Defined terms used across the Digital Information Governance reference. Each term has a single canonical definition and a stable anchor, so it can be cited directly. Version 1.1 adds the action-layer vocabulary: the terms organizations need once AI systems act on information rather than only reading it.
Core discipline
| Term | Definition |
|---|---|
| Digital Information Governance® (DIG) | A discipline for keeping AI-influenced decisions defensible and auditable. The decision layer above data, information, and AI governance. |
| AI decision governance | The common-language name for DIG: governing how AI-influenced decisions are made, recorded, and defended. |
| Information Provenance | Where the information feeding a decision came from, and whether it can be trusted. |
| Decision Traceability | A record of what was decided, by what, on what basis, and who is accountable. |
| Representation Integrity | Keeping a company accurately represented across AI systems, search, and data environments. |
| Audit Readiness | Being able to prove, on demand, that AI-influenced decisions met their obligations. |
| Decision integrity | The runtime discipline of capturing the attestation of a decision at the moment it is made. |
| Defensible AI decision | An AI-influenced decision that can be reconstructed, explained, and justified after the fact. |
| Information governance | The records and data lifecycle discipline (storage, retention, deletion). Distinct from DIG. |
The action layer: agentic AI terms
Added in v1.1 (September 2026). These terms describe governing AI that acts, the subject of AI agent governance.
| Term | Definition |
|---|---|
| Agentic AI | AI systems that pursue goals by taking actions through tools and interfaces, rather than only generating content for a person to act on. |
| AI agent | A software system that uses an AI model to decide on and carry out actions (tool calls, browser use, transactions) toward an assigned objective, with limited or no step-by-step human direction. |
| Digital employee | An AI agent doing work a person would otherwise do, operating real interfaces such as a keyboard, mouse, terminal, or browser. The term frames the governance expectation: identity, permission, and audit, like any employee. |
| Action layer | The governance layer concerned with what an AI did, extending decision-level governance one step further, from the decision to the act. Added to the DIG framework in v1.1. |
| AI agent governance | The discipline of keeping AI-executed actions defensible and auditable: what an agent was authorized to see, decide, and do, who approved that authority, and whether the action can be reconstructed afterward. |
| Execution boundary | The written limit of what an agent is permitted to do: the systems it may touch, the actions it may take, the thresholds it may not cross. At maturity Level 4 the boundary is tested, not assumed. |
| Delegated authority | Decision rights an organization has formally assigned to an AI agent, including their scope and thresholds. |
| Delegation record | The record of a grant of authority to an agent: what was delegated, by whom, when, under what conditions, and how it can be revoked. |
| Approval gate | A required human sign-off inserted before an agent action executes, typically for actions past a defined risk threshold. |
| Agent identity | A distinct, non-human identity under which an agent authenticates and acts, so that its actions are attributable and separable from any person's. |
| Scoped credential | A credential granting an agent only the access its task requires, in contrast to borrowing a person's full access. |
| Credential borrowing | An agent operating under a human's credentials, which makes its actions indistinguishable from that person's in every log. The Level 1 marker of agentic maturity. |
| Least privilege (for agents) | Granting an agent the minimum access and action rights its task requires, and nothing else. |
| Action trail | The action-level record of what an agent did: tool calls, commands, page loads, and the approvals attached to each. |
| Replayability | The property that an agent's sequence of actions can be reconstructed end to end from records after the fact. |
| Containment | The rehearsed ability to pause, revoke, or roll back an agent and its actions when something goes wrong. At Level 5 it is a tested control, not a hope. |
| Kill switch | A control that immediately halts an agent's ability to act. The containment tool of last resort. |
| Rollback | Undoing the effects of an agent's actions after execution. Part of containment. |
| Human-in-the-loop | An oversight design in which a person approves each consequential action before it executes. |
| Human-on-the-loop | An oversight design in which agents act autonomously while a person monitors and can intervene. Oversight attaches to the grant, not to each action. |
| Agent inventory | The maintained list of every agent, automation, and tool-using AI in an organization, with the credentials and access each one holds. The Level 3 floor. |
| Agent sprawl | The accumulation of agents nobody inventories: deployed independently by teams, each holding credentials and taking actions outside any governance view. |
| Machine-speed risk | Risk amplified because agents act far faster and more often than people, so a small authorization error compounds before anyone notices. |
| Misaligned action | An action an AI takes that was not authorized, or that does not serve the objective its operator intended. Frontier-lab safety frameworks name containing these actions as a design goal. |
| Autonomous action | An action an agent executes without a person approving that specific step. |
| Tool call | A single invocation by an AI of an external function, API, or interface. The atomic unit of an action trail. |
| Computer use | An AI operating a computer's actual interface (screen, cursor, keyboard) rather than a purpose-built API. |
| Model Context Protocol (MCP) | An open protocol for connecting AI systems to tools and data sources. In governance terms, every connection is an access grant that belongs in the agent's scope record. |
| Orchestration | Coordinating multiple agents or steps into one workflow. Governance must still attribute each action to the agent and the grant that produced it. |
| Sub-agent | An agent spawned by another agent to perform part of a task. Delegation records must cover authority passed downward, or scope widens silently. |
| Prompt injection | Content crafted so that an AI processing it treats it as instructions. At the action layer it becomes an authorization attack: injected text steering an agent into actions nobody approved. |
| Capability tier | A vendor-defined level of model capability and access, such as a generally available tier and a gated tier for approved users. |
| Trusted access | A vendor program granting vetted organizations access to model capabilities that are withheld from general availability. |
| Preparedness framework | A frontier lab's published system for evaluating and gating dangerous model capabilities before release. OpenAI's term; Anthropic's analogue is its Responsible Scaling Policy. |
| Critical capability | The highest capability designation in OpenAI's Preparedness Framework, first reached for cybersecurity by the Astra model in September 2026. |
Citing a term
Every entry has a stable anchor: link to /glossary#agent-identity, /glossary#execution-boundary, and so on. The full set is also published as machine-readable structured data on this page (DefinedTermSet), and the cite block below covers the page as a whole.
Cite this page
Bertram, M. (2026). DIG Glossary. Digital Information Governance® (DIG), Framework v1.1. https://digitalinformationgovernance.com/glossary
@misc{dig-glossary,
author = {Bertram, Matthew},
title = {DIG Glossary},
year = {2026},
howpublished = {Digital Information Governance (DIG), Framework v1.1},
url = {https://digitalinformationgovernance.com/glossary}
}