Skip to content
AWP v1alpha1 (draft)
Draft - v1alpha1. Fields and semantics may change before v1beta1.

Glossary (v1alpha1)

Status: draft / alpha, non-normative. Normative definitions are in the specification; this glossary summarizes them.

TermDefinition
A2AAgent2Agent protocol for communication between agents. AWP references A2A endpoints as remote agents.
ActionAn operation with an effect outside the model: a tool call, a command step or a message to a remote agent. Model invocations are not actions.
Action groupA named set of action identifiers declared in spec.actionGroups, usable wherever an action identifier is accepted.
Action identifierDotted name of an action, for example github.search_code, shell.execute, a2a.security-agent.send.
ActorWho performs or triggers something in an execution: agent, human, runtime or system.
AgentA configured use of a model with instructions, tools, permissions and limits. Also the kind Agent for reusable agent definitions.
Agent referenceAn entry in spec.agents that points to a published Agent manifest by name, exact version and optional digest.
ApprovalA decision by an authenticated human that allows a gated action or approval step to proceed.
Audit eventA structured record of something that happened in an execution, with a standard envelope and type (workflow.*, agent.*, tool.*, policy.*, approval.*, artifact.*).
BudgetLimits on cost, steps, duration, tokens, tool calls, retries and concurrency.
Conformance profileA named set of requirements a runtime can implement: core, governance, audit, security, mcp, a2a.
Conformance statementA document published by a runtime declaring the API version and profiles it conforms to and its limitations.
Data classOne of public, internal, confidential, personal, restricted, sensitive, secret; an organizational vocabulary, not a legal definition.
DeclassificationDeclaring an output with a lower data class than the data it was derived from; always recorded.
Decision recordA structured explanation of a consequential action in terms of evidence and policy checks. Not chain-of-thought.
Digest<algorithm>:<hex> hash, for manifests computed over the JCS serialization without integrity, signature and provenance fields.
EnvironmentThe organizational context of an execution (for example development, staging, production) with its own autonomy level.
ExecutionOne run of a workflow, identified by an execution identifier (awp-exec-<ULID>).
Expression${{ ... }} reference to an input, a step output or execution facts in expression-enabled fields.
Fail closedRejecting or denying when something cannot be verified or determined, instead of proceeding.
KindThe type of a manifest: Workflow, Agent or Policy.
ManifestAn AWP document with apiVersion, kind, metadata and spec.
MCPModel Context Protocol for connecting agents to tools and resources. AWP references MCP servers as tool sources.
PermissionsThe permissions object that grants or denies actions and restricts network, filesystem, secrets and environments. Permissions grant; policies only restrict.
PolicyA rule set that denies operations or requires approval under conditions. Also the kind Policy.
Policy shorthandWell-known policy settings in spec.policies (git, pullRequest, merge, production) that expand to deny rules.
Remote agentAn agent run by another system and reached through A2A.
Reproducibility recordA record produced at the end of an execution that identifies the workflow, agents, models, prompts, tools, images, policies, inputs and artifacts it used.
Risk levellow, medium, high or critical: an organizational risk declaration with recommended default treatments.
RuntimeSoftware that validates and executes manifests and enforces their rules.
Secret referencesecretRef: <name>: a pointer to a secret declared in spec.secrets. Secret values never appear in manifests.
Separation of dutiesRules that prevent the same human from both initiating or performing and approving an action.
StepA node of the workflow graph: agent, command or approval.
Tool sourceAn entry in an agent’s tools: an MCP server (type: mcp) or a runtime built-in (type: builtin).
Well-known actionReserved action identifiers with defined meaning, for example git.merge, production.deploy, external.communication.
WorkflowThe kind Workflow: agents, tools, steps, limits and governance of a unit of agentic work.