> ## Documentation Index
> Fetch the complete documentation index at: https://docs.threataware.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Glossary

> Every term Protect uses, defined once — A-Z reference

A single page that defines every term in Protect. Use Ctrl-F to find anything.

## A

| Term               | Definition                                                                                                                                                                                       |
| ------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| **Action**         | A monitored set of devices tracked through to remediation, with optional automation. Two flavours: [Continuous](/actions-continuous) (always-on) and [Snapshot](/actions-snapshot) (time-bound). |
| **Action Center**  | The hub at `/action-center` where Actions live, are managed, and their automation logs are visible. See [Action Center](/automation).                                                            |
| **Active device**  | A device seen in at least one connected source within the **Inactive device threshold** (default 30 days, in [Settings → Misc](/settings/misc)).                                                 |
| **Analyst**        | The second of four default [roles](/settings/roles). Moderate privilege, allowing in-depth data analysis.                                                                                        |
| **Audit Log**      | A complete record of every meaningful action taken in the platform. At [Settings → Audit Log](/settings/audit-log).                                                                              |
| **Automation Log** | The Action Center's record of every automation execution (email, ticket, webhook). Separate from the Audit Log.                                                                                  |

## C

| Term                    | Definition                                                                                                                                                           |
| ----------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Cloud ID**            | Your tenant's subdomain on `*.threataware.com`. Unique per customer. Provided at provisioning.                                                                       |
| **Command Palette**     | Quick navigation overlay opened with **⌘K** / **Ctrl+K** / **/**. Type to filter, Enter to jump. See [Keyboard Shortcuts](/reference/keyboard-shortcuts).            |
| **Configuration check** | A specific test a Vital performs (e.g. "real-time protection enabled"). Configurable per integration in [Vitals Configuration](/vitals-configuration).               |
| **Continuous Action**   | An Action that runs perpetually. Devices entering the trigger query are auto-added; devices leaving are auto-removed. See [Continuous Actions](/actions-continuous). |
| **Coverage Explorer**   | The visual overlap viewer at its own page `/tag-coverage-explorer`. See [Coverage Explorer](/coverage-explorer).                                                     |
| **Cross-mapping**       | In [multi-tenancy](/multi-tenancy), the default mode where devices match across tenants of the same integration.                                                     |

## D

| Term                        | Definition                                                                                                                                                                        |
| --------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Dashboard**               | The five-panel landing page at `/dashboard` (Estate Summary, Actions Summary, Tag Coverage Map, Overall Control Health, Integration Control).                                     |
| **Default View**            | A saved view designated as the page's default opening view. Configurable per page via the view dropdown.                                                                          |
| **Deduplication**           | Protect's matching algorithm that fuses multiple tools' reports of the same physical device into one record. See [Device Management](/device-management#deduplication--matching). |
| **Deployment view**         | One of two modes in the Devices grid. Shows checkmark / dash for "does this tool see this device?" The other mode is **Vitals view**.                                             |
| **Device**                  | A physical or virtual machine reported by at least one connected source.                                                                                                          |
| **Device Explorer**         | The globe-of-devices home at `/device-explorer`. See [Device Explorer](/device-explorer).                                                                                         |
| **Device retention policy** | How long deleted devices are kept ([Settings → Misc](/settings/misc)).                                                                                                            |

## E

| Term                   | Definition                                                    |
| ---------------------- | ------------------------------------------------------------- |
| **EDR**                | Endpoint Detection and Response.                              |
| **End-User Inventory** | The User Inventory at `/user-inventory` (vs. platform users). |
| **Estate Summary**     | Dashboard panel showing total devices.                        |

## F

| Term            | Definition                                                                                                                                                                                                                                                                                                                              |
| --------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Functioning** | A Vital state — control is deployed and reporting recent activity. Used in the live UI for non-required integrations that are working (e.g. directory services), and as a status indicator on the device detail panel. The config-drift composite is **Misconfigured**, not Functioning. See [Vitals states](/reference/vitals-states). |

## H

| Term        | Definition                                                                                                                      |
| ----------- | ------------------------------------------------------------------------------------------------------------------------------- |
| **Healthy** | A Vital state — control is deployed, functioning, and configured per your rules. See [Vitals states](/reference/vitals-states). |

