رفتن به محتوا

واژه‌نامه

تعریف اصطلاحاتی که هنگام ساخت سیستم‌های پاسخگوی خودکارسازی کار با هوش مصنوعی مهم‌اند.

Agentic operations is the practice of running business operations with AI agents that plan and act — not just answer — under explicit governance. Agents triage intake, retrieve grounded evidence, propose actions, and execute approved ones in real systems, while approvals, policy checks, and an audit trail keep their activity safe. It pairs agent autonomy with operational controls so automation can run in production.

مترادف‌ها: agentic workflow automation, AI operations automation, agent operations, AI ops

How is agentic operations different from a chatbot?
A chatbot answers messages. Agentic operations runs work: agents classify intake, ground answers in cited evidence, and execute governed actions in business systems, with approvals and an audit trail — the unit of value is completed, accountable work.
What keeps agentic operations safe in production?
Scoped credentials bound what agents can touch, policy overlays decide what needs human approval, evaluation gates test behavior before rollout, and every step is recorded — so autonomy never outruns accountability.

AI work automation is the use of AI models to turn unstructured requests — emails, chats, documents, forms — into completed work: grounded answers or actions executed in business systems. Unlike chat assistants, it operates on structured work items with evidence, approvals, and an audit trail, so every outcome is traceable and governed.

مترادف‌ها: AI workflow automation, agentic workflow automation, AI work orchestration, intelligent work automation

How is AI work automation different from an AI chatbot?
A chatbot produces a reply and forgets the exchange. AI work automation converts each request into a structured work item, grounds answers in cited evidence, routes proposed actions through approvals, and records the outcome — the unit of value is completed work, not a message.
How does it relate to agentic workflow automation?
They describe the same category from different angles. Agentic framing emphasizes the model planning and acting; work-automation framing emphasizes the governance around it — structured intake, evidence, approval gates, and an audit trail that makes agent activity safe to run in production.

بهینه‌سازی موتور پاسخ یعنی ساختار دادن به محتوا به‌گونه‌ای که موتورهای پاسخ هوش مصنوعی و دستیارهای گفتگو بتوانند آن را پیدا، نقل و دقیق خلاصه کنند. جایی که SEO لینک‌های رتبه‌بندی‌شده را هدف می‌گیرد، AEO خود پاسخ ترکیب‌شده را هدف می‌گیرد و برای تعریف‌های روشن، داده ساختاریافته و فایل‌های منبع قابل‌خواندن برای ماشین بهینه می‌شود.

مترادف‌ها: AEO, generative engine optimization, GEO, AI search optimization

AEO چه تفاوتی با SEO دارد؟
SEO برای رتبه گرفتن به‌عنوان یک لینک قابل کلیک در صفحه نتایج بهینه می‌کند. AEO برای انتخاب، نقل و ارجاع درون یک پاسخ تولیدشده با هوش مصنوعی بهینه می‌کند؛ چیزی که تعریف دقیق، داده ساختاریافته و خوراک‌های تمیز و قابل‌خواندن برای ماشین را پاداش می‌دهد.
چه سیگنال‌هایی به یک موتور پاسخ کمک می‌کند صفحه‌ای را ارجاع دهد؟
نوشتن با تعریف در ابتدای متن، داده ساختاریافته معتبر schema.org، یک نمایه llms.txt، نشانه‌گذاری FAQ و URLهای canonical پایدار، همگی بازیابی و نسبت‌دهی محتوا را برای موتور پاسخ آسان‌تر می‌کنند.

An audit trail is the tamper-evident record of everything that happened to a piece of work: what arrived, what the AI extracted and proposed, which evidence grounded each answer, who approved what, and which actions executed. It lets teams reconstruct and prove any outcome end to end — essential for compliance, debugging, and trust in automation.

مترادف‌ها: audit log, activity log, execution history, decision log

What does an audit trail capture in AI work automation?
Each event in a work item's life: intake and its source channel, extracted fields, retrieved evidence and citations, the AI's proposals, every approval or rejection with actor and timestamp, and the executed actions with their results.
Why does an audit trail matter for AI specifically?
AI decisions are probabilistic, so accountability has to come from the record rather than the rule. A complete trail shows what the model saw, what it proposed, and who authorized the outcome — turning otherwise opaque automation into something reviewable and defensible.

