Skip to main content

Concepts & terminology

This glossary defines the terms you will see in the console and throughout these docs. Terms are grouped by topic; each entry links to the page where you work with it.

The trust model​

TermMeaning
Two trust domainsEvery issuance is decided twice: once in the customer trust domain (your Mesh Nodes) and once by Sectigo Edge. Both must approve the same request. The ConsoleTrust health screen shows posture across both domains.
Dual-control issuanceThe result of the two trust domains: no single administrative plane can issue a certificate on its own.
Fail closedWhen required evidence (policy, quorum, signer receipt) is missing or does not match, the request is refused rather than allowed.

Your organisation​

TermMeaning
WorkspaceYour organisation's private area in Sectigo Edge. Everything you manage (certificates, nodes, policy, users) belongs to one workspace. The console shows it in the WORKSPACE block at the top of the sidebar.
Tenant / tenant IDThe technical name for a workspace. The tenant ID is a short lowercase identifier (for example northwind-health) reserved when Sectigo approves your workspace. It appears in the Account & session dialog (select your name at the bottom of the console sidebar).
Workspace request (registration)The sign-up you submit. It has a registration ID such as reg_3f6c2a91-… and must pass email verification, domain verification and approval before it becomes a workspace. See Create your account.
Enterprise domainThe DNS domain you prove you control (for example example.com). Your work email must belong to it.
RolesFive product roles control what people can do: Tenant Admin, PKI Operator, Break-glass Operator, Auditor and Application Owner. See Access & roles.

Nodes and workloads​

TermMeaning
Mesh NodeA Sectigo Edge service you install on Windows, Linux or Kubernetes. It authenticates local workloads, evaluates requests against your policy and approves or refuses them. It connects outbound only. See Mesh Nodes.
EnrollmentJoining a new Mesh Node to your workspace using a one-time enrollment package. See Enrollment.
Approval quorumHow many distinct healthy Mesh Nodes must approve a request (for example "2 of 3"). Set in your policy; the platform can enforce a minimum.
Service claimA workload or AI agent that announced itself to a Mesh Node and is waiting for an administrator to verify and claim it. Services can introduce themselves, but they cannot approve themselves. See Service claims.
Workload profileA named, exact set of rules for one kind of workload: allowed identity (for example a SPIFFE ID), DNS namespace, algorithms, lifetimes, deployment path and rotation constraints. Requests are evaluated against a specific profile.

Certificates and lifecycle​

TermMeaning
Certificate setA managed identity and its certificates, as shown on Certificates.
Dual-slot rotationOptional mode in which a certificate set has an active slot (serving now) and a staged slot (the replacement). The new certificate is validated (key, chain, configuration, application health) before an atomic promotion, and you can roll back. A failed check leaves the active slot untouched. See Rotation.
MigrationA dependency-aware plan that moves certificates to new algorithms or CAs in canary waves, with approvals and automatic restore. See Migrations.
Trust graphThe map of which services, certificates, CAs and nodes depend on each other, used to see the blast radius of a change. See Trust graph.
Crypto postureYour algorithm mix and post-quantum readiness, based on evidence of what endpoints can actually use. See Crypto posture.
Revocation (CRL / OCSP)Withdrawing a certificate before it expires, and publishing that status through certificate revocation lists and OCSP responses. See Revocation.

Policy​

TermMeaning
Policy (enterprise policy)Your workspace's signed, versioned rules: allowed algorithms, lifetimes, approval quorum, workload profiles and issuance guardrails. Changes are proposed, assessed for impact and approved before activation. See Policies.
Platform policySectigo's safety floor that sits above your policy. It is controlled outside your workspace administration and cannot be loosened by tenant administrators.
Effective policyWhat actually applies: platform policy, then enterprise policy, then the workload profile. A request is denied unless every layer allows it, and the most restrictive value wins.
Issuance guardrailsLimits that detect or block abnormal behaviour, such as request velocity per requester, namespace expansion, algorithm downgrade or lifetime escalation.

Signing​

TermMeaning
CA connectorYour connection to a signing authority: Sectigo Certificate Manager (SCM), a bring-your-own CA, or Microsoft ADCS. See CAs & signing.
Protected signerThe hardened signing boundary that holds CA keys. It signs only dual-approved requests and returns a signed receipt. Sectigo Edge keeps only the public chain and an opaque key reference for imported CAs.

Evidence and response​

TermMeaning
Audit evidenceA signed, hash-chained record of every issuance and administrative action, held by both Sectigo and you, and exportable as a portable proof bundle. See Audit evidence.
Trust eventA signed, tenant-bound fact (for example a certificate issued, a node state change or a policy activation) published to the trust event stream. See Trust events.
Kill switchAn emergency control that pauses all new issuance in the workspace without interrupting identities that already exist.
Break-glassThe guarded process for emergency actions such as the kill switch. A different person with the Break-glass Operator role and fresh MFA must approve. See Incidents & break-glass.
Fresh MFA (step-up)Some sensitive actions require that you completed multi-factor authentication within the last ten minutes. If not, you are asked to sign in again.