## I

| Term                          | Definition                                                                                                               |
| ----------------------------- | ------------------------------------------------------------------------------------------------------------------------ |
| **IdP**                       | Identity Provider (Entra ID, Okta, etc.).                                                                                |
| **Inactive device**           | Not seen in any connected source for longer than the **Inactive device threshold**. Hidden from default views.           |
| **Inactive device threshold** | Configurable in [Settings → Misc](/settings/misc). Default 30 days.                                                      |
| **Integration**               | A connection to an external tool (EDR, MDM, IdP, etc.). Configured at [Settings → Integrations](/settings/integrations). |
| **Integration Control**       | Dashboard panel showing per-integration health.                                                                          |
| **Issue**                     | A discrete, time-stamped problem detected by an integration on a specific device. See [Issues](/issues).                 |

## L

| Term               | Definition                                                                                                                |
| ------------------ | ------------------------------------------------------------------------------------------------------------------------- |
| **Last Seen**      | The most recent activity timestamp for a device.                                                                          |
| **Limited Viewer** | Lowest-privilege default [role](/settings/roles). Often the role auto-provisioned SSO users start at.                     |
| **Logic Engine**   | The rule editor that drives dynamic [tag](/tags-and-logic-engine) membership. Uses the [query language](/query-language). |

## M

| Term              | Definition                                                                                                                                                                                     |
| ----------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Matching**      | The process of identifying that two integrations reporting "a Windows laptop with serial X" are reporting the same physical device. Combined with deduplication.                               |
| **MDM**           | Mobile Device Management.                                                                                                                                                                      |
| **MFA**           | Multi-Factor Authentication.                                                                                                                                                                   |
| **Misconfigured** | The live UI's composite badge for `required:true AND deployed:true AND functioning:true AND configuredCorrectly:false`. The config-drift state. See [Vitals states](/reference/vitals-states). |
| **MSP**           | Managed Service Provider.                                                                                                                                                                      |
| **MSSP**          | Managed Security Service Provider.                                                                                                                                                             |
| **MTTR**          | Mean Time To Remediation. Shown in days on Continuous Action cards.                                                                                                                            |
| **Multi-tenancy** | Connecting multiple instances of the same integration (e.g. two Azure AD tenants). See [Multi-Tenancy](/multi-tenancy).                                                                        |

## N

| Term                | Definition                                                                                                                                                                                 |
| ------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| **Not Deployed**    | A Vital sub-state — control not present.                                                                                                                                                   |
| **Not Functioning** | A Vital state. Control is deployed but not actively working. Often a broken agent rather than a missing one. The cross-tool detection of this state is Protect's signature differentiator. |
| **Not Healthy**     | A Vital state. Either Not Deployed or Not Functioning.                                                                                                                                     |
| **Not Required**    | A Vital state. The device's tags don't require this control — no expectation, no alert.                                                                                                    |
| **NTLM**            | NT LAN Manager (Microsoft authentication protocol).                                                                                                                                        |

## O

| Term     | Definition      |
| -------- | --------------- |
| **OIDC** | OpenID Connect. |

## P

| Term                 | Definition                                                                                                                                       |
| -------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------ |
| **PII**              | Personally Identifiable Information.                                                                                                             |
| **Pinned app**       | A Reporting app added to the left rail.                                                                                                          |
| **PowerShell Relay** | The reverse-proxy mechanism that lets Protect query on-premises tools without inbound firewall rules. See [PowerShell Relay](/powershell-relay). |
| **Protect**          | The branding for the core ThreatAware product. The page header reads `ThreatAware` `Protect` `3.2.0`.                                            |
| **PSA**              | Professional Services Automation (e.g. Datto Autotask PSA).                                                                                      |

## Q

| Term               | Definition                                                                                                                                     |
| ------------------ | ---------------------------------------------------------------------------------------------------------------------------------------------- |
| **Query Language** | Protect's unified search syntax, used in Devices, Users, Issues, the Logic Engine, and Action triggers. See [Query Language](/query-language). |