Automated resolution is when an AI work platform completes a request end to end — understanding the intake, grounding an answer in cited evidence, or executing a governed action — without a person doing the work, while still leaving a full record. It is measured honestly: only requests closed correctly and within policy count, and anything uncertain is escalated rather than force-closed.

مترادف‌ها: auto-resolution, automated containment, self-service resolution, deflection

How is automated resolution measured honestly?
Only requests resolved correctly, within policy, and without human intervention count toward the rate. Uncertain or low-confidence cases are escalated, not force-closed, so the metric reflects real outcomes instead of inflated deflection.
What happens when a request can't be resolved automatically?
It becomes a WorkItem routed to the right owner with full context — the intake, evidence, and reasoning attached — so a person picks up a complete case rather than starting from scratch.

The CAIQ (Consensus Assessments Initiative Questionnaire) is a cloud-security self-assessment from the Cloud Security Alliance (CSA), aligned to the Cloud Controls Matrix (CCM). A provider answers each control question — typically yes/no with notes — to document its security posture, and CAIQ submissions can be published in the CSA STAR registry.

مترادف‌ها: Consensus Assessments Initiative Questionnaire, CSA CAIQ, CAIQ questionnaire

How does CAIQ relate to the Cloud Controls Matrix (CCM)?
The CAIQ is the question form of the CCM: each CAIQ question maps to a CCM control, so answering the CAIQ documents how a provider meets the CCM's cloud-security control domains. They are maintained together by the Cloud Security Alliance.
What is the CSA STAR registry?
STAR (Security, Trust, Assurance and Risk) is the CSA's public registry where cloud providers can publish completed CAIQ self-assessments (and higher assurance levels). A published CAIQ lets customers review a provider's posture without sending a bespoke questionnaire.

Chunking فرایند شکستن سندهای منبع به واحدهای کوچک‌تر retrieval پیش از embedding آنهاست. اندازه chunk و راهبرد مرزها تعیین می‌کند retriever با چه دقتی fact مرتبط را پیدا می‌کند و recall، precision و هزینه embedding را در یک knowledge base متوازن می‌سازد.

مترادف‌ها: text chunking, document segmentation, passage splitting, chunk strategy

چه چیزی یک chunk خوب می‌سازد؟
یک chunk خوب از نظر معنایی self-contained است، آن‌قدر اندازه‌گذاری شده که یک fact واحد میان مرزها split نشود، و metadata پایدار دارد تا بتواند با اطمینان filter، refresh و cite شود.
Chunking چگونه بر کیفیت پاسخ اثر می‌گذارد؟
chunkهای بیش از حد بزرگ relevance را dilute و token را هدر می‌دهند، و chunkهای بیش از حد کوچک context را می‌شکنند و معنا را از دست می‌دهند. انتخاب مرزها مستقیماً recall و groundedness پاسخ‌های generated را شکل می‌دهد.

Citation شواهد یعنی پیوست کردن referenceهای source قابل راستی‌آزمایی به هر claimی که یک سامانه AI مطرح می‌کند. هر passage cited به سند، record یا knowledge assetی که از آن آمده وصل می‌شود تا یک شخص پیش از اعتماد یا اقدام، grounded بودن پاسخ را تأیید کند.

مترادف‌ها: citation, source attribution, evidence linking, answer provenance

یک citation باید چه چیزهایی داشته باشد؟
حداقل source identifier و passage دقیق استفاده‌شده، و ideally یک link پایدار و timestamp، تا بازبینان تأیید کنند شواهد هنگام تولید پاسخ current بوده است.
چرا citation برای automation govern شده ضروری است؟
citation پاسخ را auditable می‌کند. بدون آن، پاسخ خودکار بی‌پاسخ‌گویی است؛ با آن، بازبین می‌تواند grounding را verify کند و audit trail ثابت کند چه شواهدی تصمیم را هدایت کرده است.

Embedding یک vector عددی است که معنای متن، تصویر یا داده دیگر را در فضایی high-dimensional نمایش می‌دهد. آیتم‌هایی با معنای مشابه vectorهایی نزدیک به هم می‌سازند و این به سامانه‌ها اجازه می‌دهد محتوا را با similarity معنایی، نه match دقیق، مقایسه، cluster و retrieve کنند.

