Glossary
The terms you meet in the AlphaAgent Console, the Organisations console and Studio, alphabetical, each defined once with a link to the page that explains it in full. Product surfaces are named as you see them: the AlphaAgent Console (hosted by Prometheus Research Labs), the Organisations console (installed in your AWS account) and Studio (deployed into an AWS account per deployment); where a term is spelt differently on two surfaces, both spellings are given.
Terms
Active configuration
The agent version, knowledge-graph version, connectors and execution environment an agent runs with. You set it on the Agent Map with Save & Activate; editing an agent creates a new version but does not change what is live until you activate it. In chat, the ⓘ button in the composer opens Active Configuration for the conversation. See Agents: configure.
Agent
A versioned worker you define with a name, a system prompt and a type. A Specialist focuses on a domain and can be used in chat and in Workflows; a Supervisor works only inside Workflows and takes no knowledge graph, connector or environment. Every edit creates a new agent version. See Agents: create and view.
Agent Map
The section of an agent's view page where you wire the agent to one knowledge-graph version, up to eight data connectors and one execution environment, then Save & Activate. See Agents: configure.
Agent Store
The External Agent Store: curated agents published by Prometheus Research Labs. Download puts a copy into your own Agents, Inactive, ready for you to wire up before activating. See Agent Store.
AMPG
Augmented Multi-Resolution Property Graph, the product name for a Studio knowledge graph. The dock tile reads AMPGs; the canvas reads Knowledge Graphs. See Knowledge graph.
AMPG update (workflow step)
A workflow step that builds the next training PDF from the results of the connected steps and creates the next version of a knowledge graph. Rewrite (default) has Opus rewrite the base version's documents with the learnings into one new document; Append keeps them and adds a document with only the learnings. The base is always the graph's newest Ready version ("Starts from vN"). See Workflows: knowledge-graph update node.
API key
A credential minted in the Organisations console under Programmatic Access that lets another system run one governed deployment's workflows over the workflow API. It is two values shown once: the key, sent as Authorization: Bearer ak_<id>.<secret>, and the key external id, sent as the X-AlphaAgent-Key-External-Id header on every call. A key has scopes, an optional IP allow-list and allowed hours, an expiry, and its own rate limit, daily run quota and concurrency. See Programmatic access and Authentication.
Approval gate
A pause in a run that waits for you. On a board card or an Inbox card it appears as Awaiting review (a produced result: Accept), Awaiting go-ahead (before a step runs: Approve & run) or Wants to run a command (Allow this command), each with Send back and a note. See Chat: the board and mentions and Inbox.
Board (Plan tab)
The right-hand pane's Plan tab in a chat or a workflow run: one card per step (node), connected by dependency edges, with status pills Pending, Running, Done, Needs re-run, Blocked, Awaiting you, Failed, Cancelled and Skipped. Clicking a card opens the node inspector with its Thread, Tool Calls, Governor and Evidence tabs. See Chat: the board and mentions.
Break-glass owner
The email address you give during the Organisations install as the first owner. After single sign-on is configured, the console is reached only through your identity provider, and this owner row is what lets you grant access to anyone else. See Install Organisations.
Buyer account
The AWS account that accepted your AWS Marketplace Private Offer and whose AWS bill carries the AlphaAgent charges. Nothing is deployed into it. See Console account, offer and licence.
Clear account
The action on a registered AWS account's page in the Organisations console that scans the account and region for every AlphaAgent resource still there and permanently deletes it, leaving the account's own registration role in place. See Deleting a deployment and clearing an account.
CloudFront front door
The CloudFront distribution the Organisation places in front of every Studio deployment's load balancer. The deployment's DNS target (CNAME) points at it, and once your DNS record resolves to it the load balancer is locked to CloudFront traffic. See Deployment detail.
Coder
The component an agent delegates code to. It runs in the agent's execution environment, reads and writes files in the workspace and produces deliverables. When a step is sent back, your note goes to the coder ("Send to the coder"). See How agents run code.
Console (AlphaAgent Console)
The web portal hosted by Prometheus Research Labs where you create your account and organisation, accept and link your AWS Marketplace subscription, create licence keys, download the Organisations bundle and mint the Organisation credential. It never connects to your AWS account. See Console licences, usage and billing.
Data connector
A versioned link that gives agents read access to an external system: SQL Database (PostgreSQL or MySQL), Snowflake, REST API, MCP Server or AWS. Every save creates a new version; agents pin a version. A connector pulled from a Library can arrive as Needs attention until its credentials are re-entered. See Data connectors.
