurance.
Confidence telemetry
Per-run confidence signals that flag low-confidence outputs before they become findings.
MCP
Model Context Protocol, the standard Assurance uses for governed agent-tool communication inside its security perimeter.
ITSM / CMDB
IT service management and configuration management database: the operational systems Assurance reads assets, services, changes, and tickets from.
ETL
Extract, transform, load: the pipeline that normalizes ingested source data into canonical governance entities.
RAG
Retrieval-augmented generation: the conventional retrieval approach Assurance replaces with reasoning-based retrieval.
GRC
Governance, risk, and compliance: the discipline, and the class of enterprise platforms Assurance reads from.
SIEM
Security information and event management: the customer systems that receive Assurance's audit and alert exports.
ZDR
Zero data retention: the SaaS model provider retains no prompts or outputs and trains on nothing.
DPA
Data processing addendum, available as part of the standard contract pack.
More in the documentation