Semantic Cluster

Policy and Access Decisions

Terms that describe how tool-call access decisions are made.

7 terms in this cluster

Policy Evaluation

Policy evaluation is the process of checking an access request against a defined set of rules to determine whether the request should be allowed or denied.

policy evaluationaccess policy checkpolicy engine evaluation

Intent Evaluation

Intent evaluation is the optional process of analyzing the context, goal, or semantic meaning of an agent's tool call request to inform the access decision, beyond just checking the tool name and parameters.

intent evaluationintent-aware authorizationsemantic access control

Intent-Aware Authorization

Intent-aware authorization is an access control approach that considers the semantic intent of an agent's action—what it is trying to accomplish—as part of the access decision, not just the technical attributes of the request.

intent-aware authorizationcontext-aware access controlgoal-aware authorization

Policy and Intent-Driven Access

Policy and intent-driven access is the combination of formal access policy and semantic intent evaluation to produce access decisions for AI agent tool calls—considering both what the agent is permitted to do and what it is trying to accomplish.

policy and intent driven accessintent and policy authorizationsemantic policy enforcement

Default Deny

Default deny is an access control principle where all actions are denied unless explicitly permitted by policy—as opposed to default allow, where actions proceed unless explicitly blocked.

default denydeny by defaultimplicit deny

Human-in-the-Loop Approval

Human-in-the-loop approval is a policy outcome where a tool call that exceeds automated policy thresholds is paused and routed to a human reviewer before execution proceeds.

human in the loop approvalhuman review for agent actionsmanual approval for tool calls

Step-Up Authorization

Step-up authorization is an access control mechanism that requires additional verification or approval before a high-risk or sensitive action is permitted, even when a base level of access has already been granted.

step-up authorizationstep-up authelevated approval for sensitive actions

AI Agent Access Control Glossary

Explore all 9 clusters

Browse the full glossary to understand the complete vocabulary of execution-time access control for AI agents.

Back to Glossary hub
Runtime Enforcement

Secure every agent tool call at execution time.

AgntID gives infrastructure teams scoped, ephemeral access control for AI agents without replacing IAM, MCP servers, tools, or agent frameworks.