Dataset
A tabular file an agent produced during a run. It is listed under Datasets in a node's Evidence tab and opens in the Preview tab. See Chat: files, previews and approvals.
Deliverable
A file a step produced for you (a PDF, document, spreadsheet, chart or data file). It appears as a card in the thread with Open in Preview, Download and Add to chat, and under Deliverables in the run's Summary. See Chat: files, previews and approvals.
Deployment
One installation of Studio in one AWS account and region, created and managed from the Organisations console. Its status is Provisioning, Awaiting input, Healthy, Degraded, Failed, Deleting, Disabled or Uninstalled. A deployment is standard or governed for its whole life. See Fleet.
Diagnostic ID
The job id shown on a failure card in the Organisations console, with a Copy button. Quote it when you contact support. See Support.
Doctor
python3 orgctl.py doctor: eleven groups of checks on an installed Organisation (secrets, tables, the admin roster, container images, services, the account template, CORS, SAML wiring, sign-out, the Console credential). Any failure exits with status 2 and names the command that repairs it. See Troubleshooting the install.
Enforcement state
Two related things. On the Console side, a licence's enforcement_status: active, or a hold such as billing_suspended, payment_overdue_warning, suspended_manual, terms_violation, security_hold, trial_expired, decommissioned or maintenance; a blocking hold is delivered to Studio on the next heartbeat with a message. On the Studio side, the runtime's health state: STARTING, OK, BLOCKED (recoverable) or KILLED (sticky). In BLOCKED or KILLED every product request answers HTTP 451 and Studio shows the Service halted banner. See What leaves your account and Banners you may see.
Execution environment
The sandboxed Linux container in which an agent runs Python and shell tools: a prebuilt AlphaAgent Python image or a custom image you push to the deployment's repository, with memory, storage and timeout you choose. Its status is Active, Creating…, Needs attention, Needs provisioning or Inactive. See Execution environments.
External ID
A secret the Organisations console generates when you register an AWS account, shown once. You pass it to the account template as the ExternalId parameter; the target role's trust policy then admits the Organisation only when it presents that value. The console shows a 12-character fingerprint so you can compare without revealing it. See Accounts.
Failure code
The stable name of the reason a deployment job stopped, for example access_denied_missing_action or stack_create_failed, shown under Technical details on the failure card with its message, what to check, who acts (Customer account, AlphaAgent or AWS) and whether it is resumable. See Failure codes and Jobs, progress and failures.
Fleet
The list of every Studio deployment your Organisation manages, on the Organisations console's home. See Fleet.
Fleet Configuration Template
A saved, versioned set of deployment settings (release, environment, sizing, node type, inference zone, model ids, PII redaction default) that can pre-fill the new-deployment wizard or be pinned by an Update Manager rule. Saving a template increments its version. See Fleet configurations and Update Manager.
Governed deployment
A deployment whose Ownership was set to Governed in the wizard: every agent, workflow, connector, environment and knowledge graph is shared by everyone assigned, everyone can open and download every user's workspace files (your own files still land in your own folder), the PII redaction default is Mask, and the workflow API is available. Studio shows the chip "Governed deployment · resources are shared by everyone assigned". The alternative is a standard deployment: each user owns what they create and sees only their own. See Working in a governed deployment and Deploy your first Studio.
Governor
The reviewer that oversees every run. Its lines appear on a card's Governor badge and in the node inspector's Governor tab as ACTIVATED, VERDICT, NOTE, STEER, GROUNDING REQUESTED, BUDGET EXHAUSTED and PROCEEDING. Its tokens are metered under the kind Governor. See Governor.
Grounding
Retrieval from the knowledge-graph version an agent pins, done before or during a step so the answer rests on your documents. The AMPG tab of the right pane shows the concepts retrieved and the grounding queries; a node's Evidence tab lists the retrievals. See Chat: the board and mentions.
Handoff
A workflow step that pauses the run until you read a message in your Inbox and choose Approve & run, Send back or Stop. See Workflows: build.
Heartbeat
The signed check-in Studio sends to the Console every five minutes to confirm its licence is valid; while a beat is failing it retries every 30 seconds. The Console records connectivity as healthy, warning (one or two missed) or unhealthy (three or more missed). A failed or unsigned beat, or a Console verdict that the licence is not valid, halts Studio until the next good beat. See What leaves your account.
