## Shared glossary

These terms describe boundaries that recur throughout the book\.&#32;They are grouped by the confusion they resolve\,&#32;not by API name\.

### State\,&#32;identity\,&#32;and scope

**Live context\,&#32;model context\,&#32;and journal\.**&#32;Live messages are held by the running agent\.&#32;Model context is prepared from that state through conversion and transformation boundaries\.&#32;The durable JSONL journal can retain older and alternative entries that are not in current model context\.&#32;None is automatically an exact captured provider request\.&#32;See&#32;[the continuity ledger](<https://present-sketch-tp94.here.now/chapters/continuity-the-continuity-ledger>)\.

**Persistent session identity and provider\-facing identity\.**&#32;`SessionManager.getSessionId()`&#32;identifies the saved conversation’s header identity\.&#32;In the described implementation\,&#32;`AgentSession.sessionId`&#32;is provider\-facing\.&#32;`/fresh`&#32;can change the latter while preserving the former\.&#32;A provider prompt\-cache key is another value\;&#32;sharing or inheriting one does not prove a cache hit or savings\.

**Entry\,&#32;leaf\,&#32;and branch\.**&#32;An entry is a journal record with its own identity and parent relationship\.&#32;The leaf selects a current path through those records\.&#32;A branch is not every entry in the file\.&#32;Seed Desk reconstructs state from&#32;`getBranch()`&#32;so a sibling snapshot is not silently treated as current\.&#32;Tree navigation and a new\-file conversational fork are different operations\.

**Reset boundary\.**&#32;A saved&#32;`reset_boundary`&#32;tells supported context rebuilds where cleared conversation context stops contributing\.&#32;It does not remove earlier journal entries\,&#32;erase a memory backend\,&#32;scrub exports\,&#32;or restore workspace files\.

**Cwd and project scope\.**&#32;Cwd is the working directory associated with an operation or session\.&#32;Launch cwd\,&#32;recorded header cwd\,&#32;and active runtime cwd can differ during fallback or failure\.&#32;Memory’s recorded per\-project bank uses resolved cwd\,&#32;not Git root\.&#32;Extension\-module discovery and skill discovery also have different traversal rules\.

**Durable memory\,&#32;bank\,&#32;store\,&#32;and injection\.**&#32;Durable memory is retained material available for later retrieval\.&#32;A bank identifies retrieval\/storage scope\;&#32;a row’s store affects what edits are supported\.&#32;Injection is the selected memory instructions and recalled text placed into current context\,&#32;not the entire database\.&#32;The recorded Mnemopi working\,&#32;episodic\,&#32;and extracted\-fact behaviors are not interchangeable\.&#32;See&#32;[the Memory command desk](<https://present-sketch-tp94.here.now/chapters/memory-the-command-desk>)\.

**Global override and resolved default\.**&#32;These describe where a configuration value came from\.&#32;A persisted global override is not proof of a global memory bank\,&#32;successful runtime initialization\,&#32;or healthy provider access\.&#32;The Memory table reports a snapshot\,&#32;not a current\-machine audit\.

**Runtime override and effective wrapper policy\.**&#32;A&#32;`Settings.override()`&#32;value is not persisted like&#32;`Settings.set()`\.&#32;The approval wrapper also reads execute\-time&#32;`autoApprove`&#32;separately from settings\.&#32;A displayed approval mode can therefore differ from the mode the wrapper uses\.&#32;Configuration inspection is not a live audit of another call or process\.&#32;See&#32;[Configuration and launch precedence](<https://present-sketch-tp94.here.now/chapters/permissions-configuration-and-launch-precedence>)\.

**Compaction and managed skill\.**&#32;Compaction makes room by summarizing active conversational context\.&#32;A managed skill is separately stored procedural guidance in a&#32;`SKILL.md`&#32;file\.&#32;Neither is a database wipe\,&#32;a guaranteed complete record\,&#32;or a deterministic script that automatically executes\.&#32;See&#32;[four places knowledge can live](<https://present-sketch-tp94.here.now/chapters/memory-four-places-knowledge-can-live>)\.

### Workers\,&#32;views\,&#32;and lifetimes

**Tan\.**&#32;An OMP tangent subagent\:&#32;a contextual\,&#32;tool\-capable child conversation that can run concurrently with Main\.&#32;It is not TanStack\,&#32;an ordinary task subagent under every task\-executor convention\,&#32;or an isolated checkout\.

**Agent ID\,&#32;job ID\,&#32;and process name\.**&#32;The agent ID addresses a conversation\/registration\.&#32;The background job ID addresses a managed run\,&#32;notably the initial Tan run\.&#32;A process name addresses a separately supervised server\,&#32;watcher\,&#32;debugger\,&#32;or similar process\.&#32;Discover their actual association before acting\;&#32;a shared display label is not a mapping\.

