Reference
Glossary
The vocabulary of Flexday AI, from Agent to Workspace, in plain language.
Written for
- Everyone
Last reviewed
Every term used across this documentation, defined once, in plain language. Where a term has its own page, the definition links to it.
Tip
Terms are grouped by first letter. A few words mean something specific in Flexday AI that differs from everyday use (for example Tenant, Template and Enabled); those entries say so.
A
- Access log
- The record a File Store keeps of reads: every download and preview, every direct link when it is issued, and listings, with who read it and through what (the Studio, an app, a Flow or an Agent). The audit trail records changes; the access log records reads. See File safety.
- Access mode
- How an Agent applies audience tags when it searches a Doc Base or reads a File Store on behalf of the person it is talking to.
- Access tags
- The audience tags a person holds on an Identity. An admin grants them on the Identity's Members tab, an email invitation can carry them for someone who has not signed in yet, and the Identity's On sign-in and For existing members Flows can set them. They decide which documents and files that person may see. See Identity.
- Action
- One typed operation that a business application offers through an Integration, such as Create ticket or Find user in ServiceNow. Each action has its own form and returns the same result shape.
- Adapter
- The part of the platform that connects it to one kind of outside service, such as a sign-in provider, an AI model provider, object storage, a vector store, a secret store, a malware scanner, a messaging channel or a business application, behind one common interface. Adding a provider changes an adapter and configuration, not the rest of the platform. Where a deployment chooses between adapters, for example for object storage, the one it uses is called its driver. See Extensibility.
- Admin Console
- The Flexday AI staff operations console: workspaces, plans and quotas, health, jobs, audit and support access. Customers never need it. A support session in a workspace is possible only while that workspace's Support access setting is on, which it is by default. See Platform surfaces.
- Agent
- A conversational AI assistant you configure rather than program: instructions, a model, an explicit list of tools, guardrails, budgets and memory. See Agent.
- Agent analytics
- Measured, real-world use of an Agent: conversation volumes, people, tools used, sources cited, guardrail events and feedback. Playground and evaluation traffic is excluded, so the numbers reflect real use.
- Agentic loop
- The cycle an Agent or the Builder runs: the model reads the situation, calls a tool, reads the result, and repeats until it can answer.
- App kit
- The shared set of helpers (running queries and actions, rendering charts and tables, formatting dates and money) that every new generated app starts with, so no app has to rebuild them.
- Apps
- The surface where end users use what was built: each deployed LaunchPad is a website on the apps origin that reads its data only through the Flex Gateway. See Platform surfaces.
- Apps origin
- The web address generated apps are served from. Where the deployment gives out workspace addresses,
each workspace's apps are on its own address,
<workspace>.apps.<domain>; the sharedapps.<domain>address keeps working either way. See Addresses and domains. - Attestation
- An independent auditor's report on how a company operates its controls, for example under SOC 2. Flexday's attestations are documents to request during due diligence; these docs do not state them.
- Audience
- A tag on a document or file (for example
financeorhr) that is matched against the tags a person holds. A match grants visibility; an item with no tags is visible to anyone allowed to search. Audiences decide who may retrieve, cite, preview or download each item. - Audit trail
- The workspace's record of changes to its Solutions, resources, settings and access, written by the database and credited to the person who made each change (or to System, for scheduled work). It refuses updates and deletes; the only exceptions are two operator-run tasks: purging a whole workspace, and compacting old entries for the Builder's saved conversation into a digest (size, SHA-256 fingerprint and message count) after a backup that still holds the originals. A new change to that conversation is recorded as the same digest. Dataset rows, runs and conversations are kept in records of their own. A separate access log answers "who downloaded this file".
B
- Blocked topic
- A subject an Agent must not discuss, checked before its model sees a message: a keyword by exact match, or a topic described in words by one fast classification. Each is set to Block (refuse) or Flag (continue and record), and a described topic can also start a Flow.