Identity provider
Your Microsoft Entra ID tenant, connected once in the Organisations console under Identity Providers through a multi-tenant app registration you create and grant admin consent to. Once connected, linking a deployment to it provisions Studio's single sign-on automatically and lets administrators assign users and groups. This is a different object from the Organisations console's own SAML application (see SAML application). See Identity Providers and Connect your identity provider.
Inbox
The Studio screen that gathers everything that needs you, is running or has just finished, filtered as All, Needs you, Running and Done. Cards are approval cards, publish cards (a new knowledge-graph version ready to adopt), running cards with Stop, and done cards. In a governed deployment, approvals from API-triggered runs appear for everyone assigned. See Inbox.
Inference zone
The Bedrock zone a deployment's model calls stay within: us or eu. It is set from the AWS account you pick in the wizard and must match that account's region. See Deploy your first Studio and Supported models.
Job
One unit of work the Organisation runs against a deployment: Install, Upgrade, Reconfigure, Rollback, Uninstall or Account wipe. A job has steps, a status (Queued, Starting, Running, Waiting for approval, Waiting for input, Succeeded, Failed, Rolled back, Cancelled) and, when it fails, a failure card. See Jobs, progress and failures.
Knowledge graph
A graph built from one PDF (up to 32 pages) that agents ground their answers in. Every build is a separate version with status Building, Ready, Failed, Cancelled or Deleting; agents pin a Ready version and keep using it until you move them. Also called an AMPG. See Knowledge graphs and Knowledge graphs in depth.
Library (Resource Store)
A shared home, created in the Organisations console, for one type of resource (agents, workflows, data connectors, environments or knowledge graphs) that your Organisation reuses across deployments. Members hold Contributor or Reader access. In Studio the same object is called a Resource Store. See Libraries and Libraries and sharing.
Licence key
The Console entitlement that authorises one Studio deployment. Its public identifier starts with aalk_; the License Token (aalk_<id>.***) is shown once at creation and pasted into the new-deployment wizard, which shows it back as "Licence provided". Studio activates against the Console with it and heartbeats from then on. See Console account, offer and licence.
Metering kind
The activity a token count is attributed to. Sixteen kinds exist, fifteen of them billable: coordinator turn, worker node, Governor, context summary, thought-map summary, visualisation contract, coder analysis, workflow condition, PII redaction, knowledge-graph build, edge discovery, embeddings and retrieval, connector guide and connector auth inference; stream metadata is recorded but not billed. Only token counts and the principal leave your account, never content. Deployment analytics can be split By activity using these kinds. See What leaves your account and Deployment detail.
My Pulls
The Studio screen listing every pull you have requested across every Resource Store you belong to, with status Pending, a phase while it is claimed, Done (opens your copy) or Rejected (shows the reason). See Libraries and sharing.
Organisation (AlphaAgent Organisations)
The management plane you install into one AWS account with orgctl.py: the Organisations console and the services behind it that register target accounts, deploy and update Studio, manage identity, roles, Libraries, API keys and audit. One Organisation manages a fleet of deployments. See The Organisations console: layout and roles.
Organisation credential
The machine credential minted on the Console's Organisation page and given to python3 orgctl.py console-credential, with which the Organisation authenticates to the Console to download Studio releases. See Install Organisations.
orgctl.py
The installer and operator command in the Organisations bundle. Run with no arguments it guides you through the install; it also offers install, status, reset, teardown and one subcommand per install step, including preflight, saml and doctor. It installs Organisations only; Studio is deployed from the Organisations console. See Install Organisations.
Parked step
A job step waiting for a person: Upload your SAML metadata, Proceed despite failed readiness checks or Confirm a destructive action. The card in the Jobs view names who can unblock it and offers Abandon this job. See Jobs, progress and failures.
PII redaction
Removal of personal data from what a workflow reads and writes. A deployment sets the floor (Off, Mask or Hash; Mask by default on governed deployments); a workflow or a run can tighten it (including Drop rows) but never loosen it. A Redact PII step writes a redacted copy of a file before it leaves the run. See PII redaction and PII redaction posture.
Preflight
Checks run before anything is created. orgctl.py runs fifteen before installing Organisations; the new-deployment wizard's Run preflight checks the target account before you launch. See Install Organisations and Deploy your first Studio.
Private Offer
The AWS Marketplace offer Prometheus Research Labs issues to you at your rate. Accepting it from your buyer account and linking it in the Console is what allows licence keys to be created. See Console account, offer and licence.