**Focus\.**&#32;The currently addressed chat view\.&#32;Selecting a Hub row is not yet successful focus\.&#32;Automatic return to Main can change the recipient of an unfinished draft\.&#32;Closing an overlay may reveal the prior chat rather than Main\.&#32;See&#32;[Leave and switch safely](<https://present-sketch-tp94.here.now/chapters/tan-5-leave-and-switch-safely>)\.

**Running\,&#32;idle\,&#32;parked\,&#32;aborted\,&#32;and absent\.**&#32;These are agent lifecycle states\,&#32;not background\-job outcomes\.&#32;Idle has an attached live session\;&#32;parked requires revival for new work\;&#32;aborted is terminal in the explicit\-kill case\;&#32;absent means no current registration\,&#32;not necessarily no transcript\.&#32;Check job state separately\.

**Cold revival\.**&#32;Reconstructing an eligible parked agent from retained history and saved initialization information using available host resources\.&#32;It does not restore a complete old runtime\,&#32;restart the original job\,&#32;or guarantee identical tools\,&#32;settings\,&#32;model\,&#32;or resource mappings\.

**Steering and follow\-up\.**&#32;Steering changes the direction of current work at supported agent\-loop boundaries\.&#32;A follow\-up waits until the current work would otherwise yield\.&#32;Focused Enter\,&#32;the follow\-up chord\,&#32;and peer messaging are distinct input paths\.&#32;Queued does not mean processed\,&#32;persisted as a durable ticket\,&#32;or completed\.

**Turn and run\.**&#32;A run can contain several assistant turns\,&#32;tool results\,&#32;and maintenance continuations\.&#32;Memory’s periodic retention threshold counts new USER turns\,&#32;not assistant replies or tool calls\.&#32;Auto\-learn’s eligible tool\-call threshold is a separate loop\.&#32;Keep each source’s counting unit attached to its setting\.

**Conversation fork and workspace isolation\.**&#32;A fork separates conversation identity or history paths\.&#32;It does not create a Git branch\,&#32;worktree\,&#32;repository snapshot\,&#32;or rollback mechanism\.&#32;Shared file effects are already present in the shared workspace\;&#32;there is no automatic Tan merge operation\.

**Initial child settings and live inheritance\.**&#32;`createSubagentSettings()`&#32;snapshots base values\,&#32;defaults child approval mode to yolo\,&#32;and then applies explicit helper overrides\.&#32;Both Task construction and the supplied initial Tan controller use it\.&#32;Per\-tool policy values remain relevant\.&#32;Later live runtime inheritance\,&#32;shared callbacks\,&#32;and revival are separate paths\;&#32;conversation ancestry does not clone every safeguard or prove permanent synchronization\.&#32;Provider service\-tier inheritance is not read\/write\/exec tier inheritance\.

**Module\-local\,&#32;factory\-local\,&#32;and branch\-local\.**&#32;Module state can be shared through cached imports\.&#32;Factory\-local state belongs to one binding\,&#32;which can survive transcript changes\.&#32;Branch\-local state is reconstructed from the selected journal ancestry\.&#32;The word session\-local is too imprecise unless the actual lifetime is stated\.&#32;See&#32;[Package Lab](<https://present-sketch-tp94.here.now/chapters/extensions-package-lab-one-file-to-an-embedded-host>)\.

**Reload\,&#32;rebind\,&#32;and new session\.**&#32;Reload may reopen a journal\.&#32;Rebinding calls a prepared factory against a fresh runtime\.&#32;A new session changes conversation identity but can reuse extension closures\.&#32;None should be used as shorthand for all three effects\.

### Authority\,&#32;results\,&#32;and observation

**Host approval\,&#32;domain grant\,&#32;and trust\.**&#32;Host approval gates a tool under host policy\.&#32;A domain grant authorizes a particular application action\,&#32;often with identity and revision limits\.&#32;Trust in an in\-process extension permits code execution\;&#32;it is not an operating\-system sandbox\.&#32;A grant cannot be inferred from draft text\,&#32;a recalled memory\,&#32;or an MCP notification\.

**Tool availability and presentation\.**&#32;Availability concerns whether a capability is enabled and reachable in the actual session\.&#32;`loadMode`&#32;concerns presentation of an enabled tool\,&#32;not permission for every call\.&#32;An enabled mounted device can be absent from the top\-level schema\.&#32;An allow policy does not install a missing tool\.

**Tool tier\.**&#32;The&#32;`read`\,&#32;`write`\,&#32;or&#32;`exec`&#32;declaration used by approval resolution\,&#32;possibly computed from arguments\.&#32;An omitted declaration defaults to exec\.&#32;A tier is not a sandbox\,&#32;syscall audit\,&#32;or proof of zero effects\:&#32;some declared read operations change agent\/job state\,&#32;and ordinary reads can use the network\.&#32;It is unrelated to a provider’s processing service tier\.