مترادف‌ها: vector embedding, text embedding, semantic vector, dense representation

چرا version مدل embedding مهم است؟
vectorهای مدل‌های متفاوت قابل مقایسه نیستند. ذخیره version مدل با هر embedding اجازه می‌دهد drift را تشخیص دهید و هنگام upgrade مدل embedding با اطمینان reindex کنید.
آیا embeddingها به متن اصلی reversible هستند؟
نه دقیقاً؛ اما embeddingها می‌توانند اطلاعات حساس را leak کنند، بنابراین باید همان tenant isolation و access control محتوای منبعی را که نمایندگی می‌کنند به ارث ببرند.

An evaluation gate is an automated quality checkpoint that scores an AI workflow against curated test cases before a change ships. Prompts, retrieval settings, or pack updates must pass thresholds for accuracy, grounding, and safety; failing changes are blocked from release. Gates turn AI quality from a hope into an enforced, repeatable engineering practice.

مترادف‌ها: eval gate, quality gate, release gate, evaluation harness

What does an evaluation gate measure?
Typically answer accuracy against expected outputs, grounding quality (are claims backed by retrieved evidence), intent-classification correctness, and safety checks — each scored over a curated dataset that reflects real production traffic.
When do evaluation gates run?
Before a configuration change is released: editing a prompt, swapping a model, tuning retrieval, or updating a pack triggers the evaluation suite, and the change only promotes if scores clear the configured thresholds.

A governed action is a system operation proposed by AI but executed only under explicit controls — scoped credentials, policy checks, and approval gates. Instead of letting a model act directly, the platform records the proposal, routes it for review when policy requires, and executes it with full attribution, so automation never outruns accountability.

مترادف‌ها: governed execution, approval-gated action, policy-gated action, controlled action

What controls apply to a governed action?
Scoped connector credentials limit what the action can touch, policy rules decide whether it needs human approval, and execution is attributed and logged — so each action carries who proposed it, who approved it, and exactly what changed.
Do all governed actions require human approval?
No. Policies can auto-approve low-risk, well-grounded actions and reserve human review for sensitive ones — by action type, monetary threshold, or risk class — so oversight concentrates where it matters.

Grounding یعنی محدود کردن خروجی مدل AI به شواهد source قابل راستی‌آزمایی، نه حافظه پارامتری آن. پاسخ grounded با passageهای بازیابی‌شده‌ای پشتیبانی می‌شود که قابل cite و check هستند و دفاع اصلی در برابر پاسخ‌های fabricated یا با اعتمادبه‌نفس اما wrong است.

مترادف‌ها: grounded AI, evidence grounding, source grounding, factual grounding

در عمل grounding چگونه enforce می‌شود؟
Retrieval فقط passageهای source مرتبط را به مدل می‌دهد، prompt از مدل می‌خواهد از همان evidence پاسخ دهد، و مرحله verification claimهایی را که citation پشتیبان ندارند رد می‌کند.
وقتی evidence برای grounding وجود ندارد چه می‌شود؟
یک سامانه grounded خوب طراحی‌شده به‌جای invent کردن پاسخ، decline می‌کند یا به انسان escalate می‌کند و به‌جای حدس مطمئن، gap صریح را نشان می‌دهد.

Hallucination خروجی مطمئن اما unsupported یا fabricated از یک مدل زبانی است؛ claimی که plausible به نظر می‌رسد اما در شواهد ارائه‌شده یا واقعیت پایه‌ای ندارد. Hallucination ریسک مرکزی در خودکارسازی knowledge work است و grounding با evidence cited مهم‌ترین mitigation آن است.

مترادف‌ها: AI hallucination, fabrication, confabulation, ungrounded output

چرا مدل‌های زبانی hallucinate می‌کنند؟
مدل‌ها متن محتمل را پیش‌بینی می‌کنند، نه factهای verified را. بدون evidence بازیابی‌شده که آنها را constrain کند، gapها را با statementهای statistically plausible اما unverified پر می‌کنند.
چگونه hallucination را کاهش می‌دهید؟
پاسخ‌ها را در sourceهای بازیابی‌شده ground کنید، citation بخواهید، claimها را با evidence verify کنید و موردهای low-confidence یا unsupported را به‌جای بازگرداندن حدس، به انسان route کنید.

