- AI agent
- Software that pursues a goal by planning, calling tools and acting with some autonomy, rather than only answering a single prompt. Because agents act, their permissions and boundaries matter as much as their answers.
- AI agent marketplace
- A catalog where teams discover, evaluate and adopt ready-made AI agents. A governed marketplace also ties each listing to a specific version, declared permissions and inspectable evidence. Learn more →
- Algen package (.algen)
- A versioned archive of an agent with a manifest, delivered for local installation after you verify its digest. Agent Hub does not execute it for you.
- Artifact digest
- A SHA-256 fingerprint of a package's bytes. Comparing the digest of your download with the one on the listing confirms you have the exact release that was reviewed.
- ASCEND
- Algen's gated assurance maturity model for one identified agent version, from M0 Declared to M5 Continuously assured. It is a scoped assessment, not certification. Learn more →
- Declared vs verified
- A declared claim is what the publisher states. A verified claim has been checked, and the listing says by whom, for which version and when. Agent Hub keeps the two visibly separate.
- Governed AI agent
- An agent whose purpose, limits, permissions, version and assurance evidence are explicit and inspectable, and whose risky actions are bounded, for example by human approval or egress controls.
- Hosted agent
- A delivery path where the publisher operates the agent behind an endpoint. Access and authentication are set by the publisher and declared on the listing.
- Human-in-the-loop decision
- A point where an agent must wait for a named person to approve or reject before it proceeds, such as releasing an analysis or acting on a customer account.
- Immutable version
- A published release that never changes. Material code, manifest, permission, delivery or evidence changes require a new version, so reviews and assessments stay attached to exactly what was reviewed.
- Import grant
- A narrowly scoped, short-lived authorization that lets a relying party such as Algen Studio redeem an approved, digest-pinned artifact after the user has acquired it.
- Least privilege
- Granting an agent only the data, tools and network destinations it needs. ASCEND M2 requires documented least privilege; M3 requires that scopes and egress are enforced at runtime.
- Marketplace manifest
- The machine-readable declaration (algen-marketplace-manifest/v1) of a version's identity, capabilities, license, ownership, data classes, network access, secrets and delivery.
- Maturity level (M0–M5)
- The cumulative ASCEND gate an agent version has passed. To claim M3, every mandatory M0, M1, M2 and M3 control must pass. There are no averaged scores or partial credit. Learn more →
- Quarantine
- The isolated holding state for uploaded packages while archive safety, secrets, dependencies and evidence are checked. Submitted code is never executed in the web or API process.
- Risk overlay
- A separate ASCEND axis describing what could happen in the scoped deployment. It never adds maturity points and cannot be lowered because controls are difficult to implement.
- SBOM (software bill of materials)
- A machine-readable inventory of an agent's dependencies, such as a CycloneDX file, used to assess supply-chain exposure for a specific version.
- Source container
- A delivery path where the agent ships as a container image that you inspect by image reference and digest, then run in your own environment.
- Verified rating
- A rating from a user with a recorded acquisition. It stays tied to the version that person acquired, and each user has one editable rating per agent.