On-behalf-of (OBO) chain · Highflame Glossary

On-behalf-of (OBO) chain

The unbroken provenance recorded on a credential (who authorized the action, what scope was granted, and how deep the delegation goes) so an audit walks back to a human.

Learn more: Agent Authorization

Part of the Agent Control Fabric: Highflame's identity, policy, and enforcement substrate for AI agents.

Glossary Terms

Prompt injection

An attack that manipulates an agent through crafted input (in a prompt, a tool result, or retrieved content) to make it act against policy.
Read → Prompt injection

Red teaming

Continuous adversarial testing of AI systems (jailbreaks, extraction, manipulation) with findings turned into enforcement policy and re-scanned to prove the fix.
Read → Red teaming

RFC 8693 (token exchange)

The standard that lets one token be exchanged for another with attenuated scope: the basis for verifiable agent-to-agent delegation.
Read → RFC 8693

Scope attenuation

Narrowing permissions at each delegation hop so a sub-agent can never hold more authority than the agent that delegated to it.
Read → Scope attenuation

Shadow agents

Agents running across clouds, IDEs, and SaaS that no one inventoried or assigned an owner: the unmanaged majority of an enterprise's agent footprint.
Read → Shadow agents

Shadow AI

The AI tools and autonomous agents adopted across an organization without IT's approval. Shadow IT for the agent era, and faster, because an agent takes minutes to wire up and can act on real systems.
Read → Shadow AI