Provenance
The line "Pulled from (deployment) · library vN · (date)" under the header of a copy you pulled from a Resource Store. See Libraries and sharing.
Pull (Download a copy)
Taking your own copy of an item from a Resource Store with Download vN. The copy arrives Inactive, ready for you to wire up. When you already hold a copy behind the library's version, the action reads Update my copy to vN; when your copy is current it reads Up to date. See Libraries and sharing.
Release
A published version of Studio (for example 2.0.14) on a channel (stable). The Organisation mirrors releases from the Console; the wizard's Version picker and a Fleet Configuration Template's Which release list only versions already mirrored. See Fleet configurations and Update Manager.
Role and grant
In the Organisations console a Role bundles Policies (permissions); a grant gives a Role to a person or a group, org-wide or on one deployment, Library, account or identity provider. StudioUser on a deployment is the grant that lets someone sign in to that Studio. See Users, groups and roles.
Run
One execution of a workflow (Run Now, a schedule or the API) or one chat turn on the board. A workflow run's status is Starting, Running, Needs you, Completed, Failed or Stopped. See Workflows: run, schedule, approve.
Run data retention
The number of days a workflow run's inputs and outputs are kept before the deployment's storage lifecycle rule expires them: 1 to 3,650, default 90, set in the wizard and changeable with Change… on the deployment's Overview. See Deployment detail.
SAML application (Organisations console)
The non-gallery SAML Enterprise Application your identity administrator creates in Entra ID during the Organisations install, from the Entity ID, Reply URL and Sign-on URL that orgctl.py prints, with the claims email, given_name and family_name. Its federation metadata XML is what python3 orgctl.py saml asks for. It signs administrators in to the Organisations console; it is not the connected identity provider that provisions Studio sign-in. See Sign in to the Organisations console with Entra ID.
Seat
One user who can sign in to one Studio deployment, counted as a StudioUser grant on that deployment (directly or through a group). A deployment has 20 seats by default. See Users, groups and roles.
Share (share request)
Pushing one version of your agent, workflow, connector, environment or knowledge graph into a Resource Store you contribute to, with Share on its view page. The Shared to strip then shows Pending, Accepted (with the library version it became) or Rejected (with the reason). See Libraries and sharing.
Sizing profile
How much compute a deployment's services get: xs, small, standard, large or xlarge. Blank means Automatic, which is standard. A change is applied through a Fleet Configuration Template and restarts the affected services. See Infrastructure sizing and costs.
Studio (AlphaAgent Studio)
The application your team works in day to day, deployed into its own AWS account from the Organisations console. See Getting started and What runs in your account: Studio.
Target account and target role
A target account is an AWS account you register in the Organisations console for Studio deployments. Registering it hands you a CloudFormation template that creates the target role (AlphaAgentOrgTarget-<suffix>, suffix prod by default), the one role the Organisation assumes in that account; its trust policy admits only the Organisation's task role presenting the account's External ID, and it denies actions outside the regions you allow. Verify on the account page checks the role can be assumed. See Accounts and Register an AWS account.
Thought map
The picture on the AMPG tab of the concepts an agent retrieved from its knowledge graph during a run, with the grounding queries that produced them. Reconstruct Thought replays the retrievals in order. See Chat: the board and mentions.
Update Manager
Rules in the Organisations console that keep chosen deployments on the release and configuration a Fleet Configuration Template specifies, on a schedule and optionally only inside a maintenance window. A rule pins a template version; Adopt vN moves it to a newer one. Each rule keeps a run history. See Fleet configurations and Update Manager.
Version
Studio never overwrites: every save of an agent, data connector or workflow creates a new numbered version, and every build of a knowledge graph is a new version. Agents and workflows pin the versions they use; a workflow's active version is the one Run Now and schedules use.
Workflow
A board of steps you lay out by hand (Task, Handoff, Conditional, AMPG update, Redact PII, up to 20) and run on demand, on a schedule or from the API, on the same engine as chat. Every save is a version; you activate one. See Workflows: build.
Workspace
Your file area in the deployment, shown on the Files tab. Every conversation and every run has its own folder under your root; uploads land in the current conversation's folder; All my files shows everything of yours, and in a governed deployment Everyone's files shows every user's files read-only. See Chat: files, previews and approvals.
Notes
- If a word on screen is not defined here, search the site for it: the page that documents that screen quotes its labels exactly.