QIS-CANON-000 QISTRUST.COM THE GOVERNANCE LAYER REV 2026-08-28 · BUILD 44
The Governance Layer · The QIS Canon v1.0

Every label on this platform resolves here.

Most reference sites use category labels as though the reader already knows what they mean. Observability, Directional, Auditability, Fiduciary duty — words doing structural work with nothing behind them. On this platform every one of them resolves to a definition, and the build fails if one does not.

Agent-to-agent vocabulary is roughly where cloud computing was in 2008: four major vendors, two protocol ecosystems, a Treasury-convened lexicon and a steady supply of academic papers, all using overlapping terms with incompatible meanings. The canon covers that vocabulary, the eight MARQUE questions, the strategy families, the stack categories and the legal doctrine — with one field nobody else publishes.

60 entities·54 industry terms·6 QIS extensions·82 negative definitions·Stable IDs · JSON

The differentiator

Every glossary defines terms positively. This one also defines them negatively.

Positive definition tells you what a word means. It does not tell you which adjacent word you have confused it with, and confusion between adjacent terms is the actual failure mode in a young vocabulary.

An Agent Card, a Model Card, a System Prompt and a Tool Manifest are four different artifacts with four different lifecycles, and they are used interchangeably every day. That is not a pedantic complaint — it has governance consequences:

The consequence

A tool manifest declares what an agent can reach. An authority grant declares what it may commit, under whose authority, and up to what limit. Reading the first as the second is the most likely agentic governance error of the next two years, and it happens because the vocabulary permits it.

So every entry here carries a notEquivalentTo field, with the reason. There are 82 of them.

Method

Two tiers, and we never blur them.

  • Canonical industry term — the term exists in the wild. We document it and cite its origin. We do not get to define these; we get to describe them accurately, and if we have described one badly we would like to know.
  • QIS Canonical Extension — a proposal from us, filling a gap we have documented elsewhere in the standards register or the control-objective crosswalk. Labeled as ours on every page, without exception.

There are only 6 extensions, deliberately. Proposing a term is legitimate; presenting a proposal as settled usage is not, and inventing vocabulary because it sounds impressive is how an ontology loses the credibility it exists to accumulate.

Identity & discovery

Identity & discovery

QIS-TERM-00001 · Emerging

A machine-readable document published by an agent that advertises what it is and what it can do — identity, declared capabilities, and the endpoints through which another agent may interact with it.

≠ Model Card≠ Tool Manifest≠ Authority Grant
Canonical industry term
QIS-TERM-00001
QIS-TERM-00002 · Emerging

The property that a specific agent is distinguishable as a durable, named actor — with an identifier that persists across sessions, a recorded authority grant, and an action history attributable to it alone.

≠ Service Account≠ Agent Card≠ Session
Canonical industry term
QIS-TERM-00002
QIS-TERM-00003 · Emerging

A catalog of known agents, their identities, declared capabilities, and endpoints, maintained so that agents and operators can discover one another without prior configuration.

≠ Model Inventory
Canonical industry term
QIS-TERM-00003
QIS-TERM-00004 · Widely used

The line across which assumptions about trustworthiness change, and at which input must therefore be validated and authority re-established.

≠ Network perimeter
Canonical industry term
QIS-TERM-00004
QIS-TERM-00023 · DID · Draft standard

A URI that resolves to a document containing public keys, authentication methods and service endpoints, controlled by its subject rather than issued by a central registry, and designed to be verifiable and persistent across the platforms the subject uses.

≠ Agent Identity≠ Authority Grant≠ Service Account
Canonical industry term
QIS-TERM-00023
QIS-TERM-00060 · Contested

A software system that takes consequential action toward a goal without a human approving each action. Used in this corpus only where the qualified form would be imprecise; every governance claim about an agent attaches to a qualified term instead.

≠ Legal agent≠ Model≠ Agent Identity≠ Assistant
QIS Canonical Extension
QIS-TERM-00060
Capability

Capability

QIS-TERM-00005 · Emerging

The process by which one agent learns what another agent or service is able to do, without that knowledge having been configured in advance.

≠ Capability Negotiation
Canonical industry term
QIS-TERM-00005
QIS-TERM-00006 · Widely used

The declared set of tools, resources and prompts an MCP server exposes to a client — the machine-readable statement of what an agent is able to reach.

