Updated for the AI Era
The Zero Trust Dictionary, updated for agentic AI.
Every Zero Trust glossary assumes a person is asking for access. Our Zero Trust Dictionary has now been updated to help you apply Zero Trust in the age of agentic AI, covering autonomous agents and non-human identities.
See more resources →Free download
Get the Zero Trust Dictionary
What's inside
A working reference, not a marketing brochure.
The same dictionary ON2IT uses internally, and with the customers we run Zero Trust operations for. Public now, because the alternative, every team improvising its own definitions, is how Zero Trust programs quietly fail.
Core Zero Trust definitions
Protect Surface, DAAS, Microperimeter, the Kipling Method, Asserted Identity, Data Toxicity and more, each anchored in the original strategic intent and extended for a world where the actor requesting access is sometimes software.
New terms for the AI era
Non-Human Identity, Ephemeral Privilege, Tool and API Control, Intent Validation, Prompt Injection and more: vocabulary that wasn't a practical security requirement five years ago and is essential now.
The frameworks you deploy
The Five Steps methodology, the Kipling Method and the Maturity Model, the frameworks you actually put to work, not abstract principles. Plus a Quick Reference your team can pin to a wall.
A preview
A few definitions, on the house.
Three of the nine new AI-era terms. The rest are in the PDF.
Non-Human Identity
Any system, service, API or AI agent that requests access on its own, without a person directing each action. Non-human identities now outnumber human identities in most enterprise environments and are the fastest-growing identity class. They cannot be trained, disciplined or held accountable, they follow logic, not judgment.
Prompt Injection
Manipulating an AI system's behavior by crafting inputs that cause it to override its intended instructions, the AI equivalent of SQL injection. The attack doesn't require network access, only the ability to influence what the agent reads.
Intent Validation
Verifying that what a system is about to do aligns with what it was authorized to do, before it does it. A procurement agent querying HR data is an intent violation, regardless of whether it has technical access to both systems.
Free download
Get the Zero Trust Dictionary
Delivered to your inbox in under a minute. No sales call, no drip campaign that pretends to be insight.
Get the dictionary