Human-in-the-loop یک الگوی طراحی است که در آن انسان‌ها proposalهای یک سامانه AI را پیش از اثرگذاری review، approve یا correct می‌کنند. این الگو judgment انسانی را برای تصمیم‌های high-risk یا low-confidence در critical path نگه می‌دارد، در حالی که automation حجم routine را مدیریت می‌کند.

مترادف‌ها: HITL, human in the loop, human oversight, human review

چه زمانی یک مرحله باید human-in-the-loop باشد؟
هرگاه تصمیم high-risk، irreversible، low-confidence یا governed by policy باشد. مرحله‌های routine، grounded و low-risk می‌توانند خودکار اجرا شوند و انسان exceptionها را review کند.
این چه تفاوتی با full automation دارد؟
Full automation بدون review عمل می‌کند. Human-in-the-loop یک checkpoint صریح وارد می‌کند تا انسان بتواند proposal را approve، edit یا reject کند و accountability برای outcomeهای حساس حفظ شود.

Model Context Protocol یک استاندارد باز است که به دستیارهای AI اجازه می‌دهد از طریق interface یکپارچه به ابزارهای خارجی و sourceهای داده وصل شوند. یک MCP server toolها و resourceهای typed را expose می‌کند که client مدل می‌تواند discover و call کند، پس capabilityها بدون code اختصاصی برای هر integration اضافه می‌شوند.

مترادف‌ها: MCP, model context protocol, MCP server, tool protocol

یک MCP server چه چیزی expose می‌کند؟
toolهای typed که مدل می‌تواند invoke کند و resourceهایی که می‌تواند بخواند؛ هرکدام با schema و annotation توصیف می‌شوند تا client قابلیت‌ها را discover و با امنیت call کند.
چرا MCP برای automation govern شده مهم است؟
به assistantهای خارجی راهی standard و schema-described برای عمل روی platform می‌دهد؛ بنابراین tool callها می‌توانند validate، scoped به tenant و از همان policy تأیید دیگر actionها عبور داده شوند.

A policy overlay is the layer of governance rules a platform applies on top of AI work — deciding what an agent may answer or do, when human approval is required, and which guardrails bind each action. Policies are versioned and evaluated at runtime against each WorkItem, so the same request is handled consistently and every decision traces back to the policy version that produced it.

مترادف‌ها: policy layer, governance overlay, policy controls, guardrail policy

What does a policy overlay control?
It controls what an AI agent is allowed to answer or execute: which actions are auto-approved, which require human approval, what grounding or evidence is required, and which connectors and data a WorkItem may touch — all evaluated per request rather than hardcoded.
Why version policies instead of hardcoding rules?
Versioned policies make governance auditable and reversible. Each decision records the policy version that produced it, so you can see why an action was allowed or held, roll a change back, and prove consistent handling during a review.

Questionnaire automation is the use of AI to draft answers to recurring questionnaires — security questionnaires, SIG and CAIQ workbooks, RFP sections, and due-diligence forms — from an organization's own approved sources. Done accountably, each questionnaire becomes a tracked work item whose answers are grounded in cited evidence, routed for approval, and exported with an audit trail.

مترادف‌ها: security questionnaire automation, RFP response automation, AI questionnaire response

How is questionnaire automation different from a chatbot writing answers?
A chatbot generates plausible text and forgets it. Accountable questionnaire automation turns each questionnaire into a structured work item, draws answers from your approved sources with citations, routes sensitive answers for approval, and records who answered what and on what basis — so the output is defensible, not just fluent.
How does questionnaire automation stay accurate?
Answers are grounded in retrieval over sources you approve and cite the evidence behind each one. When the evidence does not support an answer, a well-designed system flags it for a human instead of guessing, and sensitive answers wait for a named owner before they are sent.

Retrieval ترکیبی semantic vector search را با lexical keyword search ترکیب می‌کند تا passageهای مرتبط را بازیابی کند. Vector search معنا و paraphrase را می‌گیرد، keyword search اصطلاح‌ها و شناسه‌های دقیق را می‌گیرد، و مرحله fusion هر دو مجموعه نتیجه را merge می‌کند تا نه tokenهای دقیق و نه matchهای مفهومی از دست بروند.