≠ Authority Grant≠ Agent Card
Canonical industry term
QIS-TERM-00006
QIS-TERM-00007 · Widely used

A single call by an agent to a declared tool, with structured arguments and a structured result.

≠ Task Delegation
Canonical industry term
QIS-TERM-00007
QIS-TERM-00008 · Emerging

The transfer of responsibility for achieving an outcome from one agent to another, where the receiving agent determines how the outcome is reached.

≠ Tool Invocation≠ Escalation
Canonical industry term
QIS-TERM-00008
Context & memory

Context & memory

QIS-TERM-00009 · Widely used

The bounded span of tokens a model can attend to in a single inference, containing the prompt, retrieved material, and conversation so far.

≠ Agent Memory≠ Training Data
Canonical industry term
QIS-TERM-00009
QIS-TERM-00010 · Emerging

The persistence layer through which an agent carries state across invocations — prior decisions, retrieved documents, learned preferences — distinct from both the model weights and the context window.

≠ Context Window≠ RAG corpus
Canonical industry term
QIS-TERM-00010
QIS-TERM-00011 · Experimental

The passing of task-relevant state between agents so that a receiving agent can act without re-deriving what the sending agent already established.

Canonical industry term
QIS-TERM-00011
QIS-TERM-00012 · Widely used

An attack exploiting how an application combines untrusted input with a prompt written by a higher-trust party, causing the system to follow the untrusted instructions.

Canonical industry term
QIS-TERM-00012
Oversight

Oversight

QIS-TERM-00013 · HITL · Widely used

A risk-control approach in which a human is integrated within an AI system's decision-making process.

≠ Human Override≠ Kill Criteria
Canonical industry term
QIS-TERM-00013
QIS-TERM-00014 · Widely used

The exercised ability of a human to ignore, alter, reject or reverse a system output or action.

Canonical industry term
QIS-TERM-00014
QIS-TERM-00015 · Widely used

Layered safeguards — policies, technical controls and monitoring — applied at the data, model, application and infrastructure levels to keep a system operating within organizational or regulatory boundaries.

≠ Kill Criteria≠ Authority Grant
Canonical industry term
QIS-TERM-00015
QIS-TERM-00016 · Widely used

The sequenced, tamper-evident record of what occurred, sufficient to establish the order and content of events after the fact.

≠ Decision Record≠ Observability trace
Canonical industry term
QIS-TERM-00016
QIS-TERM-00057 · Widely used

A capability, required to be maintained and exercisable rather than merely described, to immediately cease some or all automated action as an emergency measure — without the cooperation, consent, or continued functioning of the system it stops.

≠ Human Override
Canonical industry term
QIS-TERM-00057
QIS-TERM-00058 · Experimental

The set of preconditions — cause identified or its absence expressly recorded, an accountable individual's written authorization, and, where a capability is owed to a counterparty, advance notice — that must be satisfied before a halted system may resume operation.

≠ Kill Functionality
QIS Canonical Extension
QIS-TERM-00058
Protocol

Protocol

QIS-TERM-00017 · MCP · Widely used

An open protocol connecting AI systems to external data sources and tools through a client-server interface, in which a server exposes a declared set of resources, tools and prompts to a host application's client.

≠ A2A
Canonical industry term
QIS-TERM-00017
QIS-TERM-00018 · A2A · Emerging

A protocol for interoperability between autonomous agents built by different vendors on different frameworks — capability discovery, task delegation, and structured message exchange across organizational boundaries.

≠ MCP
Canonical industry term
QIS-TERM-00018
QIS-TERM-00019 · Widely used

The coordination of multiple agents or steps toward an outcome, including sequencing, branching, retry, and the handling of partial failure.

Canonical industry term
QIS-TERM-00019
Authority

Authority

QIS-TERM-00020 · Experimental

The explicit, bounded, revocable and recorded instrument by which a principal permits a named agent to commit specified classes of action, up to stated limits, for a stated term.

≠ Tool Manifest≠ IAM policy≠ Guardrails
QIS Canonical Extension
QIS-TERM-00020
QIS-TERM-00022 · Experimental

The machine-enforceable expression of an authority grant — the runtime boundary beyond which an agent halts or escalates rather than proceeds.