- Brief
- The pinned set of instructions for a Solution that the Builder reads on every turn and never summarises away. It is how you tell the Builder "always do X" once.
- Bot
- One published Agent made available in Microsoft Teams, so people can talk to it where they already work. See Bot.
- Bot Framework
- Microsoft's service that carries messages between Microsoft Teams and a bot. A Flexday AI Bot accepts a message only when the request is signed by Microsoft's service, and sends its replies back through the same service.
- Budget
- A per-turn limit on what an Agent may spend (tool calls, output tokens and elapsed time), set under platform ceilings and checked by the engine between steps, plus a limit on turns per conversation. At 80% the Agent is told to wrap up; at 100% it gets no more tools and gives a short final answer.
- Build log
- The line-by-line narration of what the Builder is doing, one line per action, shown under the chat.
- Builder
- The AI engine that turns a plain-English request into a working Solution and keeps refining it as you chat. See The Builder.
- Bundle
- The single file a Solution export produces. It carries every resource the Solution owns and the data you choose, but never credentials or secret values. See Solution export and import.
C
- Card
- A document or a form shown inside a conversation, in Studio or in a generated app. See Interactive cards.
- Catalog (global catalog)
- The set of Templates that Flexday AI publishes for every workspace. Each catalog release is a frozen, read-only snapshot. See Template.
- Chunk
- A passage of a document that search works on: about 2,000 characters long, overlapping its neighbours, and cut at a paragraph, line or sentence break. Each passage remembers its document and, where one was detected, its section heading.
- Citation
- A reference, attached to an Agent's answer, to the retrieved documents the answer's wording matches. Fixed rules decide it, not the model, and a refusal cites nothing.
- Claim
- One piece of information about a person inside a sign-in token, such as their identifier, email address, name or groups. An Identity's claim mapping says which claims identify the person, and its rules can require a claim.
- Claim mapping
- The rules that say which parts of a signed-in person's token identify them (subject, email, name, groups). Set per Identity.
- Clone
- A new Solution created from a Template. It is an independent copy with no link back to its source.
- Connection
- Stored credentials for an outside system (an API key, a bearer token, a username and password, OAuth client credentials or an SMTP mail login). They are encrypted at rest, never shown again after saving, and decrypted only when a Flow step, an Agent tool or a test send uses them. See Connection.
- Consent (Teams)
- Whether a Bot may message a Teams conversation first. A conversation starts with implied consent once the Bot is installed or messaged there. In a one-to-one chat the person can send STOP (or UNSUBSCRIBE) to turn outreach off and START (or RESUME) to turn it back on, and uninstalling turns it off. Consent never affects the Bot's replies.
D
- Data Portrait
- An optional enrichment of a Fact Base in two stages: a Profile of measured facts about the data, and an Ontology that describes the business meaning. See Data Portrait.
- Data residency
- Where data is stored and processed. A Flexday AI deployment keeps its stores in one cloud region; calls to outside services, such as an AI model provider, go where that service runs. See Data protection and privacy.
- Defence in depth
- Several independent controls in sequence, so that one failing does not expose data. In Flexday AI: the edge, sign-in, roles and grants, database isolation, resource rules and encryption. See Security overview.
- Definition
- The meaning layer of a Fact Base: its tables, keys, relationships, constraints and plain-language descriptions. Everything downstream reads the definition.
- Delegation
- An Agent handing one task to a specialist Agent, which runs one isolated turn and returns only its answer. The original Agent stays in charge of the conversation.
- Deploy
- Making a LaunchPad's Draft live: it is copied to a new, immutable, numbered version that end users see.
- Discrepancy
- A finding in a Data Portrait's profile where the measured data disagrees with the Fact Base's definition, such as a column declared required that has empty values, or a list of allowed values that misses some the data holds. On the portrait's Fix Discrepancies page you accept the ones you agree with, and they are written into the definition.
- Doc Base
- A searchable collection of documents (policies, manuals, runbooks) with keyword, semantic and hybrid search and citations. See Doc Base.
