Code agent · Highflame Glossary

Code agent

Autonomous software that reads code, runs commands, calls tools, and changes systems on a developer's behalf. Securing one means controlling what it can access while it runs, and proving afterward what it did.

Learn more: Code agent security

Part of the Agent Control Fabric: Highflame's identity, policy, and enforcement substrate for AI agents.

Glossary Entries

Confused deputy

An attack where a low-privilege agent tricks a higher-privilege one into acting on its behalf. Scope attenuation prevents it: a sub-agent provably cannot exceed its parent's authority.

Delegated authority

The model where an agent acts on behalf of a human or another agent, holding strictly less authority than the principal that authorized it, and provably distinct from that principal.

Delegation depth

How many on-behalf-of hops a credential sits from its original human authorizer. Highflame enforces depth as a first-class policy primitive.

DPoP

Demonstrating Proof-of-Possession (RFC 9449): binds a token to a proof key so a stolen token is inert without it.

Enterprise Managed Authorization (EMA)

An MCP extension that lets a company's identity provider decide, through corporate SSO, which MCP servers an agent may connect to. It governs admission, not what the agent does once inside.

Guardrails

Inline detection and enforcement on an agent's prompts, tool calls, and responses: blocking unsafe actions in real time.