Skip to content

Glossary

Agent : A program, usually an AI agent such as Claude Code, that you run in the gate’s sandbox with noset run.

Approval : A person’s decision on a held request: approve or deny. Who may approve comes from the rule’s team and count.

Approval request : A request the gate holds because an ask rule matched it, waiting for approvers.

Ask : The decision that holds a request until people approve it. The others are allow and deny.

Chain : The hash chain the evidence is written in. Each record holds the hash of the one before, so a changed or missing record shows. Your organization has one chain, and each gate has its own.

Channel : Where gates are downloaded from: get.noset.ai (prod) or get.noset.dev (dev). Each channel’s noset logs in to its own Noset Cloud when no --server is given.

Checkpoint : A record of the latest hash of every chain, written once an hour and stamped by an independent time-stamp service, so a rewritten chain no longer matches it.

Credential broker : The part of the gate that keeps real API keys out of the sandbox. The agent sees a placeholder; the gate puts in the real key on the way out. See Credentials.

Evidence : The signed records of what happened: sessions, requests, decisions, approvals, rule changes. Check an evidence file offline with noset verify.

Four eyes : The person who started an agent cannot approve its requests. On by default; an admin can turn it off.

Gate : The noset program on a server next to your agents. It runs each agent in a sandbox, and every request the agent makes leaves through it.

Noset Cloud : Noset run by us at app.noset.ai, with many organizations. Your gates connect to it.

On-prem : The Noset server installed in your own network, with one organization. The gate is the same.

Organization : Your company in Noset: its people, teams, rules, gates and evidence.

Permit : The signed, single-use approval the gate gets when a request is approved. It covers exactly that request, as sent, for 15 minutes.

Rule : What happens to a matching request: allow, ask or deny. See Rule format.

Rule set : A named group of rules. Each gate and agent uses one; changes to it are versioned.

Sandbox : The small virtual machine an agent runs in: no network device, your folder at /workspace, everything else read-only or temporary.

Session : One noset run. It belongs to the person who confirmed it, and its records name that person, the Linux user and the command.