Terms appendix
Document: LK-MAN-EN-05 · Version: 0.1
Last updated: 2026-07-18 · Status: draft / requires product review
Alphabetical index
A · C · D · E · F · I · M · O · P · R · S · T · U · W
<a id="a"></a>
A
Administrator (Admin): role that can manage most organization resources and settings without Owner-only authority.
Alert: event produced by a condition or change that may require attention.
API: programming interface for system integrations. Use it with keys, scopes, and least privilege.
ASM (Attack Surface Management): continuous discovery and assessment of exposed assets and services. ASM Plus expands depth and capacity.
Asset: domain, service, identity, brand, or other item within authorized scope.
<a id="c"></a>
C
Case: tracking unit that groups work, owners, states, findings, and remediation evidence.
Certificate Transparency (CT): public certificate logs that support discovery of names and certificates associated with domains.
Confidence: estimate of certainty for an observation; evaluate it alongside evidence and coverage.
Controller: entity that determines the purposes and means of personal-data processing.
Coverage: proportion or scope of assets and checks effectively observed.
<a id="d"></a>
D
Deduplication: controlled grouping or suppression of repeated events within a window.
DKIM: cryptographic email signature used by receivers to validate the signing domain and message integrity.
DMARC: email policy and reporting mechanism based on SPF/DKIM alignment for a domain.
DTO: response structure that models and limits fields exposed through an API.
<a id="e"></a>
E
Entitlement: effective capability or limit resulting from a plan and applicable overrides.
Evidence: technical data supporting an observation. It may be sensitive and requires controlled access and retention.
Export: data package supplied to an authorized person or organization; it must never include internal secrets.
<a id="f"></a>
F
Finding: normalized condition observed on an asset, including state, severity, source, and evidence.
<a id="i"></a>
I
Identity Leak: exposure or finding related to a monitored identity. Processing requires particular minimization and restricted access.
Idempotency key: identifier used to prevent the same event or request from being processed more than once.
Incident: material interruption or degradation that can be managed through uptime and communicated on a status page.
<a id="m"></a>
M
Member: read and authorized-use role without general administrative privileges.
MFA: multi-factor authentication; adds a second factor to a password.
Multi-tenant: architecture in which several organizations share a service while data and permissions remain logically isolated.
<a id="o"></a>
O
Organization: tenant grouping members, plan, domains, settings, and operational data.
Override: temporary or specific exception that changes a plan capability or limit for one organization.
Owner: role with maximum authority over the organization, owners, and billing.
<a id="p"></a>
P
Processor/agent: entity that processes personal data on behalf of and under instructions from a controller.
<a id="r"></a>
R
RBAC: role-based access control.
Recheck: a new check requested after remediation or another change.
Retention: period for keeping a data class before deletion, anonymization, or archival under the applicable rule.
Risk acceptance: authorized decision not to remediate a risk temporarily or permanently, with reason, approver, and defined review.
Risk score: aggregate prioritization indicator; it does not replace evidence or analysis.
RUA: usually XML-based DMARC aggregate report summarizing senders and authentication results.
<a id="s"></a>
S
Scope: specific permission granted to a key or integration.
Severity: estimate of a condition's technical impact; combine it with exposure and context.
Snapshot: representation of state at a point in time, used to compare changes or produce a consistent report.
SPF: DNS policy declaring servers authorized to send email for a domain.
Status page: controlled public view communicating selected availability, components, and incidents.
<a id="t"></a>
T
Takedown: process to request removal or disabling of content or infrastructure; it requires evidence and legal/procedural review.
Tenant: see Organization.
TLS: cryptographic protocol used to protect connections and authenticate endpoints with certificates.
<a id="u"></a>
U
Uptime: availability and response measurement through periodic service checks.
<a id="w"></a>
W
Webhook: HTTP event delivery to a configured endpoint. Protect it and validate authenticity.
Change control: v0.1 — initial glossary, 2026-07-18.