مترادف‌ها: hybrid search, dense-sparse retrieval, vector plus keyword search, fusion retrieval

چرا vector و keyword search را ترکیب کنیم؟
Vector search ممکن است اصطلاح‌های دقیق نادر مثل SKU یا error code را از دست بدهد، و keyword search paraphraseها را از دست می‌دهد. fusion هر دو، قوت‌های هرکدام را برمی‌گرداند و recall را روی queryهای واقعی بالا می‌برد.
دو مجموعه نتیجه چگونه ترکیب می‌شوند؟
یک روش fusion مانند reciprocal rank fusion یا weighted score blend candidateهای merge شده را rerank می‌کند، و اغلب برای precision نهایی یک cross-encoder reranker هم بعد از آن می‌آید.

Retrieval-augmented generation تکنیکی است که خروجی مدل زبانی را به سندهای source بازیابی‌شده ground می‌کند، نه اینکه فقط به حافظه پارامتری آن تکیه کند. سامانه passageهای مرتبط را از knowledge base fetch می‌کند، آنها را context می‌دهد و از مدل می‌خواهد فقط با همان evidence پاسخ دهد.

مترادف‌ها: RAG, retrieval augmented generation, grounded generation, context augmentation

چرا به‌جای fine-tuning از RAG استفاده کنیم؟
RAG دانش را در store خارجی نگه می‌دارد که فوراً update می‌شود، بنابراین پاسخ‌ها current می‌مانند و هر claim به source قابل trace است. Fine-tuning دانش را در weightها bake می‌کند که refresh آن کندتر و attribution آن سخت‌تر است.
یک RAG pipeline شامل چیست؟
معمولاً ingestion و chunking، embedding، index برای vector یا hybrid search، retriever و مرحله generation که مدل را روی passageهای بازیابی‌شده condition می‌کند و evidence cited برمی‌گرداند.

A security questionnaire is a structured set of questions one organization sends another — usually a customer to a vendor — to assess how it protects data and systems. Common formats include the SIG, CAIQ, RFP security sections, and custom spreadsheets, and answers must be consistent, evidence-backed, and reviewed before they are returned.

مترادف‌ها: vendor security questionnaire, third-party security questionnaire, security assessment questionnaire, due diligence questionnaire

What formats do security questionnaires come in?
Common formats include standardized frameworks like the SIG (Standardized Information Gathering) and CAIQ (Consensus Assessments Initiative Questionnaire), the security section of an RFP, and custom spreadsheets a customer sends. The underlying questions overlap heavily, which is why past answers are the main source for new ones.
How do teams answer security questionnaires efficiently?
The fastest, safest approach reuses approved prior answers and source documents — previous questionnaires, security policies, SOC 2 reports, DPAs — retrieved and cited per answer, with sensitive answers routed to a named owner for approval before the completed workbook is returned.

The SIG (Standardized Information Gathering) questionnaire is a standardized third-party risk assessment maintained by Shared Assessments. It provides a common library of questions across security, privacy, and resilience domains, and ships in scoped variants (such as SIG Core and SIG Lite) so assessors can right-size the depth of a vendor review.

مترادف‌ها: SIG questionnaire, Standardized Information Gathering questionnaire, Shared Assessments SIG

What is the difference between SIG Core and SIG Lite?
SIG Lite is a shorter, higher-level set for lower-risk vendors or a first pass; SIG Core is the deeper, more comprehensive set for higher-risk or in-depth reviews. Both draw from the same Shared Assessments question library, so answers map across variants.
Who maintains the SIG?
The SIG is maintained by Shared Assessments, an industry member organization, and is updated periodically to track regulations and control frameworks. It is widely used so vendors can reuse consistent answers across many customers.

SSO ورود را متمرکز می‌کند و به IdP اجازه می‌دهد سیاست‌هایی مانند MFA و دسترسی مشروط را اعمال کند. دسترسی به Threada همچنان به کاربر موجود و نقش مستأجرِ مدیریت‌شده توسط ادمین نیاز دارد.

