Kanonik
Menu

Glossary

General meanings and Kanonik context. A term explains an idea; it does not by itself establish a product capability.

Action authorization checks

General meaning: Checking whether an actor has permission to perform a particular action.

Adversarial evaluation

General meaning: Testing with challenging cases designed to expose errors and unsafe behavior.

Agent-led workflows

General meaning: Workflows in which AI uses tools to carry out several related steps, rather than only producing a text response.

With Kanonik: Instructions and tools help your AI prepare records, submit proposals and revise work after feedback. Your team can spend more time assessing the result and less time copying information between documents. The compliance structure around the agent's work stays in Kanonik.

Kanonik guide: Working with your AI through MCP

Answer sets

General meaning: A selected group of answer versions prepared for a particular response.

With Kanonik: An answer set groups selected answer versions for a particular questionnaire response. Membership and review state help keep a product-specific answer from becoming an unsupported company-wide statement.

Approved-content integrity

General meaning: Keeping an approval tied to the content that the reviewer examined.

Assurance format interoperability

General meaning: Exchanging assurance information without losing its scope, dates or qualifications.

Assurance work dashboard

General meaning: A view of assurance tasks and their recorded review states.

With Kanonik: The dashboard brings questionnaire and review work into a view of what is approved, unfinished, or waiting for an owner. Its counts describe recorded workflow states rather than an overall compliance score.

Bounded agent decision requests

General meaning: Requests that identify a specific action and its limits for review.

Bring your own model

General meaning: Bring your own model (BYOM) means using an AI model you choose instead of being limited to the assistant supplied with an application.

With Kanonik: Use the AI your team is comfortable with. Your AI does the reasoning over an MCP connection; Kanonik provides compliance instructions, a structured program record and a checking and review workflow. Kanonik hosts no general model and never asks for or stores your credentials. The model doing the preparation can change while the compliance program stays in Kanonik.

Kanonik guide: Bring your own model for compliance

Business continuity operations

General meaning: Preparing to maintain or recover important operations during disruption.

Changed-basis review

General meaning: Reviewing an earlier conclusion because information it relied on has changed.

With Kanonik: A recorded change or supersession can identify saved answers whose supporting basis needs another look. This concerns connected, supported change paths, not a guarantee that every update in every source is observed.

Constrained evidence and remediation plans

General meaning: Plans whose steps stay within defined permissions and approval boundaries.

Contract interpretation boundary

General meaning: The line between finding a clause in a contract and deciding what it legally means.

Controlled record changes

General meaning: Changes to authoritative records are subject to defined checks and authorization.

With Kanonik: Proposals stay separate from accepted records until they pass checking and a named person approves them. The verification and approval workflow gives a team a place to inspect a proposed change, question it and decide what to accept.

Kanonik guide: Checking AI work and keeping approval with people

Cross-company assurance network

General meaning: Repeated exchanges of assurance information among organizations.

Decision history

General meaning: The traceable relationship between a decision, its predecessors, supporting information and revisions.

With Kanonik: Kanonik keeps the recorded feedback, verification results and named approval behind a change, with its before-and-after state. Reviewers can see why work was sent back or accepted without reconstructing the exchange from email. The retained history does not include every intermediate draft or all AI reasoning.

Kanonik guide: One compliance record across models and frameworks

Defined rules and record structure

General meaning: Handling exact rules, such as required fields, in ordinary code, and leaving questions of judgment to people or AI.

With Kanonik: Defined checks sit alongside model-assisted review. Exact requirements such as required fields can be checked consistently, while interpretation still needs judgment.

Kanonik guide: Checking AI work and keeping approval with people

Delegated authority

General meaning: Give another actor limited authority with an explicit scope, purpose, expiration and means of revocation.

Demand-led integrations

General meaning: Connections selected to meet an identified workflow need.

Digitally signed records

General meaning: A digital signature lets someone check that particular data was signed using a particular key and has not changed since.

With Kanonik: Verification materials are supplied for checking the signed, covered history in an audit export.

Kanonik guide: Checking an audit record outside Kanonik

Directed evidence collection

General meaning: Request specific evidence to resolve a defined uncertainty instead of collecting everything available.

Enterprise private deployment

General meaning: Running software within an agreed private hosting boundary.

Enterprise risk management

General meaning: Managing risks across an organization rather than within one compliance workflow.

ESG operations

General meaning: Managing environmental, social and governance information and reporting.

Event history

General meaning: A record kept as a sequence of changes, from which the current state is calculated.

With Kanonik: Recorded changes stay available so the program can be examined beyond its latest state. That helps a team investigate how a record developed.

Kanonik guide: One compliance record across models and frameworks

Evidence freshness

General meaning: Whether evidence is recent enough and still applicable to the decision being made.

With Kanonik: Claim-staleness checks help identify recorded support that needs attention. Your team can review the affected answer rather than rely only on a calendar reminder to reconsider everything.

