Every label on this platform resolves here.
Most reference sites use category labels as though the reader already knows what they mean. Observability, Directional, Auditability, Fiduciary duty — words doing structural work with nothing behind them. On this platform every one of them resolves to a definition, and the build fails if one does not.
Agent-to-agent vocabulary is roughly where cloud computing was in 2008: four major vendors, two protocol ecosystems, a Treasury-convened lexicon and a steady supply of academic papers, all using overlapping terms with incompatible meanings. The canon covers that vocabulary, the eight MARQUE questions, the strategy families, the stack categories and the legal doctrine — with one field nobody else publishes.
Every glossary defines terms positively. This one also defines them negatively.
Positive definition tells you what a word means. It does not tell you which adjacent word you have confused it with, and confusion between adjacent terms is the actual failure mode in a young vocabulary.
An Agent Card, a Model Card, a System Prompt and a Tool Manifest are four different artifacts with four different lifecycles, and they are used interchangeably every day. That is not a pedantic complaint — it has governance consequences:
A tool manifest declares what an agent can reach. An authority grant declares what it may commit, under whose authority, and up to what limit. Reading the first as the second is the most likely agentic governance error of the next two years, and it happens because the vocabulary permits it.
So every entry here carries a notEquivalentTo field, with the reason. There are 82 of them.
Two tiers, and we never blur them.
- Canonical industry term — the term exists in the wild. We document it and cite its origin. We do not get to define these; we get to describe them accurately, and if we have described one badly we would like to know.
- QIS Canonical Extension — a proposal from us, filling a gap we have documented elsewhere in the standards register or the control-objective crosswalk. Labeled as ours on every page, without exception.
There are only 6 extensions, deliberately. Proposing a term is legitimate; presenting a proposal as settled usage is not, and inventing vocabulary because it sounds impressive is how an ontology loses the credibility it exists to accumulate.
Identity & discovery
A machine-readable document published by an agent that advertises what it is and what it can do — identity, declared capabilities, and the endpoints through which another agent may interact with it.
The property that a specific agent is distinguishable as a durable, named actor — with an identifier that persists across sessions, a recorded authority grant, and an action history attributable to it alone.
A catalog of known agents, their identities, declared capabilities, and endpoints, maintained so that agents and operators can discover one another without prior configuration.
The line across which assumptions about trustworthiness change, and at which input must therefore be validated and authority re-established.
A URI that resolves to a document containing public keys, authentication methods and service endpoints, controlled by its subject rather than issued by a central registry, and designed to be verifiable and persistent across the platforms the subject uses.
A software system that takes consequential action toward a goal without a human approving each action. Used in this corpus only where the qualified form would be imprecise; every governance claim about an agent attaches to a qualified term instead.
Capability
The process by which one agent learns what another agent or service is able to do, without that knowledge having been configured in advance.
The declared set of tools, resources and prompts an MCP server exposes to a client — the machine-readable statement of what an agent is able to reach.
A single call by an agent to a declared tool, with structured arguments and a structured result.
The transfer of responsibility for achieving an outcome from one agent to another, where the receiving agent determines how the outcome is reached.
Context & memory
The bounded span of tokens a model can attend to in a single inference, containing the prompt, retrieved material, and conversation so far.
The persistence layer through which an agent carries state across invocations — prior decisions, retrieved documents, learned preferences — distinct from both the model weights and the context window.
The passing of task-relevant state between agents so that a receiving agent can act without re-deriving what the sending agent already established.
An attack exploiting how an application combines untrusted input with a prompt written by a higher-trust party, causing the system to follow the untrusted instructions.
Oversight
A risk-control approach in which a human is integrated within an AI system's decision-making process.
The exercised ability of a human to ignore, alter, reject or reverse a system output or action.
Layered safeguards — policies, technical controls and monitoring — applied at the data, model, application and infrastructure levels to keep a system operating within organizational or regulatory boundaries.
The sequenced, tamper-evident record of what occurred, sufficient to establish the order and content of events after the fact.
A capability, required to be maintained and exercisable rather than merely described, to immediately cease some or all automated action as an emergency measure — without the cooperation, consent, or continued functioning of the system it stops.
The set of preconditions — cause identified or its absence expressly recorded, an accountable individual's written authorization, and, where a capability is owed to a counterparty, advance notice — that must be satisfied before a halted system may resume operation.
Protocol
An open protocol connecting AI systems to external data sources and tools through a client-server interface, in which a server exposes a declared set of resources, tools and prompts to a host application's client.
A protocol for interoperability between autonomous agents built by different vendors on different frameworks — capability discovery, task delegation, and structured message exchange across organizational boundaries.
The coordination of multiple agents or steps toward an outcome, including sequencing, branching, retry, and the handling of partial failure.