**Approval mode\.**&#32;The default tier comparison\:&#32;`always-ask`&#32;admits read\;&#32;`write`&#32;admits read and write\;&#32;`yolo`&#32;admits all tiers\.&#32;Higher\-precedence applicable policies remain relevant\.&#32;The schema default in the permissions snapshot is yolo\,&#32;not a claim about the reader’s settings\.&#32;Always\-ask does not mean every call prompts\.

**Approval policy and provenance\.**&#32;`allow`\,&#32;`prompt`\,&#32;and&#32;`deny`&#32;are resolver outcomes and supported explicit policies\.&#32;Tool deny and effective user deny precede automatic admission\.&#32;Explicit tool allow\/prompt can outrank non\-deny user policy\.&#32;A resolved&#32;`source`&#32;identifies tool\,&#32;user\,&#32;or mode where supplied\;&#32;it is not execution evidence\.&#32;See&#32;[Approval Desk](<https://present-sketch-tp94.here.now/chapters/permissions-approval-desk-modes-and-policies>)\.

**Policy key and invoking\-tool fallback\.**&#32;`policyKey`&#32;lets a declaration select another user\-policy identity\,&#32;such as a device reached through write\.&#32;A missing or invalid keyed policy falls back to the invoking tool’s policy\.&#32;A valid keyed policy replaces that fallback\,&#32;including a fallback deny\;&#32;the lookup is not an intersection of every entry\.&#32;Raw property presence can still matter to a later wrapper predicate even when normalization ignored its value\.

**Override\-only prompt and explicit prompt\.**&#32;`override: true`&#32;without an explicit policy requests prompting in non\-yolo resolution but is ignored in yolo\.&#32;An explicit tool prompt survives the resolver’s yolo branch\.&#32;An override combined with explicit tool allow remains allow after deny checks\.&#32;Forwarded xdev prompting has an additional wrapper predicate\,&#32;so resolver policy and actual nested prompt count are not interchangeable\.

**AutoApprove\.**&#32;The execute\-time boolean that makes the wrapper use yolo before resolution\.&#32;The supplied built\-in CLI sets it through&#32;`--auto-approve`&#32;or&#32;`--yolo`\,&#32;not a listed&#32;`-y`&#32;alias\.&#32;It can outrank a displayed explicit approval mode but does not remove effective explicit denies or acknowledge pending provider safety checks\.

**One\-call approval and declined call\.**&#32;The generic wrapper offers Approve and Deny\.&#32;Only exact Approve is positive\;&#32;dismissal\/undefined is refused\,&#32;and a throwing selector stops the call\.&#32;The answer does not persist an allow\-for\-session policy\.&#32;A declined call is different from a configured deny and does not undo earlier effects\.

**Forwarded xdev approval\.**&#32;`xdevApproved`&#32;is context used to suppress a particular unchanged\-input duplicate prompt after an outer write gate\.&#32;Explicit user policy\,&#32;surviving overrides\,&#32;provider checks\,&#32;and supported input replacement affect the inner decision\.&#32;The source tests object identity\,&#32;not a domain revision hash\.&#32;It is not an arbitrary nested\-tool grant\.&#32;See&#32;[Dispatch Desk](<https://present-sketch-tp94.here.now/chapters/permissions-dispatch-desk-device-and-path-gates>)\.

**Pending provider safety checks\.**&#32;Computer\-provider metadata can require explicit acknowledgement independently of ordinary tier admission\.&#32;The wrapper sets&#32;`providerSafetyApproved`&#32;after the required positive selection\.&#32;Synthetic metadata tests prove that local transition\,&#32;not provider delivery\,&#32;physical computer behavior\,&#32;or the entirety of provider safety policy\.

**Permission\-denied file fallback\.**&#32;A later seam for selected denied native byte writes or unlinks\,&#32;not the approval dialog and not an elevated writer by itself\.&#32;Write and delete registries are separate and process\-wide\;&#32;requests identify origin and resolved target according to the primitive\.&#32;A handler’s true result is a durability\/completion contract\,&#32;not a grant or independent proof\.&#32;Unsupported routes and host policy remain separate\.

**Revision\.**&#32;A precondition token or counter whose meaning belongs to its issuer\.&#32;Seed Desk uses session and state\-entry identity\;&#32;Review Desk uses a numeric domain counter with separate authority invalidation\;&#32;the website uses opaque document revisions\.&#32;A content revision identifies authored material\,&#32;not the fresh page state required by&#32;`act()`\.&#32;The generic tool approval does not replace these domain preconditions\.

**Returned content and structured details\.**&#32;Extension tool&#32;`content`&#32;is the normal model\-facing result\.&#32;`details`&#32;is host\/rendering metadata and is not automatically model\-visible\.&#32;A custom renderer or notification is presentation\,&#32;not a substitute for a complete queryable result\.