≠ Authority Grant
QIS Canonical Extension
QIS-TERM-00022
QIS-TERM-00024 · Widely used

A permission issued by a principal to a named third party to access specified data, for a specified purpose, for a specified duration, revocable at any time by the principal and enforced at the interface.

≠ Authority Grant≠ Terms of Service
Canonical industry term
QIS-TERM-00024
QIS-TERM-00059 · Experimental

A limit on an autonomous system expressed as a value capable of automated evaluation — a number with a unit, or an enumerated set of permitted members — recorded with who set it, on what basis, where it is enforced, whether that enforcement actually exists, and when it is next reviewed.

≠ Risk Limit≠ Key Risk Indicator≠ Guardrail≠ Threshold
QIS Canonical Extension
QIS-TERM-00059
Auditability

Auditability

QIS-TERM-00021 · ADR · Experimental

The structured record of a single consequential agent action, sufficient to reconstruct it: the authority under which it was taken, the agent and model state that took it, the evidence available at the time, the reasoning trace, the action committed, and the oversight conditions evaluated.

≠ Audit Trail≠ Observability trace
QIS Canonical Extension
QIS-TERM-00021
MARQUE questions

MARQUE questions

QIS-TERM-00025 · Widely used

The permission under which an actor may bind a principal. In agentic finance, the specific answer to: what is this agent permitted to commit, who granted that permission, up to what limit, for how long, and how is it revoked.

≠ Capability≠ Access control
Canonical industry term
QIS-TERM-00025
QIS-TERM-00026 · Widely used

The arrangement by which a human remains accountable for a system's behavior in the interval between a decision being taken and that decision being reviewed. The governed quantity is the interval, not the reviewer.

≠ Monitoring≠ Governance
Canonical industry term
QIS-TERM-00026
QIS-TERM-00027 · Widely used

The degradation of a system's relationship with its objective over time, as conditions move away from those it was built and tested under. Distinguished from a wrong answer: drift produces gradually less right ones.

≠ Data drift≠ Model failure
Canonical industry term
QIS-TERM-00027
QIS-TERM-00028 · Widely used

The property that a past decision can be reconstructed exactly — same inputs, same model state, same evidence, same output — rather than merely narrated from a log.

≠ Logging≠ Explainability
Canonical industry term
QIS-TERM-00028
QIS-TERM-00029 · Widely used

The identification, before the fact, of the named person who answers for a system's consequences — and who has both the authority and the information to have prevented them.

≠ Responsibility≠ Liability
Canonical industry term
QIS-TERM-00029
QIS-TERM-00030 · Emerging

What an agent is, as a distinguishable actor and as a legal matter: whether it can be individually named, whether its actions are attributable to it alone, and to whom its outputs belong.

≠ Authentication≠ Legal personality
Canonical industry term
QIS-TERM-00030
QIS-TERM-00031 · Emerging

What happens when many independently governed agents converge on the same action at the same time, and whether individually compliant systems can be collectively destabilizing.

≠ Concentration risk≠ Herding
Canonical industry term
QIS-TERM-00031
QIS-TERM-00032 · Emerging

The demonstrable property of meeting a stated standard — as distinct from claiming alignment with one. Requires a standard specific enough to fail.

≠ Alignment≠ Certification≠ Compliance
Canonical industry term
QIS-TERM-00032
Strategy families

Strategy families

QIS-TERM-00033 · Widely used

A strategy whose return depends on the direction of price movement, taking long or short positions according to an expected path rather than a spread or a differential.

≠ Long-only
Canonical industry term
QIS-TERM-00033
QIS-TERM-00034 · Widely used

A strategy whose return accrues from holding a position over time — a yield, a roll, or a spread that converges — rather than from a change in direction.

≠ Fixed income
Canonical industry term
QIS-TERM-00034
QIS-TERM-00035 · Widely used

Compensation earned for bearing a risk other participants prefer to avoid. The return is the payment for taking the other side of a structural preference, not for predicting anything.

≠ Alpha
Canonical industry term
QIS-TERM-00035
QIS-TERM-00036 · Widely used

A strategy expressed through instruments whose value derives from an underlying — options, futures, swaps — where the derivative structure is itself essential to the return rather than incidental to it.

