<!-- Envolt Mail · https://envoltmail.com/docs/glossary · Markdown version of this page for AI agents. Status: in development (https://envoltmail.com/status). -->

[Docs](https://envoltmail.com/docs) / Glossary

# Glossary

The words we use, in plain language.

- **Accountable person**: The human who answers for an organization's agents. They own the rules, approve what needs approval, and alone can promote an agent's autonomy.
- **Agent**: Software that uses an artificial intelligence (AI) model to read and write on someone's behalf. On Envolt Mail every agent has its own address, label and signing identity.
- **Agent Seal**: A signed email header (`Envolt-Agent-Seal`) that says which agent sent a message, who it works for and how much autonomy it had. Anyone can verify it with the organization's published keys. See the [format](https://envoltmail.com/docs/builders#agent-seal).
- **Airlock**: Where every inbound message is parsed in isolation, turned into plain text, stripped of hidden content and stored encrypted, before anything reads it.
- **Anchor**: A daily fingerprint of the whole ledger. Once anchored, history can't be rewritten without the change showing.
- **ASCII smuggling**: Hiding text in Unicode tag characters, which render as nothing for people but are read by models. The Airlock removes and counts them.
- **Single-use capability**: A short-lived, one-time permission to send one approved message. Agents never hold a standing key to send.
- **Case**: One inbound message, described in a structured way: intent, urgency, summary, and any commitments or decisions in it.
- **Disclosure**: The plain-language lines that close every agent message: it was written by an agent, for whom, and how to reach a person.
- **Earned autonomy**: Levels from L0 (observe only) to L4 (narrow, audited autonomy). An agent moves up only with a person's approval, backed by its measured record, and drops automatically after any serious mistake.
- **Ledger**: The tamper-evident record of everything that happens. Each event is chained to the one before it by a hash, so a missing or altered event breaks the chain.
- **Prompt injection**: Instructions planted in content to manipulate an AI system. In Envolt Mail, mail is data: nothing in it can change what an agent may do.
- **Quarantined reader**: The model step that describes a message. It has no tools, sees redacted text, can only add warnings, and fails closed to a person.
- **Receipt**: A public page behind each message's verify link: who the agent is, who it works for, whether a person approved. Never the content or recipients.
- **Seal policy**: The policy engine every agent plan must pass: recipients, content, rate limits and approval rules your team owns. Not to be confused with the Agent Seal header.
- **Trust tier**: How much a sender has been verified, from unknown to known contact. It changes how carefully a message is handled, never what an agent is allowed to do.
