Glossary
The words we use, in plain language.
- Accountable person
- The human who answers for an organization's agents. They own the rules, approve what needs approval, and alone can promote an agent's autonomy.
- Agent
- Software that uses an artificial intelligence (AI) model to read and write on someone's behalf. On Envolt Mail every agent has its own address, label and signing identity.
- Agent Seal
- A signed email header (
Envolt-Agent-Seal) that says which agent sent a message, who it works for and how much autonomy it had. Anyone can verify it with the organization's published keys. See the format. - Airlock
- Where every inbound message is parsed in isolation, turned into plain text, stripped of hidden content and stored encrypted, before anything reads it.
- Anchor
- A daily fingerprint of the whole ledger. Once anchored, history can't be rewritten without the change showing.
- ASCII smuggling
- Hiding text in Unicode tag characters, which render as nothing for people but are read by models. The Airlock removes and counts them.
- Single-use capability
- A short-lived, one-time permission to send one approved message. Agents never hold a standing key to send.
- Case
- One inbound message, described in a structured way: intent, urgency, summary, and any commitments or decisions in it.
- Disclosure
- The plain-language lines that close every agent message: it was written by an agent, for whom, and how to reach a person.
- Earned autonomy
- Levels from L0 (observe only) to L4 (narrow, audited autonomy). An agent moves up only with a person's approval, backed by its measured record, and drops automatically after any serious mistake.
- Ledger
- The tamper-evident record of everything that happens. Each event is chained to the one before it by a hash, so a missing or altered event breaks the chain.
- Prompt injection
- Instructions planted in content to manipulate an AI system. In Envolt Mail, mail is data: nothing in it can change what an agent may do.
- Quarantined reader
- The model step that describes a message. It has no tools, sees redacted text, can only add warnings, and fails closed to a person.
- Receipt
- A public page behind each message's verify link: who the agent is, who it works for, whether a person approved. Never the content or recipients.
- Seal policy
- The policy engine every agent plan must pass: recipients, content, rate limits and approval rules your team owns. Not to be confused with the Agent Seal header.
- Trust tier
- How much a sender has been verified, from unknown to known contact. It changes how carefully a message is handled, never what an agent is allowed to do.