مترادف‌ها: saml, federated login, enterprise sso

چرا SSO برای platformهای shell-and-pack مهم است؟
SSO ورود را متمرکز می‌کند و به IdP اجازه می‌دهد سیاست‌هایی مانند MFA و دسترسی مشروط را اعمال کند. دسترسی به Threada همچنان به کاربر موجود و نقش مستأجرِ مدیریت‌شده توسط ادمین نیاز دارد.

A vendor security review is the process by which an organization evaluates the security and compliance posture of a third-party supplier before onboarding and periodically afterward. It typically combines a security questionnaire, evidence collection (SOC 2, ISO, pen-test summaries), and a documented risk decision with an owner and an audit trail.

مترادف‌ها: vendor security assessment, third-party security review, third-party risk assessment, vendor risk review

What is the difference between a vendor security review and a security questionnaire?
The questionnaire is one input; the review is the whole process. A vendor security review gathers questionnaire responses plus supporting evidence, assesses residual risk, records a decision and its owner, and schedules re-review — so the questionnaire is the data, the review is the governed workflow around it.
How often should vendor security reviews happen?
Most programs review a vendor at onboarding and then on a risk-based cadence — annually for higher-risk vendors, or when scope, data access, or the vendor's controls change. Keeping each review as an auditable record makes the next cycle a re-check rather than a restart.

Vertical pack یک configuration بسته‌بندی‌شده است که platform را برای یک domain مشخص از کار تنظیم می‌کند: intentها، fieldهای extraction، sourceهای evidence، policyها و actionها. Packها اجازه می‌دهند team یک workflow متمرکز، مثل IT access یا vendor security، را بدون بازسازی engine زیرین launch کند.

مترادف‌ها: pack, vertical pack, solution pack, domain pack

Vertical pack چه چیزی را configure می‌کند؟
intentهایی که می‌شناسد، fieldهایی که extract می‌کند، evidenceی که پاسخ‌ها را در آن ground می‌کند، policyهای تأییدی که enforce می‌کند و actionهای govern شده‌ای که برای آن domain کاری می‌تواند propose کند.
آیا packها customizable هستند؟
بله. pack یک configuration آغازین است که teamها در Studio با تنظیم intentها، promptها، sourceهای evidence و policyها آن را با process واقعی خود تطبیق می‌دهند.

Work packet بسته contextی است که پیرامون WorkItem assembled می‌شود تا بتوان درباره آن reasoning و action کرد: درخواست اصلی، fieldهای extracted، evidence بازیابی‌شده، policy قابل اعمال و هر action پیشنهادی. این briefing کامل و self-contained برای یک قطعه کار است.

مترادف‌ها: work bundle, context packet, task packet, work context

Work packet چه تفاوتی با WorkItem دارد؟
WorkItem record tracked خود درخواست است. Work packet context assembled، یعنی evidence، policy و proposalها، است که پیرامون آن record جمع می‌شود تا answer یا action را هدایت کند.
چرا context را در packet جمع کنیم؟
یک packet self-contained به مدل یا بازبین اجازه می‌دهد بدون جست‌وجو در سامانه‌ها تصمیم بگیرد و دقیقاً حفظ می‌کند چه evidenceیی در زمان decision برای audit trail در دسترس بوده است.

WorkItem واحد کار در Threada است: یک درخواست ورودی منفرد، از email، chat، document یا form، که به recordی structured و trackable normalize می‌شود. هر WorkItem intent، fieldهای extracted، evidence و history کامل هر decision و action انجام‌شده روی خود را حمل می‌کند.

مترادف‌ها: work item, task record, tracked request, unit of work

WorkItem چه تفاوتی با support ticket دارد؟
ticket معمولاً conversation را track می‌کند. WorkItem خود کار را track می‌کند: intent classified، fieldهای extracted، evidenceی که هر answer را ground می‌کند و actionهای govern شده، همگی end to end auditable.
WorkItem از چه lifecycleی عبور می‌کند؟
Intake درخواست را normalize می‌کند، intent classification آن را route می‌کند، evidence retrieval پاسخ پیشنهادی را ground می‌کند و هر action پیش از resolve و record شدن WorkItem از approval policy عبور می‌کند.

