Glossary¶
The vocabulary NullRun uses, in one place. Each entry says what the term means and links to the page that goes deeper on it.
Enforcement¶
Gate
: The check that runs before a supported tool or model call executes.
It returns one of three decisions — allow, block, or
require_approval — and it is the only thing standing between an
agent's intent and its side effects. See
Circuit breaker.
Policy
: A rule attached to your organization or to a single workflow. Each
policy answers one enforcement question, and the applicable ones
are aggregated most-restrictive-wins across scopes. The four types
are BudgetLimit, RateLimit, ToolBlock, and
LoopDetection. See Policies.
ToolBlock
: The policy type that decides which tools an agent may call. Its
patterns are glob matches over canonical tool names, unioned across
every scope that applies. It is always hard: it fails closed on
a transport error regardless of the budget's
enforcement_mode. See Tool policies.
Sensitive tool
: A tool that should never run without a human paying attention —
sending mail, moving money, deleting a record. NullRun does not
ship a built-in list of these; you express them as ToolBlock
patterns. See Sensitive tools.
Fail-closed / fail-open
: What the gate does when it cannot reach the policy engine.
ToolBlock and aggregate rate limiting fail closed (the call is
refused) because the policy is the authoritative gate; per-key rate
limits and budget checks fail open because the budget
enforcement layer behind them is the real backstop. See
Policies.
Circuit breaker : The SDK-side guard that short-circuits gate calls after repeated infrastructure failures, so an unreachable gateway does not turn into a hang. It opens on transport errors and closes again after a cooldown. See Circuit breaker.
Cost¶
Budget : The maximum a workflow may spend in one billing period. Amounts are in cents. See Budgets.
Enforcement mode
: Whether a budget blocks hard or soft. Hard refuses the call once
the projected cost exceeds what is left. Soft allows a bounded
overdraft, but only when all three hold: the policy is set to
Soft, an active chain_id exists, and the cost stays inside both
max_overdraft_cents and max_overdraft_percent. The chain
returns to Hard mode once the cap is exhausted. See
Budgets.
Reservation : The amount a workflow commits at gate time, before the call runs. The actual cost is consumed against it afterwards, so the reserve / consume invariant keeps a single call from being implicitly re-reserved. See Budgets.
Runtime¶
Workflow : One agent you run. Each workflow carries its own budget, its own API keys, and its own policies, and its cost binds to it as a logical unit rather than to a single session. See Workflow context.
Chain
: A group of workflows that run as one logical unit under a shared
chain context, so a kill or an overrun surfaces across the rest. A
chain that exceeds its max duration is rejected by the gate with
CHAIN_MAX_DURATION_EXCEEDED. See
Workflow context.
Action : One concrete operation an agent wants to perform — a tool call or a model call, with its arguments. The unit the gate evaluates and the unit an approval is bound to. See Human approval.
Action source : The gateway's name for one MCP server (or built-in provider) the SDK has talked to. One row in Governance → Action Sources. See MCP servers.
Trace : Everything that happened during one run of your agent: every LLM call, every tool call, and how long each took. See Tracing.
Span : One node in a trace — a single LLM or tool call, with its timing and its correlation ids. Spans nest, and a parent trace id propagates across a workflow so the dashboard renders a true waterfall. See Tracing.
Control¶
Approval
: A human decision that lets one specific action run. The grant is
bound to the exact action payload through a SHA-256
action_digest; if the payload drifts, the grant is refused. See
Human approval.
action_digest : The SHA-256 hash that binds an approval to the action it approves. A digest mismatch after approval produces a hard block rather than letting the substituted action through. See Human approval.
Control plane : The WebSocket channel between the dashboard and your running agent. It is what makes Kill, Pause, and Resume take effect immediately rather than on the next gate call. See Control plane.
Kill
: The control-plane signal that stops a workflow. It arrives as
WorkflowKilledInterrupt, which inherits from NullRunError
directly — it is not a policy decision, so
except NullRunDecision does not catch it. See
Error handling.
Pause
: The control-plane signal that suspends a workflow. It surfaces as
WorkflowPausedException carrying a resume_after, and maps to
HTTP 503 with a Retry-After header. See
Error handling.