A
| Term | Definition |
|---|---|
| Action | A monitored set of devices tracked through to remediation, with optional automation. Two flavours: Continuous (always-on) and Snapshot (time-bound). |
| Action Center | The hub at /action-center where Actions live, are managed, and their automation logs are visible. See Action Center. |
| Active device | A device seen in at least one connected source within the Inactive device threshold (default 30 days, in Settings → Misc). |
| Analyst | The second of four default roles. Moderate privilege, allowing in-depth data analysis. |
| Audit Log | A complete record of every meaningful action taken in the platform. At Settings → Audit Log. |
| Automation Log | The Action Center’s record of every automation execution (email, ticket, webhook). Separate from the Audit Log. |
C
| Term | Definition |
|---|---|
| Cloud ID | Your tenant’s subdomain on *.threataware.com. Unique per customer. Provided at provisioning. |
| Command Palette | Quick navigation overlay opened with ⌘K / Ctrl+K / /. Type to filter, Enter to jump. See Keyboard Shortcuts. |
| Configuration check | A specific test a Vital performs (e.g. “real-time protection enabled”). Configurable per integration in Vitals Configuration. |
| Continuous Action | An Action that runs perpetually. Devices entering the trigger query are auto-added; devices leaving are auto-removed. See Continuous Actions. |
| Coverage Explorer | The visual overlap viewer at its own page /tag-coverage-explorer. See Coverage Explorer. |
| Cross-mapping | In multi-tenancy, the default mode where devices match across tenants of the same integration. |
D
| Term | Definition |
|---|---|
| Dashboard | The five-panel landing page at /dashboard (Estate Summary, Actions Summary, Tag Coverage Map, Overall Control Health, Integration Control). |
| Default View | A saved view designated as the page’s default opening view. Configurable per page via the view dropdown. |
| Deduplication | Protect’s matching algorithm that fuses multiple tools’ reports of the same physical device into one record. See Device Management. |
| Deployment view | One of two modes in the Devices grid. Shows checkmark / dash for “does this tool see this device?” The other mode is Vitals view. |
| Device | A physical or virtual machine reported by at least one connected source. |
| Device Explorer | The globe-of-devices home at /device-explorer. See Device Explorer. |
| Device retention policy | How long deleted devices are kept (Settings → Misc). |
E
| Term | Definition |
|---|---|
| EDR | Endpoint Detection and Response. |
| End-User Inventory | The User Inventory at /user-inventory (vs. platform users). |
| Estate Summary | Dashboard panel showing total devices. |
F
| Term | Definition |
|---|---|
| Functioning | A Vital state — control is deployed and reporting recent activity. Used in the live UI for non-required integrations that are working (e.g. directory services), and as a status indicator on the device detail panel. The config-drift composite is Misconfigured, not Functioning. See Vitals states. |
H
| Term | Definition |
|---|---|
| Healthy | A Vital state — control is deployed, functioning, and configured per your rules. See Vitals states. |
I
| Term | Definition |
|---|---|
| IdP | Identity Provider (Entra ID, Okta, etc.). |
| Inactive device | Not seen in any connected source for longer than the Inactive device threshold. Hidden from default views. |
| Inactive device threshold | Configurable in Settings → Misc. Default 30 days. |
| Integration | A connection to an external tool (EDR, MDM, IdP, etc.). Configured at Settings → Integrations. |
| Integration Control | Dashboard panel showing per-integration health. |
| Issue | A discrete, time-stamped problem detected by an integration on a specific device. See Issues. |
L
| Term | Definition |
|---|---|
| Last Seen | The most recent activity timestamp for a device. |
| Limited Viewer | Lowest-privilege default role. Often the role auto-provisioned SSO users start at. |
| Logic Engine | The rule editor that drives dynamic tag membership. Uses the query language. |
M
| Term | Definition |
|---|---|
| Matching | The process of identifying that two integrations reporting “a Windows laptop with serial X” are reporting the same physical device. Combined with deduplication. |
| MDM | Mobile Device Management. |
| MFA | Multi-Factor Authentication. |
| Misconfigured | The live UI’s composite badge for required:true AND deployed:true AND functioning:true AND configuredCorrectly:false. The config-drift state. See Vitals states. |
| MSP | Managed Service Provider. |
| MSSP | Managed Security Service Provider. |