Auditability
The structured record of a single consequential agent action, sufficient to reconstruct it: the authority under which it was taken, the agent and model state that took it, the evidence available at the time, the reasoning trace, the action committed, and the oversight conditions evaluated.
MARQUE questions
The permission under which an actor may bind a principal. In agentic finance, the specific answer to: what is this agent permitted to commit, who granted that permission, up to what limit, for how long, and how is it revoked.
The arrangement by which a human remains accountable for a system's behavior in the interval between a decision being taken and that decision being reviewed. The governed quantity is the interval, not the reviewer.
The degradation of a system's relationship with its objective over time, as conditions move away from those it was built and tested under. Distinguished from a wrong answer: drift produces gradually less right ones.
The property that a past decision can be reconstructed exactly — same inputs, same model state, same evidence, same output — rather than merely narrated from a log.
The identification, before the fact, of the named person who answers for a system's consequences — and who has both the authority and the information to have prevented them.
What an agent is, as a distinguishable actor and as a legal matter: whether it can be individually named, whether its actions are attributable to it alone, and to whom its outputs belong.
What happens when many independently governed agents converge on the same action at the same time, and whether individually compliant systems can be collectively destabilizing.
The demonstrable property of meeting a stated standard — as distinct from claiming alignment with one. Requires a standard specific enough to fail.
Strategy families
A strategy whose return depends on the direction of price movement, taking long or short positions according to an expected path rather than a spread or a differential.
A strategy whose return accrues from holding a position over time — a yield, a roll, or a spread that converges — rather than from a change in direction.
Compensation earned for bearing a risk other participants prefer to avoid. The return is the payment for taking the other side of a structural preference, not for predicting anything.
A strategy expressed through instruments whose value derives from an underlying — options, futures, swaps — where the derivative structure is itself essential to the return rather than incidental to it.
A strategy that ranks instruments against one another at a point in time and takes offsetting long and short positions across the ranking, rather than comparing an instrument to its own history.
A strategy held for what it does when other holdings fail, accepting a negative expected return in normal conditions as the price of a payoff in dislocation.
The layer that determines how individual return sources are combined and sized — weighting, risk targeting, rebalancing and constraint application — as distinct from the signals being combined.
Stack categories
The property that a system's internal state can be understood from the signals it emits — traces, metrics and logs — without modifying it to ask.
The layer that coordinates multiple agents or steps toward an outcome — sequencing, branching, retry, and the handling of partial failure.
The systematic measurement of whether a system produces acceptable outputs against defined criteria, on a held-out or adversarial set, before and after deployment.
The recording of what was run, with which data, code, parameters and result, so that a past experiment can be identified and reproduced.
The selection of relevant material from a corpus and its supply to a model as context, determining what evidence the model sees before it answers.
Retrieval by similarity in an embedding space, returning items whose vector representation is closest to a query's.
A store in which relationships between entities are first-class and indexed, so that traversal across connections is efficient rather than a series of joins.
The recorded history of a data element — where it came from, what was done to it, and by which job — sufficient to trace an output back to its sources.
The degree to which data is accurate, complete, timely and fit for the specific use being made of it — assessed against declared expectations rather than in the abstract.
The movement of data from a source system into an environment where it can be used, including extraction, transport and initial landing.
The conversion of raw data into analysis-ready form — cleaning, joining, aggregating, deriving — expressed as code and ideally versioned and tested.
A query engine optimized for analytical workloads — scanning and aggregating large columnar datasets — as distinct from transactional processing.
The interface in which analysis is written, executed and iterated — notebooks, IDEs and their execution models.
Programmable rules applied to what a system may accept or emit, enforced in code rather than stated in policy, and capable of halting execution.
Legal doctrine
The obligation of a person entrusted with another's interests to act in that person's interest rather than their own — comprising, for investment advisers, a duty of care and a duty of loyalty that cannot be waived, though their application varies with the scope of the relationship.
The obligation to exercise the skill, prudence and diligence that a reasonable professional would exercise in the same circumstances — measured against a standard of conduct, not against the outcome.
Critical analysis of a model by objective, competent parties with sufficient independence to maintain objectivity and enough organizational standing to compel change.
Built to be traversed, not just read.
Each entry is an entity with a stable identifier, an adoption status, semantic aliases, typed relationships and its own provenance block. Identifiers do not change; URLs may. Cite the identifier.
The relationships carry verbs — governedBy, implements, constrains, delegatesTo, notEquivalentTo — which is what turns a glossary into something queryable. "Show me every term that constrains an agent's authority" is a traversal, not a search.
Free to read, cite and index under the dual license. If a definition here is wrong, or an origin is misattributed, tell us — corrections are published with attribution, and a lexicon nobody corrects is a lexicon nobody uses.