**Owner anchor\,&#32;delivery ID\,&#32;receipt\,&#32;and wake\.**&#32;An owner anchor records where delayed work belongs\.&#32;A stable delivery ID supports deduplicated retry\.&#32;The receipt describes body admission or commitment\,&#32;while wake describes whether another agent turn is scheduled or pending\.&#32;A committed body is not proof that the model answered it\.&#32;See&#32;[owner\-addressed delivery](<https://present-sketch-tp94.here.now/chapters/extensions-background-work-and-owner-addressed-delivery>)\.

**Read\-only observation\.**&#32;Read\-only names the intended mutation boundary\,&#32;not a universal promise of zero side effects or disclosure\.&#32;A Main request can require model use\;&#32;a Hub job inspection can consume delivery bookkeeping\;&#32;an extension’s show command can append a custom message\.&#32;Read the exact operation contract\.&#32;Do not silently equate this phrase with every operation declared read\-tier\.

**Completion\.**&#32;Settlement of an operation and correctness of an assignment are different claims\.&#32;A completed job\,&#32;accepted message\,&#32;nonthrowing domain refusal\,&#32;or success banner must be interpreted through its actual result fields and postconditions\.&#32;Approval requested\/resolved events and prompt counts likewise do not replace an execution or effect count\.

**TUI\,&#32;RPC\,&#32;and ACP\.**&#32;TUI is terminal presentation and input\.&#32;RPC and ACP provide host\/client protocol surfaces\,&#32;with adapter\-specific semantic UI\.&#32;`hasUI`&#32;does not mean every terminal component\,&#32;dialog option\,&#32;or composer method works\.&#32;Protocol proof is not physical terminal proof\.&#32;In the supplied approval runner\,&#32;`hasUI()`&#32;tests for a non\-no\-op adapter\;&#32;RPC can install a select\-capable adapter\,&#32;while ACP form support depends on negotiation\.

### Copies\,&#32;disclosure\,&#32;and evidence

**Artifact and internal resource address\.**&#32;Artifacts are stored outputs or session\-adjacent resources\,&#32;not necessarily workspace files\.&#32;`memory://`\,&#32;`history://`\,&#32;`local://`\,&#32;`artifact://`\,&#32;and&#32;`agent://`&#32;are OMP resource schemes with different handlers\,&#32;not HTTP endpoints on this site\.&#32;Follow actual returned IDs and links\;&#32;a Tan transcript does not imply an ordinary\-task result artifact exists\.&#32;`xd://`&#32;is a tool\-dispatch address\,&#32;not an operator grant\.

**Sidecar\.**&#32;An auxiliary file whose meaning depends on the operation\:&#32;a dump JSON file\,&#32;a memory database companion\,&#32;or an agent tombstone are not the same object\.&#32;Temporary or adjacent does not mean automatically deleted\,&#32;fully backed up\,&#32;or safe to disclose\.

**Dump\,&#32;export\,&#32;and share\.**&#32;A dump represents current context and can create clipboard text plus a temporary sidecar\.&#32;HTML export copies session\-manager history\,&#32;with live versus file\-based metadata differences and possible nested transcripts\.&#32;Sharing uses a default snapshot or a custom executable route and is a separate disclosure decision\.&#32;See&#32;[choosing a snapshot](<https://present-sketch-tp94.here.now/chapters/continuity-review-packet-choosing-a-snapshot>)\.

**Embedded and offline\.**&#32;Embedded data can be recovered from a file even when its viewer fails\.&#32;The described HTML viewer still depends on CDN scripts\;&#32;the recorded blocked\-script case displayed controls but no transcript\.&#32;Base64 encoding is not encryption\.

**Redaction\,&#32;encryption\,&#32;trimming\,&#32;cancellation\,&#32;and revocation\.**&#32;Redaction transforms selected outgoing data according to available recognition and field rules\.&#32;Encryption controls access to a sealed representation\.&#32;Trimming loses content to meet a size budget\.&#32;Cancellation may stop only a particular phase or UI\.&#32;Revocation would withdraw access or authority\;&#32;no generic share\-link revocation workflow is established here\.&#32;None substitutes for recipient and purpose approval\.

**Recorded observation\,&#32;source\-backed expectation\,&#32;and exercise\.**&#32;A recorded observation belongs to the named historical check\.&#32;A source\-backed expectation follows the supplied source account\.&#32;An exercise is a result to reason about or independently test\.&#32;Browser lesson ticks are a fourth thing\:&#32;self\-report\.&#32;Combining the books does not upgrade any of these into new live verification\.&#32;The permissions cases’ expected fields remain authored data\;&#32;their separate executed report supplies observations for the named cases only\.