Kanonik guide: Keeping evidence-linked answers fit for reuse

Evidence origin

General meaning: Information about where data originated and how it was handled or transformed.

With Kanonik: Kanonik records where a piece of evidence came from, when it arrived and whether it has changed since, together with the proposals, checks and approvals that shaped the accepted record. That record does not show that the underlying fact is correct: a self-report can be wrong, and an approved record can go stale.

Kanonik guide: Keeping evidence-linked answers fit for reuse

Evidence request planning

General meaning: Choosing which evidence to request to resolve a particular uncertainty.

Evidence status

General meaning: Distinguishing available support from missing, outdated, inaccessible or conflicting information.

Evidence-based preflight

General meaning: Check the required conditions and supporting evidence before an action proceeds.

Evidence-linked claims

General meaning: A statement includes explicit references to the information supporting it.

With Kanonik: Saved claims connect to supporting records and versions. When your team prepares an answer, the basis can travel with the statement rather than remain in someone's memory or chat history.

Kanonik guide: Keeping evidence-linked answers fit for reuse

Execution receipts

General meaning: A record of what an executor actually did, linked to the authorized task and observed result.

Export fidelity checks

General meaning: Checking that shared output retains the intended content and qualifications.

Foresight

General meaning: Assessing a proposed change before applying it to the accepted record.

With Kanonik: Foresight compares a proposed change with your approved promises before you make it: adding a vendor or replacing one. For each promise it shows No conflict, Conflict, Needs information or Not applicable, with the facts it used, and it writes nothing to the accepted record. It is a check against recorded commitments, not an automatic legal verdict.

Kanonik guide: Reviewing change and keeping assurance current

Framework-independent record

General meaning: The underlying information model is not tied to one standard or assessment framework.

With Kanonik: Kanonik keeps program information separate from the framework used to view it, and every supported framework (SOC 2, ISO/IEC 27001, HIPAA, GDPR and 12 more) reads from the same record. When you add a second framework, Kanonik suggests how your existing controls map to it, and a person confirms each mapping.

Kanonik guide: One compliance record across models and frameworks

Full FAIR risk modeling

General meaning: Estimating financial risk using the Factor Analysis of Information Risk approach.

Generic policy-to-code compilation

General meaning: Translating policy requirements into executable rules.

Guided entry

General meaning: Questions that help someone supply the context needed for a bounded review.

Hash-chained history

General meaning: Each entry contains a cryptographic link to the preceding history, making changes detectable against a trusted reference.

With Kanonik: Audit exports let recipients check the integrity of covered history against a trusted reference.

Kanonik guide: Checking an audit record outside Kanonik

Human approval

General meaning: A person reviews or decides at specified points in an automated workflow.

With Kanonik: The review interface shows a proposed change and its checking results. A named reviewer can accept it or send it back with reasons. People spend less time on preparation, with a clear decision still made in the review process.

Kanonik guide: Checking AI work and keeping approval with people

Incident operations

General meaning: Coordinating the people and actions needed to respond to an incident.

Independent receipt consumer

General meaning: A reader that checks another party's assurance against its own acceptance requirements.

Instruction origin

General meaning: Knowing which instructions, and which version of them, an AI agent was given.

Irreversible action boundary

General meaning: The point beyond which a corrective action cannot readily be undone.

Large framework catalog

General meaning: A collection of standards or assessment frameworks available for use.

Least privilege

General meaning: Giving each person, account or agent only the access its task needs.

With Kanonik: Source-system access stays under customer control. Your AI uses the permissions your organization gives it without handing Kanonik a separate set of source-system credentials.

Kanonik guide: Working with your AI through MCP

Legacy tools

Established compliance and risk-management software, typically configured by the customer and connected to its systems through vendor connectors.

With Kanonik: Kanonik works through the customer's chosen AI and a structured program record, rather than a catalog of standing connectors into each of the customer's systems.

Compare approaches

Live assurance

General meaning: Keeping assurance conclusions under review as the supporting information changes.

With Kanonik: Saved claims connect to their evidence and decisions so changes to recorded support can bring an answer back for review. This keeps answers current between audits for changes that are recorded in Kanonik. Changes in systems that are not connected are not detected.

Kanonik guide: Reviewing change and keeping assurance current

Maintained external status

General meaning: Information about whether an earlier record remains acceptable, has expired or needs review.

Managed AI

General meaning: An AI assistant that the software vendor sets up and runs for you.

Model Context Protocol

General meaning: Model Context Protocol (MCP) is a standard connection that lets AI applications use business tools and information.

With Kanonik: MCP is the standard connection your AI client uses to reach Kanonik. Your AI works with our compliance tools and structured record, preparing proposals and responding to review feedback, without a separate connector for each system. You keep the AI environment your organization has chosen, and Kanonik gives its work a place to be checked, reviewed and retained.

Kanonik guide: Working with your AI through MCP

Multi-client operations and handover

General meaning: Managing work across several clients or products while keeping their responsibilities separate.

