Docs / Glossary

Glossary

The words we use, in plain language.

Accountable person
The human who answers for an organization's agents. They own the rules, approve what needs approval, and alone can promote an agent's autonomy.
Agent
Software that uses an artificial intelligence (AI) model to read and write on someone's behalf. On Envolt Mail every agent has its own address, label and signing identity.
Agent Seal
A signed email header (Envolt-Agent-Seal) that says which agent sent a message, who it works for and how much autonomy it had. Anyone can verify it with the organization's published keys. See the format.
Airlock
Where every inbound message is parsed in isolation, turned into plain text, stripped of hidden content and stored encrypted, before anything reads it.
Anchor
A daily fingerprint of the whole ledger. Once anchored, history can't be rewritten without the change showing.
ASCII smuggling
Hiding text in Unicode tag characters, which render as nothing for people but are read by models. The Airlock removes and counts them.
Single-use capability
A short-lived, one-time permission to send one approved message. Agents never hold a standing key to send.
Case
One inbound message, described in a structured way: intent, urgency, summary, and any commitments or decisions in it.
Disclosure
The plain-language lines that close every agent message: it was written by an agent, for whom, and how to reach a person.
Earned autonomy
Levels from L0 (observe only) to L4 (narrow, audited autonomy). An agent moves up only with a person's approval, backed by its measured record, and drops automatically after any serious mistake.
Ledger
The tamper-evident record of everything that happens. Each event is chained to the one before it by a hash, so a missing or altered event breaks the chain.
Prompt injection
Instructions planted in content to manipulate an AI system. In Envolt Mail, mail is data: nothing in it can change what an agent may do.
Quarantined reader
The model step that describes a message. It has no tools, sees redacted text, can only add warnings, and fails closed to a person.
Receipt
A public page behind each message's verify link: who the agent is, who it works for, whether a person approved. Never the content or recipients.
Seal policy
The policy engine every agent plan must pass: recipients, content, rate limits and approval rules your team owns. Not to be confused with the Agent Seal header.
Trust tier
How much a sender has been verified, from unknown to known contact. It changes how carefully a message is handled, never what an agent is allowed to do.