Glossary
Short definitions. Each points to where the term is developed.
Agent loop. A runtime loop that asks the model for its next action, runs it and feeds back the result, bounded by step, history, retry and time limits. → Agents and agent loops
Append-only history. An audit table that refuses updates and deletes. In
Parts I and III this is a database trigger (not covering TRUNCATE or the
table owner). In Part V it is application code. → Runtime state, domain state and audit history
Approval token. In Parts I and III, an HMAC-signed, expiring, single-use token binding a human's choice to an action, a resource, an actor, a request, a premise and a payload digest. It is signed by the agent runtime with a secret the model never sees, and verified by the MCP server with the same secret. → Approvals
Authority. The standing to make a consequential decision binding. Distinct from capability and permission. → Capability, permission and authority
AshAI. An Ash extension that exposes Ash actions as AI tools; Tauros serves
them over MCP at /mcp. → AshAI and MCP
BFF (backend-for-frontend). The template's Rust gateway: it holds the OIDC flow and an opaque session, and mints identity headers for internal services. → Security and trust boundaries
BIP39 / BIP32 / BIP44 / BIP86. Standards for mnemonic recovery phrases, hierarchical deterministic key derivation, multi-account paths (used for Ethereum) and Taproot single-key paths (used for Bitcoin). → Derive, don't invent
Capability. What a component can cause at all, usually defined by a tool surface. → Models, tools, capability, identity and authority
Checkpoint. LangGraph's record of a completed graph step, used to resume a thread. Not a business record, and not a guarantee about side effects. → Model execution state
Component evidence. ETF Research's per-component grouping of the facts behind a score, handed to the model so it can explain a decision it did not make. → Design evidence for the model
Conversation. Sophos's application-level container of runs, distinct from a LangGraph thread. → Model execution state
Custody. Effective control over secret material. Arktos separates model custody (none), service custody (transient, in process) and operator custody (holds the master keys). → Model cryptographic authority
Durability boundary. The line between state that must survive a process and state that must not. → Design durability boundaries
Exact-payload approval. Approving a specific immutable revision named by id and content hash, never "whatever the record currently contains". → Exact-payload approval
expected_choice. The premise signed into a Part I/III approval token: the
state or decision the human was shown. The mutation boundary refuses the
token if reality differs. → Approval boundaries
Grounding. Making the system of record the only source of domain facts. Grounded is not the same as correct. → Grounding and authoritative state
Guardrail. A filter on text entering or leaving the agent loop. Not authorisation. → Guardrails and deterministic controls
HKDF. A key derivation function. Arktos uses it to derive purpose-separated subkeys from one master key. → Design key hierarchies
Human-in-the-loop. A design in which the model proposes, a human decides, and deterministic code verifies and applies. → Human-in-the-loop
Idempotency key. A caller-supplied identity making a retried request return the original result instead of acting twice. → Idempotency
Local-first. Owning the important data flows and runtime dependencies, not merely running the model locally. → Local-first and runtime ownership
MCP (Model Context Protocol). A protocol through which an agent discovers and calls tools served by another process. In this book it is used as a capability boundary. → Tools and MCP
Nonce. A single-use value in an approval token, consumed in the same transaction as the mutation so that a replayed token is refused.
Permission. What an actor may do under policy (an Ash policy, an authorisation check). Distinct from authority.
Policy version. rules_version and profile_version in ETF Research,
recorded with every decision. → Decisions that survive policy change
Prompt injection. Instructions smuggled into model input by a user or by data. It can change what a model says or requests; it should never be able to change what the system authorises. → Prompt injection vs deterministic authority
ReAct. A reason-and-act agent pattern: the model alternates between choosing an action and reading its result.
Renormalisation. ETF Research's explicit treatment of missing metrics: re-weighting the available ones and capping the result. → Uncertainty is policy
Revision (Tauros). An immutable snapshot of an invoice's financial payload, sealed with a SHA-256 hash. → Invoice revisions
Run. Sophos's application record of one user message's execution, with a
status (running, completed, failed, interrupted).
→ Model execution state
SQLCipher. An encrypted SQLite. Arktos's database is encrypted with
DATABASE_KEY, independent of the per-record encryption under MASTER_KEY.
SSE (Server-Sent Events). One-way HTTP streaming. Sophos uses it for
live output, with Last-Event-ID reconnection. → Streaming is not persistence
State machine. An explicit set of states and allowed transitions. In
Tauros the only way into approved is the guarded :approve transition.
→ Financial state machines
Thread. LangGraph's identifier for one checkpoint history.
Zeroisation. Overwriting secret material in memory when it is no longer needed. → Minimize secret lifetimes
Tauros roadmap epics
Tauros lessons refer to roadmap epics by number. At the pinned revision:
| Epic | Scope | Status |
|---|---|---|
| 1 | Humans, agents and ownership | done |
| 2 | Payment destination onboarding | done |
| 3 | Invoice drafts and the human approval gate | done |
| 4 | AI capabilities with AshAI | done |
| 5 | Auditability and supervision (incl. database-enforced append-only audit) | planned |
| 6 | Issuing, payments and reconciliation | planned |
| 7 | Data protection and compliance | planned |
| 8 | Semantic search and summaries | planned |
| 9 | Optional Arktos integration | planned |
Source: docs/ROADMAP.md.