Offline verification

General meaning: Checking a file on your own machine without contacting the service that produced it.

With Kanonik: The audit export includes the event chain and verification materials. Recipients can recompute the sealed record's hash chain in their own browser, on their own machine, with no Kanonik account.

Kanonik guide: Checking an audit record outside Kanonik

One connected record

General meaning: A shared, consistently structured representation of information used across different interfaces and workflows.

With Kanonik: Controls, policies, risks, evidence references and claims sit in a shared structure. Your AI and the review interface work with that record, and framework views draw on it. Changing a model or looking at another framework need not mean recreating the underlying program.

Kanonik guide: One compliance record across models and frameworks

Owned obligation records

General meaning: Records of commitments, their source and the person responsible for them.

With Kanonik: A specific commitment is recorded with its source, scope, and responsible owner. A reviewer confirms qualifications and interpretation; recording an obligation does not automatically detect every event that might trigger it.

Pinned evidence versions

General meaning: References to the specific versions of information used for a decision.

With Kanonik: A claim can retain references to the particular supporting record versions used when it was prepared. This preserves the historical basis even when newer records exist, not the continued truth of that basis.

Policy gateway integration

General meaning: Exchange facts or decisions with other systems that evaluate or enforce policy.

Portable assurance

General meaning: An assurance record remains useful and inspectable outside the application that created it.

With Kanonik: Audit exports carry recorded history and local verification materials outside the workspace. A recipient can inspect that covered history without joining your team. A Proof Snapshot is free on both plans, with no cap.

Kanonik guide: Checking an audit record outside Kanonik

Product and data scope

General meaning: The service, product and data use to which a statement applies.

With Kanonik: Claims and their supporting basis identify the service, product, and data use they cover. A record for one product should not be treated as evidence for another without a scope review.

Questionnaire answer export

General meaning: Taking prepared answers out of a working system for sharing.

With Kanonik: Questionnaire export takes selected answers out of the working response for sharing. Review should reconcile the output with the intended approved versions and preserve unanswered or unresolved items.

Questionnaire skill

General meaning: Instructions that guide an AI through preparing questionnaire answers.

With Kanonik: A dedicated skill gives the AI instructions for preparing questionnaire work in Kanonik. It assists preparation and does not acquire the authority to approve its own answers.

Questionnaire workflow

General meaning: Organizing questions and reviewed responses for a customer or assessor.

With Kanonik: Customer questions and the answers being prepared for them are organized with review states and supporting records, so a draft response stays distinct from an accepted company answer.

Rechecking on change

General meaning: Revisiting an earlier check when information it relied on changes.

With Kanonik: When a record that a check relied on changes in Kanonik, the check is revisited. Kanonik does not watch unconnected systems, so a change that nobody records is not picked up.

Kanonik guide: Reviewing change and keeping assurance current

Recipient-specific exchange

General meaning: Share assurance information limited to a particular recipient, purpose and subject.

Rules and model review

General meaning: Checking a proposal twice: once against fixed rules and once by an AI model reading it in context.

With Kanonik: Every proposed change passes a two-tier check on the server before it is accepted: rules first, then an LLM review of the proposal in context. Your AI can only propose; it cannot skip the check or write to your record directly. Below a confidence threshold the change goes to a human review queue instead of being applied. Feedback from both tiers guides revisions, so the reviewer does not have to find every problem alone.

Kanonik guide: Checking AI work and keeping approval with people

Safe request retries

General meaning: Repeating a request without causing duplicate effects.

Saved answers

General meaning: Retaining answers so they can be reviewed and reused in later responses.

With Kanonik: Saved answer versions let a team reuse earlier work with its supporting basis. Reuse still needs review for the destination question and product rather than assuming similar wording means the same scope.

Scoped approvals

General meaning: Authorization applies to a defined action or item, rather than granting unrestricted permission.

With Kanonik: The work being reviewed stays separate from unrelated changes. Approvals use signed, short-lived, single-use tokens; a broader request needs its own decision.

Kanonik guide: Checking AI work and keeping approval with people

Scoped decision receipt

General meaning: A record of a decision together with its scope and supporting information.

Separation of duties

General meaning: Dividing a sensitive task so that no single person controls all of it, for example by having one person propose a change and another approve it.

With Kanonik: Separation of duties is recommended: one person prepares a change and another approves it. On a single-user workspace one person may approve their own AI's proposal by recording an exception, which is sealed into the record with the approval.

Kanonik guide: Checking AI work and keeping approval with people

Tenant isolation checks

General meaning: Keeping one customer's data and operations separate from another's.

Two-date history

General meaning: A history that keeps two dates for each fact: when it applied and when it was recorded.

With Kanonik: Historical questions about when a fact applied are distinguished from when it was recorded. Those dates can matter when explaining a past decision.

Kanonik guide: One compliance record across models and frameworks