# Breakout controls

Runtime controls that keep an agent aligned to its mission: containing, redirecting, or stopping it when it veers off course, before the action lands.

Learn more: [AI Runtime Security](/content/blog/ai-runtime-security-how-to-protect-your-genai-stack-from-real-world-threats/index.html)

Part of [the Agent Control Fabric](/content/platform/index.html): Highflame's identity, policy, and enforcement substrate for AI agents.

## Glossary Entries

### **Cascade revocation**  
Revoking a parent credential instantly invalidates everything it delegated, collapsing the affected delegation tree rather than waiting for tokens to expire.  
[Read →](/content/glossary/cascade-revocation/index.html)

### **Cedar**  
An open, formally analyzable policy language. Highflame authors authorization policy in Cedar and enforces the same policy at every boundary an agent crosses.  
[Read →](/content/glossary/cedar/index.html)

### **CIBA**  
Client-Initiated Backchannel Authentication: an out-of-band flow that pauses a sensitive agent action for explicit, attributable human approval.  
[Read →](/content/glossary/ciba/index.html)

### **Code agent**  
Autonomous software that reads code, runs commands, calls tools, and changes systems on a developer's behalf. Securing one means controlling what it can access while it runs, and proving afterward what it did.  
[Read →](/content/glossary/code-agent/index.html)

### **Confused deputy**  
An attack where a low-privilege agent tricks a higher-privilege one into acting on its behalf. Scope attenuation prevents it: a sub-agent provably cannot exceed its parent's authority.  
[Read →](/content/glossary/confused-deputy/index.html)

### **Delegated authority**  
The model where an agent acts on behalf of a human or another agent, holding strictly less authority than the principal that authorized it, and provably distinct from that principal.  
[Read →](/content/glossary/delegated-authority/index.html)
