Capability
Capacidad
What a system can do: language, reasoning, code generation, tool use, long-horizon autonomy.
Editorial vocabulary
The canonical terms ATLAS uses, and the one distinction that holds the whole project together: capability becomes authority when a model output turns into an executed effect.
Capacidad
What a system can do: language, reasoning, code generation, tool use, long-horizon autonomy.
Autoridad
The power to act on data, identity, tools, permissions or decisions. Capability becomes authority when a model output turns into an executed effect.
Superficie de exposición
What a capability can reach: data, identity, tools, permissions and decisions.
Riesgo
A coordinate in the atlas: the input, the authority it can reach, the failure it can trigger, and the control evidence that would make it tolerable.
Control
A boundary with memory: it records what the organization permits, who accepts the residual risk, and what evidence must exist after execution.
Salvaguarda
A protective measure. In ATLAS, 'safeguard' and 'control' are treated as synonyms; 'control' is the canonical term.
Evidencia
The proof that a control operates: configuration, policy, logs, records or evaluation results that connect a control to a framework requirement.
Framework
An external normative or methodological reference (OWASP, NIST, MITRE ATLAS, ISO, EU AI Act, Google SAIF) that ATLAS maps to its risks and controls.
Frontera de confianza
The point at which content or instructions from one trust domain enter another. Prompt injection is a trust-boundary failure.
Riesgo operativo
The risk that a system's output produces an operational effect on data, access or action. ATLAS maps operational risk, not model behavior in isolation.
IA agéntica
Systems that plan, remember, invoke tools and execute multi-step actions with delegated authority.
Gobierno
Who owns the system, who accepts residual risk, and with what evidence.