پروتکل Agent2Agent یک استاندارد باز است تا عامل‌های خودمختار یکدیگر را کشف کنند، کارها را مبادله کنند و بیرون از مرزهای سازمانی هماهنگ شوند. این پروتکل تعریف می‌کند یک عامل چگونه قابلیت‌هایش را اعلام می‌کند و عامل دیگر چگونه کاری را تفویض و تا تکمیل دنبال می‌کند.

مترادف‌ها: A2A, agent2agent, agent-to-agent protocol, agent interoperability

A2A چه تفاوتی با MCP دارد؟
MCP یک مدل را به ابزارها و داده‌ها وصل می‌کند. A2A عامل‌ها را به یکدیگر وصل می‌کند و تعریف می‌کند یک عامل چگونه کاری را به عامل دیگر می‌سپارد و وضعیت آن را دنبال می‌کند، نه اینکه مدل چگونه یک ابزار منفرد را فراخوانی کند.
کارهای A2A چگونه دنبال می‌شوند؟
یک کار A2A به یک record کاری tracked نگاشت می‌شود تا lifecycle، شواهد و نتیجه آن درست مانند کاری که از انسان یا فرم آمده قابل حسابرسی باشد.

پیشنهاد اقدام یک پیشنهاد ساختاریافته و قابل بازبینی برای تغییر یک سامانه کسب‌وکار متصل است؛ خودکارسازی آن را ایجاد می‌کند اما هنوز اجرا نشده است. این پیشنهاد سامانه هدف، عملیات و پارامترهای دقیق را نام می‌برد تا یک شخص یا policy بتواند پیش از هر رخدادی آن را تأیید، ویرایش یا رد کند.

مترادف‌ها: proposed action, action suggestion, draft action, pending action

چرا به‌جای اجرای مستقیم، ابتدا اقدام را پیشنهاد کنیم؟
پیشنهاد کردن، intent را از اثر جدا می‌کند. policy تأیید و بازبینان می‌توانند عملیات و پارامترهای دقیق را بررسی کنند و نگذارند یک خطای خودکار به system of record برسد.
پیشنهاد اقدام شامل چه چیزهایی است؟
integration هدف، عملیاتی که باید انجام شود، پارامترهای resolve شده، شواهد پشتیبان و تصمیم policy درباره اینکه پیش از اجرا تأیید لازم است یا نه.

تفویض اختیار به عامل یعنی اعطای کنترل‌شده اختیاری محدود و زمان‌دار به یک عامل AI تا از طرف یک کاربر یا عامل دیگر عمل کند. تفویض دقیقاً مشخص می‌کند کدام قابلیت‌ها، tenantها و اقدام‌ها مجازند، بنابراین عامل زیر حدودی صریح، قابل لغو و قابل حسابرسی کار می‌کند.

مترادف‌ها: delegated authority, scoped delegation, agent authorization, agent grant

دامنه تفویض چه چیزی را تعریف می‌کند؟
قابلیت‌هایی که عامل می‌تواند استفاده کند، tenantی که در آن می‌تواند عمل کند، اقدام‌هایی که می‌تواند پیشنهاد یا اجرا کند و زمان انقضا را تعریف می‌کند؛ بنابراین اختیار محدود، زمان‌دار و قابل لغو می‌ماند.
تفویض چگونه پاسخ‌گو می‌ماند؟
هر اقدام تفویض‌شده هم به عامل و هم به principal تفویض‌کننده نسبت داده می‌شود و در audit trail ثبت می‌گردد؛ اقدام‌های حساس همچنان از policy تأیید عبور می‌کنند.

جداسازی tenant تضمین می‌کند داده و configuration هر مشتری در یک سامانه multi-tenant به‌صورت منطقی جدا و برای tenantهای دیگر غیرقابل دسترس بماند. این جداسازی در هر layer، storage، retrieval و access control، enforce می‌شود تا یک سازمان هرگز کار سازمان دیگر را نبیند یا بر آن اثر نگذارد.

مترادف‌ها: multi-tenant isolation, tenant scoping, data partitioning, tenancy boundary

در هنگام retrieval، جداسازی tenant چگونه enforce می‌شود؟
هر query به tenant درخواست‌کننده scoped می‌شود و محتوای ذخیره‌شده tenant identifier دارد، بنابراین vector و keyword search فقط evidence همان tenant را می‌توانند برگردانند.
آیا isolation فقط درباره data است؟
نه. configuration، policy، embeddingها و audit logها را هم پوشش می‌دهد، تا هیچ جنبه‌ای از کار یک tenant حتی روی infrastructure مشترک به دیگری leak نکند.

