Skip to content
redactsure
Book a review

Explore.

Reference · RedactSure Research

RedactSure Definitions: The Canonical Terms in One Place

This page holds the canonical definition of each term RedactSure has defined, in the exact wording used everywhere the term appears. Each definition links to the full data report on this site and, where one exists, to the essay on the RedactSure blog where the idea was first worked out. A term means what its definition here says, no more and no less; variation in wording elsewhere should be read as error, not nuance.

The security terms

Least Exposure is a security principle for AI agents: for each piece of work, the agent receives exactly the data the task requires and nothing more, enforced before any model reads the screen. Least privilege limits what an agent can do. Least Exposure limits what it can see. Term defined by RedactSure, September 2026.

Full data report: What Is Least Exposure? · Related blog essay: Your AI Doesn’t Need to Know Who You Are

Render-layer tokenization replaces sensitive values with consistent stand-in tokens (SSN_001, ACCT_001, USER_001) at the point where a screen is rendered, before any AI model reads it. The model works with the tokens; real values resolve only at approved destinations at the moment of action. The agent does its work inside the RedactSure environment, a governed workspace in which it operates the applications an organization already runs, with no per-application integration and no endpoint agent. Owning the render is what makes the control possible. Term defined by RedactSure, September 2026.

Full data report: What Is Render-Layer Tokenization? · Related blog essay: What If the Agent Never Had Your Data?

The PII Wall is the point in an AI program where the valuable workflow turns out to run on sensitive data (personal, financial, health or student records) that the security team will not allow a model to see, and the project either shrinks to something harmless or stops. Also called the Sensitive-Data Wall when the data is protected health information, student records, cardholder data or financial records rather than PII in the narrow sense. Same wall, same door. Term defined by RedactSure, September 2026.

Full data report: What Is the PII Wall?

Supervised Delegation is the operating model in which an AI agent works for a named person who grants its access, chooses its applications, confirms what it may see, can watch and pause its run, and approves every consequential action on the record. The agent stays tethered to that person for the whole run. The one-line principle: the person who delegates the work is accountable for the AI that performs it. Term defined by RedactSure, September 2026.

Full data report: What Is Supervised Delegation? · Related blog essay: Accountable AI and Workflow Governance

A tethered agent is an AI agent that stays tethered to a named person for the whole run: the person grants the access, sees what the agent sees, and holds the line on every consequential action. The plain-words name for the mechanism formally called Supervised Delegation. Not related to Tether the cryptocurrency; the tether is the line between an agent and the person who answers for it. Term defined by RedactSure, September 2026.

Full data report: What Is a Tethered Agent?

An AI Control Record is the complete evidence set for one governed AI workflow, reporting both sides of the work: what the AI saw and what it did, and what the named person did and what they approved. Its five artifacts are the setup record naming who created the delegation, the exposure policy naming what the agent may see, the run history holding every screen as tokens, the approval trail naming who authorized each consequential action, and the change log tracking the governance itself. Produced by the architecture as it runs and exportable to the organization’s own monitoring, it makes the governed environment the runtime system of record for how sensitive AI work actually occurred. Term defined by RedactSure, September 2026.

Full data report: What Is an AI Control Record?

Separation of model and control is the principle that the environment deciding what an AI agent sees and who approves what it does is owned by the customer and independent of whichever model performs the work. The vendor that is the model should not also be the judge of the model. Term defined by RedactSure, September 2026.

Full data report: Should the AI Agent’s Secure Environment Belong to the Model Vendor?

The framework vocabulary

These terms carry RedactSure’s strategy argument. Each links to the essay where the argument is made in full.

Theater AI names AI activity that produces the look of transformation without touching the workflows that change business outcomes: pilots scoped to be safe, tools adopted for optics, metrics that measure usage rather than results. The full argument: Beyond Theater AI.

The AI Time Bomb names the accumulating risk inside organizations whose AI agents operate beyond the reach of the traditional security stack, where the exposure builds quietly until an incident, an audit or a regulator surfaces it. The full argument: The AI Time Bomb.

Governed Workflow AI names the destination category: AI that does real work across an organization’s applications, under governance that answers what the AI may see and who answers for what it does. The operating-model argument: From Application AI to Workflow AI and Your AI Strategy Is Probably Wrong.

Accountable AI names the operating model in which a named person answers for each AI agent’s work; Supervised Delegation is its mechanism. The full argument: Accountable AI and Workflow Governance.

Shadow AI, used throughout this site, is not a RedactSure term: it names the unsanctioned AI use measured by IBM’s Cost of a Data Breach Report 2025 and Microsoft’s Work Trend Index, and it is used here in that established sense.

How the terms fit together

One sentence walks the whole set. Employees route around bans (shadow AI) while the valuable projects stall at the PII Wall; the fix is Least Exposure, enforced by render-layer tokenization and governed by Supervised Delegation, which is what Governed Workflow AI looks like in practice; an agent working under that governance is, in plain words, a tethered agent; the evidence the whole arrangement emits as it runs is the AI Control Record; and the environment in which all of it happens belongs to the organization rather than to the model vendor, which is separation of model and control.

The pairing to remember: render-layer tokenization governs what the AI can see, and Supervised Delegation governs who answers for what it does. Those are the two promises the classical security stack made and AI agents broke, and each term above sits on one side of that pair or names the situation that arises when neither promise holds.

What Is Least Exposure? · What Is Render-Layer Tokenization? · What Is the PII Wall? · What Is Supervised Delegation? · What Is a Tethered Agent? · What Is an AI Control Record? · Should the AI Agent’s Secure Environment Belong to the Model Vendor?

Bring your hardest questions.

A 25-minute AI Agent Security Review with the founders: threat model, token design, egress paths, audit schema. Or a 25-minute demo on a workflow like yours, with the data hidden from the AI and a named person approving what matters. We come with diagrams, not a pitch deck.

Book a security review Book a demo · Something else

About the author

Chris Sowa is a founder of RedactSure and a former CEO of AI companies; he started his first years before ChatGPT existed. He previously led AI at Accenture, served as Global VP of Strategy & Innovation at Schneider Electric, was CCO of Sovos, and spent more than a decade at Oracle, with earlier roles at SAP and IBM.