- Draft
- The editable working copy of a resource: a LaunchPad's files, a Flow's graph, an Agent's definition. Drafts never run in production; published or deployed versions do.
- Driver
- The adapter a deployment is set to use for an outside service, for example Amazon S3 or Azure Blob Storage for object storage.
- Due diligence
- The checks a buying organisation makes before adopting a supplier: reading the documentation, requesting the supplier's own documents, and testing the product. See Evaluating Flexday AI.
- Duplicate-prevention field
- A unique field named on a ServiceNow Connection so that, if a create request is interrupted, the step can check whether the record was created and either use it or safely try again, instead of stopping for a person to confirm.
- Durable job
- Work that runs on the background worker instead of inside a web request, with a lasting record in the database: Builder turns, Flow runs, document indexing, Agent turns, exports and imports among them. It survives a closed browser and a restarted service, and sends a heartbeat while it runs. See Background jobs and resilience.
- Dynamic identity resolution
- A Flex Gateway mode in which each caller is matched to the Identity for their own sign-in provider, so one gateway can serve people from many organisations.
E
- Editor
- See Solution roles.
- Embedding
- A numeric representation of the meaning of a passage of text, used for semantic search.
- Enabled
- For a Flow, whether it may start from its own trigger (a schedule, an event or an incoming webhook) and whether an Identity may run it to set access tags. It is separate from being published and is off by default. For an Agent, whether it serves real conversations in apps, the API, Teams and other Agents; it can still be tested in the Studio, and it is on by default.
- End user
- Someone who uses what was built (a generated app, a public API, a Teams Bot), as opposed to a builder who creates it in Studio. End users never need a Studio account.
- Endpoint
- A named operation on a Flex Gateway. There are four kinds: query (run a saved query), flow (start a published Flow), agent (talk to a published Agent) and file (upload and download).
- Evaluation
- A set of golden test cases with assertions, run against an Agent's real engine. Publishing can require the latest evaluation to pass.
- Export
- Packaging a whole Solution into a bundle file. See Bundle.
F
- Fact Base
- A queryable dataset: a live PostgreSQL schema of its own, a business definition, sample data and saved queries. It is the data source that apps, Flows and Agents read from. See Fact Base.
- File handle
- The small reference a file becomes when it moves between steps or into a conversation. It grants nothing by itself; access is re-checked every time it is used.
- File reference
- Another name for a file handle.
- File Store
- Governed file storage: folders, immutable versions, audience tags, retention and quota, plus malware scanning where the deployment has a scanner switched on. See File Store.
- Finish gate
- The automatic checks the Builder runs when it declares a build finished: its read queries are wired to its gateway, calls that point at nothing are reported (a check the Builder may set aside when it does not apply), anything not really built yet is declared as a placeholder, and your "Done when" criteria are checked and shown to you as met or not met.
- Flex Gateway
- A Solution's public API, served on the apps address. Its endpoints run saved queries, Flows, Agents and file operations. Callers are checked against the Identity attached to the gateway, and each endpoint can follow that rule, require sign-in or be open to anonymous callers. See Flex Gateway.
- Flow
- A visual workflow: triggers, conditions, loops, data steps, HTTP calls, email, files, forms, AI steps and business-application steps, run as a durable job and recorded step by step. See Flow.
- Form
- A card that collects validated, structured input from a person, inside a conversation or a Flow.
G
- Global catalog
- See Catalog (global catalog).
- Global search
- The Studio search box that finds Solutions, resources, people and Templates, showing only what you can already open.
- Grant
- One capability an Agent is explicitly allowed to use, such as querying a particular Fact Base or running a particular Flow. The list of grants, not the prompt, is the security boundary.
- Grounding
- An Agent setting that tells it to search your own documents and data before stating a fact about your business, to say so when the answer is not there, and to label anything else as general help. If it answers without searching, it is reminded once.
