ResourcesGlossary17 terms

Terms for the agentic enterprise

The vocabulary this work needs, defined the way we use it in a report. Where a term already means something in SEO or in security, the difference is stated rather than assumed. Most disagreements about readiness are disagreements about these words.

What the number is made of.

WARI
Webzero Agent Readiness Index
One number for whether an agent sent to your property leaves with the outcome it was sent for, safely, at a defensible cost. Outcome-driven, governance-gated and confidence-adjusted, so it cannot be raised by preparation alone.
Outcome completion
The scoring layer
A value-weighted customer task that finished: the account opened, the claim filed, the instruction booked. The only layer that produces score. Discovery explains a result, governance gates it, cost adjusts it, and none of them add points.
Perturbation set
Adversarial conditions
The deliberate degradations a run is repeated under: stale sessions, reworded labels, slow third parties, partial outages. Readiness measured only on the happy path describes a lab, not a live property.
Confidence adjustment
Sample penalty
Small samples are penalised for their own uncertainty, and thin evidence withholds a score rather than inflating one. Nine of ten is not ninety of a hundred. What you receive is the floor of what agents can do.
Frozen instrument
Versioned benchmark fleet
The agents and task library are pinned between runs. A score movable by tuning the agent would measure the agent; the only way this number rises is that the property got better.

What an agent actually touches.

Action surface
Callable operation
An operation an agent can invoke directly, with a documented schema, idempotency and a returned result. Distinct from a rendered control, which requires a paint, a pointer and a human reading the label.
Trajectory
Run log
The full ordered record of one attempt: every step, retry, branch and dead end. The unit of evidence in a report, and what makes a finding reproducible rather than an assertion.
Dead end
Terminal step
A step from which no available action advances the journey. Costly precisely because everything before it succeeded, so the property paid for discovery, identity and intent and returned nothing.
Conditional branch
Progressive disclosure
Required fields or steps that exist only after a client-side event. Valid to a human clicking through, structurally invisible to a client reading the document, and a leading cause of failed submissions.
Hand-off boundary
Third-party redirect
The point where a journey crosses to a vendor domain for KYC, payment or signature. State, consent scope and return path must cross explicitly; assuming a cookie and a reading human loses the completion.
llms.txt
Machine policy file
A root-level declaration of what machine clients may do, at what rate, and where the callable surfaces are. Necessary and nowhere near sufficient: it announces intent, it does not complete a journey.

What decides whether the score survives.

Governance gate
Non-compensatory control
A control that decides whether score survives instead of contributing to it. Consent, injection resistance, audit trail and confirmation are gates: no volume of completed journeys averages past a missing one.
Scoped consent
Delegated mandate
A recorded, bounded authority for an agent to act for a named customer: which actions, which accounts, for how long. The alternative is an agent impersonating a browser, which is neither auditable nor defensible.
Confirmation contract
Irreversible-action guard
An explicit confirmation step, bound to the stated intent, that an irreversible operation refuses to proceed without. Applies to anything that moves money, cancels cover or closes a position.
Injection resistance
Prompt-injection boundary
Whether instructions embedded in page content, documents or third-party responses can redirect an agent acting under your mandate. Tested as an attack, not reviewed as a policy.
Audit trail
Attributable record
A record that shows which agent, under whose mandate, performed which action, and what was returned. The difference between an agentic channel a risk committee can approve and one it cannot.
Agent access policy
Published contract
The stated terms for machine clients: identification, rate, permitted actions, and how refusals are communicated. An undeclared policy fails the gate even when the underlying controls are sound.

See these terms applied to your property.

A WARI engagement returns every one of them as a measured value with the trajectory evidence behind it.

Read next