## R

| Term                    | Definition                                                                                                                                                                                                                |
| ----------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Read-only**           | Protect itself is read-only — integrations use read-only credentials wherever the upstream tool supports them, and Protect never writes back to vendor APIs. Actions can trigger outbound automations with your approval. |
| **Reporting**           | The reporting / app-building surface inside Protect at `/studio/editor`. See [Reporting](/reporting).                                                                                                                     |
| **Resolution criteria** | In an Action, the explicit definition of "fixed" beyond just leaving the trigger query. See [Action Center](/automation#advanced-configuration).                                                                          |
| **RMM**                 | Remote Monitoring and Management.                                                                                                                                                                                         |
| **Role**                | A bundle of permissions. Protect ships with four defaults (Super Admin, Analyst, Viewer, Limited Viewer); custom roles can be created. See [Settings → Roles](/settings/roles).                                           |

## S

| Term                 | Definition                                                                                                                                                               |
| -------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| **SAML**             | Security Assertion Markup Language.                                                                                                                                      |
| **Saved View**       | A named, persisted combination of query + column selection + sort, visible in the view dropdown. Can be Private / Team / Everyone.                                       |
| **SCCM**             | System Center Configuration Manager (Microsoft).                                                                                                                         |
| **Scheduled Report** | A recurring email delivery of a saved view's contents in CSV / JSON / XLSX. At [Settings → Scheduled Reports](/settings/scheduled-reports).                              |
| **Schema**           | The canonical structure of Device Data and User Data inside Protect. Editable at [Settings → Schemas](/settings/schemas).                                                |
| **Silent failure**   | An EDR or security agent that's deployed and appears healthy in its own console but stopped reporting weeks ago. Protect detects this via cross-tool correlation.        |
| **Snapshot Action**  | An Action with a fixed device list captured at creation time and a deadline. Used for projects rather than always-on hygiene. See [Snapshot Actions](/actions-snapshot). |
| **SSO**              | Single Sign-On. Supported via Microsoft Entra ID (self-service), Okta (manual setup), and generic SAML / OIDC.                                                           |
| **Stealth Devices**  | Beta feature detecting unmanaged devices. See [Stealth Devices](/stealth-devices).                                                                                       |
| **Super Admin**      | The highest-privilege default [role](/settings/roles).                                                                                                                   |
| **Sync**             | Periodic API pull from an integration.                                                                                                                                   |

## T

| Term                 | Definition                                                                                                                                                              |
| -------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Tag**              | A label applied to devices or users via the [Logic Engine](/tags-and-logic-engine). Drives Vitals scope, Action targeting, and access control.                          |
| **Tag Coverage Map** | Dashboard tree-map visualisation of tag distribution.                                                                                                                   |
| **Team**             | A logical group of users for sharing saved views, Actions, and Reporting apps.                                                                                          |
| **Tenant**           | A separate logical environment in a tool (e.g. multiple Azure AD directories). Distinct from a "Protect tenant" which means your whole organisation's Protect instance. |
| **Threshold**        | Inactive device cutoff (typically 30 days).                                                                                                                             |

## U

| Term    | Definition                                                                           |
| ------- | ------------------------------------------------------------------------------------ |
| **UPN** | UserPrincipalName — not what Protect matches on (uses the `mail` attribute instead). |

## V

| Term                     | Definition                                                                                                                                                             |
| ------------------------ | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Viewer**               | Read-only default [role](/settings/roles).                                                                                                                             |
| **Vital**                | A single integration's view of a single device's security control state. Computed continuously. See [Security Monitoring](/security-monitoring).                       |
| **Vitals Configuration** | The per-integration settings that decide what a Healthy / Functioning / Misconfigured state means for that control. See [Vitals Configuration](/vitals-configuration). |
| **Vitals view**          | One of two modes in the Devices grid. Shows Healthy / Functioning / Not Healthy. The other is **Deployment view**.                                                     |

## X

| Term      | Definition                                                                                                  |
| --------- | ----------------------------------------------------------------------------------------------------------- |
| **X-Ray** | The per-device transparency view showing raw payloads from each connected integration. See [X-Ray](/x-ray). |
| **XDR**   | Extended Detection and Response.                                                                            |