- Guardrails
- Automatic checks around an Agent's model. Before it: a message-rate limit, a length limit, blocked patterns, personal-data handling (warn, mask or block; off by default), blocked topics and optional moderation. After it: masking of personal data in the reply, when that handling is set to mask or block. A blocked message never reaches the model.
H
- Heartbeat
- The signal a running background job sends every 15 seconds to show it is still alive. A job whose heartbeat has been silent for 90 seconds is failed by a scheduled sweep, so no work waits forever.
- Host family
- One of the kinds of public address a deployment serves: the Studio, the API and the shared apps address, plus the Admin Console and each workspace's own apps address where the deployment is set up for them.
- Hybrid search
- Search that runs a keyword search and a meaning-based (semantic) search together and fuses the two result lists by rank. It keeps answering from keywords if the semantic half is briefly unavailable.
I
- Idempotency key
- A key built from the run, the step, the loop iteration and a fingerprint of what is sent, claimed before an outside effect such as an email, an API write or a file send, so a retried step does not normally repeat it. In rare failures a duplicate is still possible.
- Identity
- The named sign-in or credential set that a Flex Gateway checks callers against. There are nine mechanisms (for example OpenID Connect, SAML federation, API keys, signed requests, client certificates) and thirty provider presets. See Identity.
- Import
- Creating a brand-new Solution from an exported bundle, never merging into or overwriting an existing one. Importing a single Agent or Flow adds it as a new draft to a Solution you choose, unless that Solution already has one with the same name.
- In doubt
- The state of a write to an outside application that was cut off and could not be checked. It is never sent a second time; a person checks the application instead.
- Integration
- A Flow step that performs one typed action in a business application your company already uses, such as raising a ServiceNow incident, through a saved Connection. See Integration.
- Intent
- A named purpose you define on an Agent's Intents page (for example "billing questions") that is added to its prompt to help it route a request. Intents guide; grants decide.
- Interactive card
- See Card.
- Issuer
- The identity provider that issued a sign-in token, named inside the token by its address. Flexday AI accepts a token only from an issuer it expects: the provider set up for the workspace, for the Studio, and the Identity's provider, for a gateway.
L
- LaunchPad
- A web application generated for a Solution. It has a Draft you can change safely, numbered immutable versions and one live version, and it reads data only through the Flex Gateway. See LaunchPad.
- Lint
- The automatic checks run before an Agent or Flow is published. Errors block publishing; warnings are advisory and never block.
M
- Managed File Store
- A File Store that Flexday AI creates and owns on behalf of another resource, for example to hold a Doc Base's uploads, a Fact Base's sample data or the Builder's chat attachments. It cannot be renamed or deleted on its own.
- Manager
- See Solution roles.
- Member impersonation
- A Studio feature, switched on per Identity, that lets a workspace owner or admin test a live app as a real member of that Identity. It needs a reason, expires within an hour, can be revoked, and emails the member when their address is known.
- Model
- The AI model that does the reasoning. Flexday AI offers Anthropic Claude models and, where configured, Azure AI Foundry GPT models, chosen per task. Workspace and resource settings offer only Claude models for the Builder.
O
- Open workspace
- The default Solution access setting: every member sees every Solution as an Editor and every viewer as a Viewer, and a grant can raise a member's access. See Restricted workspace.
- Ontology
- The second stage of a Data Portrait: an AI-written business description of the data's domain, concepts, lifecycles, metrics and assumptions, which a person can review and sign off.
P
- Pinned gateway
- The Flex Gateway a LaunchPad is linked to and resolves its endpoints against, falling back to the Solution's first enabled gateway. A Solution can have several gateways, though the Builder normally reuses one.
- Playground
- The Studio area where you chat with an Agent before and after publishing it.
- Present
- A File Store grant permission that lets an Agent show a document to the person as a card. Reading or listing files does not include it: it must be granted on its own. See Interactive cards.
