Definitions
Glossary
NHIM, runtime enforcement, deploy eval, and evidence terms — auto-linked across docs and the control plane.
Start here
- Deploy & evalDeploy eval tracks
Blekline platform eval is organized in three tracks: Track 01 (Kubernetes fleet), Track 02 (Docker sidecar), Track 03 (MCP integrator). Each track maps to a deployment hub checklist and evidence export path.
- Deploy & evalEval journey
The eval journey is Blekline's structured path for security architecture review — NHIM audit, sidecar or MCP wiring, runtime log review, and compliance export. It is evidence enablement, not certification.
- Runtime enforcementMCP proxy
The Blekline MCP proxy sits between an agent client and downstream MCP servers — evaluating tool calls against workspace policy before execution. It is the primary governance surface for Cursor, Claude Code, and Codex integrators.
- Evidence & auditMetadata-only audit
Metadata-only audit means default telemetry exports tool names, risk tiers, policy rule IDs, and lineage references — not prompt bodies or customer PII. SIEM, Slack, and compliance pack exports follow this contract unless explicitly opted in.
- Identity & NHIMNHIM (Non-Human Identity Management)
NHIM is Blekline's category for governing autonomous agents at the execution boundary — who the agent is, what tools may run, and whether session lineage permits action. It complements human IAM with stateful runtime enforcement.
- Runtime enforcementTrust Vault
Trust Vault is Blekline's stateful tokenization layer: sensitive values are replaced with cryptographic placeholders before LLM context, then re-hydrated in-cluster on approved tool calls. Placeholders use the BLW_VAULT_* format.
A
D
E
I
L
M
- Mandatory hopDeploy & eval
A mandatory hop requires agent traffic to pass through Blekline ingress (sidecar or MCP proxy) before reaching models, tools, or the public internet. Fleet benchmarks (B6) verify agents cannot bypass the hop.
- MCP proxyRuntime enforcement
The Blekline MCP proxy sits between an agent client and downstream MCP servers — evaluating tool calls against workspace policy before execution. It is the primary governance surface for Cursor, Claude Code, and Codex integrators.
- Metadata-only auditEvidence & audit
Metadata-only audit means default telemetry exports tool names, risk tiers, policy rule IDs, and lineage references — not prompt bodies or customer PII. SIEM, Slack, and compliance pack exports follow this contract unless explicitly opted in.
N
- NHIM (Non-Human Identity Management)Identity & NHIM
NHIM is Blekline's category for governing autonomous agents at the execution boundary — who the agent is, what tools may run, and whether session lineage permits action. It complements human IAM with stateful runtime enforcement.
- NHIM auditEvidence & audit
NHIM audit is a static Kubernetes cluster scan (`nhim-audit` CLI) that inventories agent workloads, egress paths, and sidecar coverage before Blekline deploy. Output JSON feeds the deployment hub posture upload.
- Non-Human Identity (NHI)Identity & NHIM
A Non-Human Identity (NHI) is a machine identity used by software agents, services, and automation — not a human user account. NHIs need runtime enforcement because static entitlements do not observe what agents actually do in production.
P
R
S
T
Z
16 terms indexed · Eval journey · NHIM overview