# CIBA

Client-Initiated Backchannel Authentication: an out-of-band flow that pauses a sensitive agent action for explicit, attributable human approval.

Part of [the Agent Control Fabric](/content/platform/index.html): Highflame's identity, policy, and enforcement substrate for AI agents.

## Glossary Terms

### Code agent
Autonomous software that reads code, runs commands, calls tools, and changes systems on a developer's behalf. Securing one means controlling what it can access while it runs, and proving afterward what it did.\
[Read →](/content/glossary/code-agent/index.html)

### Confused deputy
An attack where a low-privilege agent tricks a higher-privilege one into acting on its behalf. Scope attenuation prevents it: a sub-agent provably cannot exceed its parent's authority.\
[Read →](/content/glossary/confused-deputy/index.html)

### Delegated authority
The model where an agent acts on behalf of a human or another agent, holding strictly less authority than the principal that authorized it, and provably distinct from that principal.\
[Read →](/content/glossary/delegated-authority/index.html)

### Delegation depth
How many on-behalf-of hops a credential sits from its original human authorizer. Highflame enforces depth as a first-class policy primitive.\
[Read →](/content/glossary/delegation-depth/index.html)

### DPoP
Demonstrating Proof-of-Possession (RFC 9449): binds a token to a proof key so a stolen token is inert without it.\
[Read →](/content/glossary/dpop/index.html)

### Enterprise Managed Authorization (EMA)
An MCP extension that lets a company's identity provider decide, through corporate SSO, which MCP servers an agent may connect to. It governs admission, not what the agent does once inside.\
[Read →](/content/glossary/ema/index.html)