خودکارسازی intake فرایند تبدیل درخواست‌های ورودی unstructured به recordهای structured و machine-readable بدون ورود دستی داده است. درخواست را classify می‌کند، fieldهای مهم را extract می‌کند و نتیجه را به workflow می‌فرستد تا کار به‌صورت سازگار پاسخ داده یا action شود.

مترادف‌ها: request intake, automated triage, intake processing, request normalization

چه نوع intakeهایی می‌توانند خودکار شوند؟
email، chat message، web form، uploaded document و recordهای synced از سامانه‌های متصل همگی می‌توانند به همان شکل structured برای handling downstream normalize شوند.
آیا خودکارسازی intake جای انسان را می‌گیرد؟
نه. بار data entry و triage دستی را حذف می‌کند تا انسان‌ها روی exceptionهای judgment-heavy، approvalها و تصمیم‌های high-riskی تمرکز کنند که policy به آنها route می‌کند.

طبقه‌بندی intent مرحله‌ای است که مشخص می‌کند یک درخواست ورودی واقعاً چه می‌خواهد و متن unstructured را به یک دسته تعریف‌شده از کار map می‌کند. classification دقیق هر WorkItem را به workflow، sourceهای evidence و policy درست route می‌کند و بنیاد automation قابل اعتماد است.

مترادف‌ها: intent detection, request classification, intent recognition, routing classification

چرا intent classification مهم است؟
کل مسیر downstream را تعیین می‌کند. درخواست misclassified evidence غلط را retrieve و policy غلط را apply می‌کند، بنابراین accuracy classification کیفیت همه مراحل بعدی را gate می‌کند.
accuracy classification چگونه اندازه‌گیری می‌شود؟
با evaluation gate روی یک set برچسب‌خورده، tracking precision و recall برای هر intent و پایش confusion میان categoryهای مشابه پیش از live شدن workflow.

گردش‌کار تأیید دنباله‌ای govern شده از checkpointهاست که یک اقدام پیشنهادی باید پیش از اجرا از آنها عبور کند. هر مرحله تصمیم را بر اساس ریسک، نقش یا policy به بازبین درست می‌رساند و ثبت می‌کند چه کسی چه چیزی را تأیید کرده تا نتیجه کاملاً پاسخ‌گو باشد.

مترادف‌ها: approval flow, review workflow, authorization workflow, sign-off process

چه چیزی می‌تواند نیاز به تأیید را فعال کند؟
نیازها می‌توانند بر اساس workflow، channel، کلاس ریسک، آستانه مالی یا نوع اقدام اعمال شوند؛ بنابراین فقط مرحله‌هایی که واقعاً نیاز به نظارت دارند برای بازبین متوقف می‌شوند.
گردش‌کار تأیید چگونه قابل حسابرسی می‌ماند؟
هر درخواست، تأیید، ویرایش و رد با actor و timestamp ثبت می‌شود و trail انتها به انتهایی می‌سازد که ثابت می‌کند هر اقدام govern شده را چه کسی مجاز کرده است.

نقض SLA زمانی رخ می‌دهد که کار تعهدی تعریف‌شده در service-level agreement، مانند deadline پاسخ یا حل، را از دست بدهد. تشخیص و escalation خودکار breachها accountability را visible نگه می‌دارد و مطمئن می‌کند کار در معرض ریسک پیش از از دست رفتن تعهد به افراد درست برسد.

مترادف‌ها: service level breach, SLA violation, missed SLA, deadline breach

نقض SLA چگونه خودکار تشخیص داده می‌شود؟
هر WorkItem timerهای تعهد خودش را دارد و سامانه elapsed time را با thresholdها می‌سنجد، با نزدیک شدن deadline escalation ایجاد می‌کند و اگر missed شود breach را ثبت می‌کند.
وقتی breach نزدیک است چه می‌شود؟
Policy می‌تواند WorkItem را escalate کند، به ownerها notify کند یا queue را reprioritize کند تا توجه پیش از missed شدن واقعی تعهد به کار at-risk منتقل شود.