| MTTR | Mean Time To Remediation. Shown in days on Continuous Action cards. |
| Multi-tenancy | Connecting multiple instances of the same integration (e.g. two Azure AD tenants). See Multi-Tenancy. |
N
| Term | Definition |
|---|---|
| Not Deployed | A Vital sub-state — control not present. |
| Not Functioning | A Vital state. Control is deployed but not actively working. Often a broken agent rather than a missing one. The cross-tool detection of this state is Protect’s signature differentiator. |
| Not Healthy | A Vital state. Either Not Deployed or Not Functioning. |
| Not Required | A Vital state. The device’s tags don’t require this control — no expectation, no alert. |
| NTLM | NT LAN Manager (Microsoft authentication protocol). |
O
| Term | Definition |
|---|---|
| OIDC | OpenID Connect. |
P
| Term | Definition |
|---|---|
| PII | Personally Identifiable Information. |
| Pinned app | A Reporting app added to the left rail. |
| PowerShell Relay | The reverse-proxy mechanism that lets Protect query on-premises tools without inbound firewall rules. See PowerShell Relay. |
| Protect | The branding for the core ThreatAware product. The page header reads ThreatAware Protect 3.2.0. |
| PSA | Professional Services Automation (e.g. Datto Autotask PSA). |
Q
| Term | Definition |
|---|---|
| Query Language | Protect’s unified search syntax, used in Devices, Users, Issues, the Logic Engine, and Action triggers. See Query Language. |
R
| Term | Definition |
|---|---|
| Read-only | Protect itself is read-only — integrations use read-only credentials wherever the upstream tool supports them, and Protect never writes back to vendor APIs. Actions can trigger outbound automations with your approval. |
| Reporting | The reporting / app-building surface inside Protect at /studio/editor. See Reporting. |
| Resolution criteria | In an Action, the explicit definition of “fixed” beyond just leaving the trigger query. See Action Center. |
| RMM | Remote Monitoring and Management. |
| Role | A bundle of permissions. Protect ships with four defaults (Super Admin, Analyst, Viewer, Limited Viewer); custom roles can be created. See Settings → Roles. |
S
| Term | Definition |
|---|---|
| SAML | Security Assertion Markup Language. |
| Saved View | A named, persisted combination of query + column selection + sort, visible in the view dropdown. Can be Private / Team / Everyone. |
| SCCM | System Center Configuration Manager (Microsoft). |
| Scheduled Report | A recurring email delivery of a saved view’s contents in CSV / JSON / XLSX. At Settings → Scheduled Reports. |
| Schema | The canonical structure of Device Data and User Data inside Protect. Editable at Settings → Schemas. |
| Silent failure | An EDR or security agent that’s deployed and appears healthy in its own console but stopped reporting weeks ago. Protect detects this via cross-tool correlation. |
| Snapshot Action | An Action with a fixed device list captured at creation time and a deadline. Used for projects rather than always-on hygiene. See Snapshot Actions. |
| SSO | Single Sign-On. Supported via Microsoft Entra ID (self-service), Okta (manual setup), and generic SAML / OIDC. |
| Stealth Devices | Beta feature detecting unmanaged devices. See Stealth Devices. |
| Super Admin | The highest-privilege default role. |
| Sync | Periodic API pull from an integration. |
T
| Term | Definition |
|---|---|
| Tag | A label applied to devices or users via the Logic Engine. Drives Vitals scope, Action targeting, and access control. |
| Tag Coverage Map | Dashboard tree-map visualisation of tag distribution. |
| Team | A logical group of users for sharing saved views, Actions, and Reporting apps. |
| Tenant | A separate logical environment in a tool (e.g. multiple Azure AD directories). Distinct from a “Protect tenant” which means your whole organisation’s Protect instance. |
| Threshold | Inactive device cutoff (typically 30 days). |
U
| Term | Definition |
|---|---|
| UPN | UserPrincipalName — not what Protect matches on (uses the mail attribute instead). |
V
| Term | Definition |
|---|---|
| Viewer | Read-only default role. |
| Vital | A single integration’s view of a single device’s security control state. Computed continuously. See Security Monitoring. |
| Vitals Configuration | The per-integration settings that decide what a Healthy / Functioning / Misconfigured state means for that control. See Vitals Configuration. |
| Vitals view | One of two modes in the Devices grid. Shows Healthy / Functioning / Not Healthy. The other is Deployment view. |
X
| Term | Definition |
|---|---|
| X-Ray | The per-device transparency view showing raw payloads from each connected integration. See X-Ray. |
| XDR | Extended Detection and Response. |