AI observability · Highflame Glossary
AI observability
Capturing and querying everything an agent does at runtime, LLM calls, tool calls, file and network activity, tied to identity, so you can ask why something happened and who did it, not just read logs.
Learn more: AI Observability
Part of the Agent Control Fabric: Highflame's identity, policy, and enforcement substrate for AI agents.
Keep exploring the glossary.
[**Attribute-based access control (ABAC)**
Authorization decisions keyed to attributes (the agent's claims, owner, trust tier, and delegation depth) rather than shared keys or static roles.
Read →](/content/glossary/abac/index.html)
[**Authorization**
Deciding whether a given actor is allowed to take a given action. Distinct from authentication (proving who you are); authorization is what an agent may do.
Read →](/content/glossary/authorization/index.html)
[**Blast radius**
The set of systems and data a compromised agent or credential could reach. Identity-scoped access shrinks it; cascade revocation contains it.
Read →](/content/glossary/blast-radius/index.html)
[**Breakout controls**
Runtime controls that keep an agent aligned to its mission: containing, redirecting, or stopping it when it veers off course, before the action lands.
Read →](/content/glossary/breakout-controls/index.html)
[**Cascade revocation**
Revoking a parent credential instantly invalidates everything it delegated, collapsing the affected delegation tree rather than waiting for tokens to expire.
Read →](/content/glossary/cascade-revocation/index.html)
[**Cedar**
An open, formally analyzable policy language. Highflame authors authorization policy in Cedar and enforces the same policy at every boundary an agent crosses.
Read →](/content/glossary/cedar/index.html)