≠ Leverage
Canonical industry term
QIS-TERM-00036
QIS-TERM-00037 · Widely used

A strategy that ranks instruments against one another at a point in time and takes offsetting long and short positions across the ranking, rather than comparing an instrument to its own history.

≠ Time-series≠ Market neutral
Canonical industry term
QIS-TERM-00037
QIS-TERM-00038 · Widely used

A strategy held for what it does when other holdings fail, accepting a negative expected return in normal conditions as the price of a payoff in dislocation.

≠ Hedging≠ Diversification
Canonical industry term
QIS-TERM-00038
QIS-TERM-00039 · Widely used

The layer that determines how individual return sources are combined and sized — weighting, risk targeting, rebalancing and constraint application — as distinct from the signals being combined.

≠ Allocation
Canonical industry term
QIS-TERM-00039
Stack categories

Stack categories

QIS-TERM-00040 · Widely used

The property that a system's internal state can be understood from the signals it emits — traces, metrics and logs — without modifying it to ask.

≠ Monitoring≠ Auditability
Canonical industry term
QIS-TERM-00040
QIS-TERM-00041 · Widely used

The layer that coordinates multiple agents or steps toward an outcome — sequencing, branching, retry, and the handling of partial failure.

Canonical industry term
QIS-TERM-00041
QIS-TERM-00042 · Widely used

The systematic measurement of whether a system produces acceptable outputs against defined criteria, on a held-out or adversarial set, before and after deployment.

≠ Validation
Canonical industry term
QIS-TERM-00042
QIS-TERM-00043 · Widely used

The recording of what was run, with which data, code, parameters and result, so that a past experiment can be identified and reproduced.

Canonical industry term
QIS-TERM-00043
QIS-TERM-00044 · Widely used

The selection of relevant material from a corpus and its supply to a model as context, determining what evidence the model sees before it answers.

Canonical industry term
QIS-TERM-00044
QIS-TERM-00045 · Widely used

Retrieval by similarity in an embedding space, returning items whose vector representation is closest to a query's.

≠ Graph traversal
Canonical industry term
QIS-TERM-00045
QIS-TERM-00046 · Widely used

A store in which relationships between entities are first-class and indexed, so that traversal across connections is efficient rather than a series of joins.

Canonical industry term
QIS-TERM-00046
QIS-TERM-00047 · Widely used

The recorded history of a data element — where it came from, what was done to it, and by which job — sufficient to trace an output back to its sources.

Canonical industry term
QIS-TERM-00047
QIS-TERM-00048 · Widely used

The degree to which data is accurate, complete, timely and fit for the specific use being made of it — assessed against declared expectations rather than in the abstract.

Canonical industry term
QIS-TERM-00048
QIS-TERM-00049 · Widely used

The movement of data from a source system into an environment where it can be used, including extraction, transport and initial landing.

Canonical industry term
QIS-TERM-00049
QIS-TERM-00050 · Widely used

The conversion of raw data into analysis-ready form — cleaning, joining, aggregating, deriving — expressed as code and ideally versioned and tested.

Canonical industry term
QIS-TERM-00050
QIS-TERM-00051 · Widely used

A query engine optimized for analytical workloads — scanning and aggregating large columnar datasets — as distinct from transactional processing.

Canonical industry term
QIS-TERM-00051
QIS-TERM-00052 · Widely used

The interface in which analysis is written, executed and iterated — notebooks, IDEs and their execution models.

Canonical industry term
QIS-TERM-00052
QIS-TERM-00053 · Emerging

Programmable rules applied to what a system may accept or emit, enforced in code rather than stated in policy, and capable of halting execution.

Canonical industry term
QIS-TERM-00053
Open data

Built to be traversed, not just read.

Each entry is an entity with a stable identifier, an adoption status, semantic aliases, typed relationships and its own provenance block. Identifiers do not change; URLs may. Cite the identifier.

The relationships carry verbs — governedBy, implements, constrains, delegatesTo, notEquivalentTo — which is what turns a glossary into something queryable. "Show me every term that constrains an agent's authority" is a traversal, not a search.

Free to read, cite and index under the dual license. If a definition here is wrong, or an origin is misattributed, tell us — corrections are published with attribution, and a lexicon nobody corrects is a lexicon nobody uses.