Shared glossary
These terms describe boundaries that recur throughout the book. They are grouped by the confusion they resolve, not by API name.
State, identity, and scope
Live context, model context, and journal. Live messages are held by the running agent. Model context is prepared from that state through conversion and transformation boundaries. The durable JSONL journal can retain older and alternative entries that are not in current model context. None is automatically an exact captured provider request. See the continuity ledger.
Persistent session identity and provider-facing identity. SessionManager.getSessionId() identifies the saved conversation’s header identity. In the described implementation, AgentSession.sessionId is provider-facing. /fresh can change the latter while preserving the former. A provider prompt-cache key is another value; sharing or inheriting one does not prove a cache hit or savings.
Entry, leaf, and branch. An entry is a journal record with its own identity and parent relationship. The leaf selects a current path through those records. A branch is not every entry in the file. Seed Desk reconstructs state from getBranch() so a sibling snapshot is not silently treated as current. Tree navigation and a new-file conversational fork are different operations.
Reset boundary. A saved reset_boundary tells supported context rebuilds where cleared conversation context stops contributing. It does not remove earlier journal entries, erase a memory backend, scrub exports, or restore workspace files.
Cwd and project scope. Cwd is the working directory associated with an operation or session. Launch cwd, recorded header cwd, and active runtime cwd can differ during fallback or failure. Memory’s recorded per-project bank uses resolved cwd, not Git root. Extension-module discovery and skill discovery also have different traversal rules.
Durable memory, bank, store, and injection. Durable memory is retained material available for later retrieval. A bank identifies retrieval/storage scope; a row’s store affects what edits are supported. Injection is the selected memory instructions and recalled text placed into current context, not the entire database. The recorded Mnemopi working, episodic, and extracted-fact behaviors are not interchangeable. See the Memory command desk.
Global override and resolved default. These describe where a configuration value came from. A persisted global override is not proof of a global memory bank, successful runtime initialization, or healthy provider access. The Memory table reports a snapshot, not a current-machine audit.
Runtime override and effective wrapper policy. A Settings.override() value is not persisted like Settings.set(). The approval wrapper also reads execute-time autoApprove separately from settings. A displayed approval mode can therefore differ from the mode the wrapper uses. Configuration inspection is not a live audit of another call or process. See Configuration and launch precedence.
Compaction and managed skill. Compaction makes room by summarizing active conversational context. A managed skill is separately stored procedural guidance in a SKILL.md file. Neither is a database wipe, a guaranteed complete record, or a deterministic script that automatically executes. See four places knowledge can live.
Workers, views, and lifetimes
Tan. An OMP tangent subagent: a contextual, tool-capable child conversation that can run concurrently with Main. It is not TanStack, an ordinary task subagent under every task-executor convention, or an isolated checkout.
Agent ID, job ID, and process name. The agent ID addresses a conversation/registration. The background job ID addresses a managed run, notably the initial Tan run. A process name addresses a separately supervised server, watcher, debugger, or similar process. Discover their actual association before acting; a shared display label is not a mapping.
Focus. The currently addressed chat view. Selecting a Hub row is not yet successful focus. Automatic return to Main can change the recipient of an unfinished draft. Closing an overlay may reveal the prior chat rather than Main. See Leave and switch safely.
Running, idle, parked, aborted, and absent. These are agent lifecycle states, not background-job outcomes. Idle has an attached live session; parked requires revival for new work; aborted is terminal in the explicit-kill case; absent means no current registration, not necessarily no transcript. Check job state separately.
Cold revival. Reconstructing an eligible parked agent from retained history and saved initialization information using available host resources. It does not restore a complete old runtime, restart the original job, or guarantee identical tools, settings, model, or resource mappings.
Steering and follow-up. Steering changes the direction of current work at supported agent-loop boundaries. A follow-up waits until the current work would otherwise yield. Focused Enter, the follow-up chord, and peer messaging are distinct input paths. Queued does not mean processed, persisted as a durable ticket, or completed.
Turn and run. A run can contain several assistant turns, tool results, and maintenance continuations. Memory’s periodic retention threshold counts new USER turns, not assistant replies or tool calls. Auto-learn’s eligible tool-call threshold is a separate loop. Keep each source’s counting unit attached to its setting.