- Preview as
- Testing an Agent, in the Playground or a live app's chat, as if you held certain audience tags, to see which documents and files that audience could reach. While previewing, Agent tools that would send, write or run something are refused.
- Profile
- The first stage of a Data Portrait: measured facts about the live data (empty values, distinct values, ranges, averages and percentiles), gathered by AI through read-only queries it is told to keep to aggregates, each returning at most 20 rows.
- Proof of concept
- A short, time-boxed trial of Flexday AI on one real process, measured against success criteria agreed beforehand. See Running a proof of concept.
- Provision
- Creating a Fact Base's live database schema from its verified definition, in one all-or-nothing step.
- Publish
- Turning a draft into a new numbered version that people and systems use. Flows, Agents and Templates are published or released, apps are deployed, Fact Bases provisioned and Data Portraits signed off.
- Published version
- An immutable, numbered snapshot of a Flow or Agent. Live traffic (apps, schedules, webhooks, the API and Teams) always uses a published version; Studio test runs and Playground chats can use the draft.
Q
- Quarantine
- The state of a file whose malware scan is pending, infected or failed. It is never served, downloaded or previewed, and an infected or failed file is never indexed; a Doc Base can index a directly uploaded document while its scan is still pending.
- Query (saved query)
- A named SQL statement with declared parameters, saved on a Fact Base. When the Builder wires an app, its read queries become gateway endpoints automatically; queries that change data are exposed only on purpose.
R
- Release
- A new version of a Template (major, minor or patch). Solutions cloned afterwards receive the change; existing clones are never altered.
- Resource
- One building block inside a Solution: a LaunchPad, Fact Base, Data Portrait, Doc Base, File Store, Flow, Agent, Flex Gateway, Identity, Connection, Variable or Bot. Each belongs to one Solution or Template and can reference only what is inside the same one.
- Restricted workspace
- A Solution access setting under which people see only the Solutions they hold a grant on; the database hides the rest. The platform's operators set it per workspace; there is no Studio switch for it.
- Retention
- How long something is kept before the platform removes it. A File Store can set a retention window for deleted files and a limit on earlier versions; neither is set by default. The file access log and stored form submissions are kept for the workspace's retention window (30 days by default), which is also the grace period before an offboarded workspace is purged.
- Role
- A level of access. A person holds one workspace role and, on a Solution, possibly a Solution role; a query runs under a Fact Base role, described next.
- Role (Fact Base role)
- The database role a query runs under. Every Fact Base has a reader and a writer role, and you can add custom roles with a grant matrix.
- Row policy
- A rule on a Fact Base table that limits which rows a query can see or change: for example only the signed-in person's own rows, rows tagged for their audience, or rows matching a custom condition.
- Row-level security
- A database feature that filters every read and write by a policy. Flexday AI uses PostgreSQL row-level security to keep each workspace's Solutions and their contents apart, and to hide unshared Solutions in a Restricted workspace. A request with no workspace scope sees none of those records.
- Run
- One execution of a Flow, from its trigger to its result, run as a durable job and recorded step by step: each step's input, output, status and timing. A live run keeps the published version and the Variable values it started with.
- runQuery and runAction
- The two helpers a generated app's widgets use:
runQueryruns a saved query, andrunActionruns a Flow exposed on the gateway, or shows a "coming soon" notice if none is wired. Apps use the runtime SDK directly for chat, files and sign-in. - Runtime SDK
- The small script present in every page of a generated app (
window.Flexday) that calls endpoints, signs people in and talks to Agents. It never names a server address.
S
- SAML
- Security Assertion Markup Language, a single sign-on standard many corporate identity providers support. Flexday AI accepts SAML sign-in through a user pool that federates with your provider, both for the Studio and for the apps you build.
- Saved query
- See Query (saved query).
- Scan verdict
- The result of checking a file for malware: pending, clean, skipped (not scanned), infected or failed. Only a clean or skipped file is served.
- Secret
- A Variable type for a token or key. It is sealed when saved, never shown again, usable only in HTTP request headers and application action inputs, and never readable by an Agent.