Conversation fork and workspace isolation. A fork separates conversation identity or history paths. It does not create a Git branch, worktree, repository snapshot, or rollback mechanism. Shared file effects are already present in the shared workspace; there is no automatic Tan merge operation.
Initial child settings and live inheritance. createSubagentSettings() snapshots base values, defaults child approval mode to yolo, and then applies explicit helper overrides. Both Task construction and the supplied initial Tan controller use it. Per-tool policy values remain relevant. Later live runtime inheritance, shared callbacks, and revival are separate paths; conversation ancestry does not clone every safeguard or prove permanent synchronization. Provider service-tier inheritance is not read/write/exec tier inheritance.
Module-local, factory-local, and branch-local. Module state can be shared through cached imports. Factory-local state belongs to one binding, which can survive transcript changes. Branch-local state is reconstructed from the selected journal ancestry. The word session-local is too imprecise unless the actual lifetime is stated. See Package Lab.
Reload, rebind, and new session. Reload may reopen a journal. Rebinding calls a prepared factory against a fresh runtime. A new session changes conversation identity but can reuse extension closures. None should be used as shorthand for all three effects.
Authority, results, and observation
Host approval, domain grant, and trust. Host approval gates a tool under host policy. A domain grant authorizes a particular application action, often with identity and revision limits. Trust in an in-process extension permits code execution; it is not an operating-system sandbox. A grant cannot be inferred from draft text, a recalled memory, or an MCP notification.
Tool availability and presentation. Availability concerns whether a capability is enabled and reachable in the actual session. loadMode concerns presentation of an enabled tool, not permission for every call. An enabled mounted device can be absent from the top-level schema. An allow policy does not install a missing tool.
Tool tier. The read, write, or exec declaration used by approval resolution, possibly computed from arguments. An omitted declaration defaults to exec. A tier is not a sandbox, syscall audit, or proof of zero effects: some declared read operations change agent/job state, and ordinary reads can use the network. It is unrelated to a provider’s processing service tier.
Approval mode. The default tier comparison: always-ask admits read; write admits read and write; yolo admits all tiers. Higher-precedence applicable policies remain relevant. The schema default in the permissions snapshot is yolo, not a claim about the reader’s settings. Always-ask does not mean every call prompts.
Approval policy and provenance. allow, prompt, and deny are resolver outcomes and supported explicit policies. Tool deny and effective user deny precede automatic admission. Explicit tool allow/prompt can outrank non-deny user policy. A resolved source identifies tool, user, or mode where supplied; it is not execution evidence. See Approval Desk.
Policy key and invoking-tool fallback. policyKey lets a declaration select another user-policy identity, such as a device reached through write. A missing or invalid keyed policy falls back to the invoking tool’s policy. A valid keyed policy replaces that fallback, including a fallback deny; the lookup is not an intersection of every entry. Raw property presence can still matter to a later wrapper predicate even when normalization ignored its value.
Override-only prompt and explicit prompt. override: true without an explicit policy requests prompting in non-yolo resolution but is ignored in yolo. An explicit tool prompt survives the resolver’s yolo branch. An override combined with explicit tool allow remains allow after deny checks. Forwarded xdev prompting has an additional wrapper predicate, so resolver policy and actual nested prompt count are not interchangeable.
AutoApprove. The execute-time boolean that makes the wrapper use yolo before resolution. The supplied built-in CLI sets it through --auto-approve or --yolo, not a listed -y alias. It can outrank a displayed explicit approval mode but does not remove effective explicit denies or acknowledge pending provider safety checks.
One-call approval and declined call. The generic wrapper offers Approve and Deny. Only exact Approve is positive; dismissal/undefined is refused, and a throwing selector stops the call. The answer does not persist an allow-for-session policy. A declined call is different from a configured deny and does not undo earlier effects.
Forwarded xdev approval. xdevApproved is context used to suppress a particular unchanged-input duplicate prompt after an outer write gate. Explicit user policy, surviving overrides, provider checks, and supported input replacement affect the inner decision. The source tests object identity, not a domain revision hash. It is not an arbitrary nested-tool grant. See Dispatch Desk.
Pending provider safety checks. Computer-provider metadata can require explicit acknowledgement independently of ordinary tier admission. The wrapper sets providerSafetyApproved after the required positive selection. Synthetic metadata tests prove that local transition, not provider delivery, physical computer behavior, or the entirety of provider safety policy.
Permission-denied file fallback. A later seam for selected denied native byte writes or unlinks, not the approval dialog and not an elevated writer by itself. Write and delete registries are separate and process-wide; requests identify origin and resolved target according to the primitive. A handler’s true result is a durability/completion contract, not a grant or independent proof. Unsupported routes and host policy remain separate.
Revision. A precondition token or counter whose meaning belongs to its issuer. Seed Desk uses session and state-entry identity; Review Desk uses a numeric domain counter with separate authority invalidation; the website uses opaque document revisions. A content revision identifies authored material, not the fresh page state required by act(). The generic tool approval does not replace these domain preconditions.
Returned content and structured details. Extension tool content is the normal model-facing result. details is host/rendering metadata and is not automatically model-visible. A custom renderer or notification is presentation, not a substitute for a complete queryable result.
Owner anchor, delivery ID, receipt, and wake. An owner anchor records where delayed work belongs. A stable delivery ID supports deduplicated retry. The receipt describes body admission or commitment, while wake describes whether another agent turn is scheduled or pending. A committed body is not proof that the model answered it. See owner-addressed delivery.
Read-only observation. Read-only names the intended mutation boundary, not a universal promise of zero side effects or disclosure. A Main request can require model use; a Hub job inspection can consume delivery bookkeeping; an extension’s show command can append a custom message. Read the exact operation contract. Do not silently equate this phrase with every operation declared read-tier.
Completion. Settlement of an operation and correctness of an assignment are different claims. A completed job, accepted message, nonthrowing domain refusal, or success banner must be interpreted through its actual result fields and postconditions. Approval requested/resolved events and prompt counts likewise do not replace an execution or effect count.
TUI, RPC, and ACP. TUI is terminal presentation and input. RPC and ACP provide host/client protocol surfaces, with adapter-specific semantic UI. hasUI does not mean every terminal component, dialog option, or composer method works. Protocol proof is not physical terminal proof. In the supplied approval runner, hasUI() tests for a non-no-op adapter; RPC can install a select-capable adapter, while ACP form support depends on negotiation.
Copies, disclosure, and evidence
Artifact and internal resource address. Artifacts are stored outputs or session-adjacent resources, not necessarily workspace files. memory://, history://, local://, artifact://, and agent:// are OMP resource schemes with different handlers, not HTTP endpoints on this site. Follow actual returned IDs and links; a Tan transcript does not imply an ordinary-task result artifact exists. xd:// is a tool-dispatch address, not an operator grant.
Sidecar. An auxiliary file whose meaning depends on the operation: a dump JSON file, a memory database companion, or an agent tombstone are not the same object. Temporary or adjacent does not mean automatically deleted, fully backed up, or safe to disclose.
Dump, export, and share. A dump represents current context and can create clipboard text plus a temporary sidecar. HTML export copies session-manager history, with live versus file-based metadata differences and possible nested transcripts. Sharing uses a default snapshot or a custom executable route and is a separate disclosure decision. See choosing a snapshot.
Embedded and offline. Embedded data can be recovered from a file even when its viewer fails. The described HTML viewer still depends on CDN scripts; the recorded blocked-script case displayed controls but no transcript. Base64 encoding is not encryption.
Redaction, encryption, trimming, cancellation, and revocation. Redaction transforms selected outgoing data according to available recognition and field rules. Encryption controls access to a sealed representation. Trimming loses content to meet a size budget. Cancellation may stop only a particular phase or UI. Revocation would withdraw access or authority; no generic share-link revocation workflow is established here. None substitutes for recipient and purpose approval.
Recorded observation, source-backed expectation, and exercise. A recorded observation belongs to the named historical check. A source-backed expectation follows the supplied source account. An exercise is a result to reason about or independently test. Browser lesson ticks are a fourth thing: self-report. Combining the books does not upgrade any of these into new live verification. The permissions cases’ expected fields remain authored data; their separate executed report supplies observations for the named cases only.
Connections and next steps · Unified editorial chapter; connects the recorded source material without rerunning it.