- Secret storage
- Where a deployment seals Secret Variables: Flexday AI's own encrypted storage, under the workspace's own key, by default, or AWS Secrets Manager or Azure Key Vault where the deployment is set to use one. It is set by the deployment, not by a workspace.
- Servable
- Whether a file may be handed out right now: its upload is complete and verified, and its scan verdict allows it. It is checked each time the file is read.
- Session
- One conversation with an Agent. It keeps the Variable values it started with and, except for a Playground chat on the draft, the Agent version it started with.
- Snapshot (configuration snapshot)
- The set of Variable values captured when a Flow run or conversation starts. A later edit reaches the next run, never the one already running (secrets excepted, which are read fresh).
- Solution
- The container for everything built for one purpose: its apps, data, documents, files, automations, agents, API, credentials and settings. Everything inside references only what is inside. See Solution.
- Solution roles
- The three levels of access a person can hold on one Solution: Viewer (see it), Editor (change it) and Manager (also share it). A Solution role never lifts anyone past their workspace role, so a workspace Viewer stays a Viewer. In an Open workspace a role can raise a member's default access but not lower it; in a Restricted workspace people see only the Solutions they hold a role on.
- Studio
- The Flexday AI web application where people build, run and govern Solutions. See Platform surfaces.
- Support access
- The workspace setting that allows Flexday staff to open a support session in the workspace. It is on by default; an owner can switch it off, which refuses new sessions and ends live ones. A session is read-only unless staff choose write access when starting it, lasts at most an hour, and is recorded against the staff member.
T
- Template
- A reusable copy of a Solution that people start new Solutions from. Using one copies its resources in a background job, with no AI build; the copies arrive as drafts to review and publish, with credentials, and the app's links to Flows, Agents and file uploads, to set up again. See Template.
- Tenant
- The technical word for a Workspace. The documentation uses "workspace".
- Tenant isolation
- Keeping each customer's data invisible to every other customer on shared infrastructure. In Flexday AI it is enforced by PostgreSQL row-level security and by workspace-prefixed storage keys. See Data isolation.
- Tool
- A capability an Agent can call during a turn, such as searching a Doc Base or running a Flow. Every tool that reaches your data, files, Flows, other Agents or outside systems comes from a grant; a few built-in conversation tools (asking a question, showing a form, returning a structured answer) come from the Agent's own settings.
- Trigger
- The first step of every Flow, saying how it starts: Manual, Schedule, Webhook or Event. A published Flow can also be run directly by an app's button, an API call, an Agent, another Flow, or an Identity when someone signs in.
- Turn
- One message and everything done in response to it. Builder turns and Agent conversation turns each run as a durable background job; a turn an Agent takes for a Flow step, another Agent or an evaluation runs inside that caller's work.
V
- Variable
- A named, typed setting a Solution or Template owns, such as
SUPPORT_EMAIL, read by key from Flows and Agents. Types are Text, Number, True / false, JSON and Secret. See Variable. - Version
- An immutable, numbered snapshot of a resource: a deployed app version, a provisioned Fact Base, a published Flow or Agent, a Template release.
- Viewer
- See Solution roles and Workspace roles.
W
- Webhook
- A signed HTTP request from an outside system that starts a published Flow. Each Flow's webhook has an unguessable address and a signature over the body, is rate-limited per sender, and ignores a repeat that carries the same idempotency key.
- Widget
- One self-contained part of a generated app page (a chart, a table, a form). Apps built with the current layout keep each widget in its own file; older apps keep their page code together.
- Workspace
- A customer's own space in Flexday AI: its members, roles, settings, Solutions and Templates. Workspaces are kept apart from each other; the one exception is the global catalog, whose Templates any workspace can copy. See Workspace.
- Workspace roles
- The level of access a person holds across a workspace: Owner, Admin, Member or Viewer. Owners and admins manage members, settings and access; they can always reach every Solution.