ข้ามไปยังเนื้อหา

อภิธานศัพท์

คำจำกัดความสำหรับคำที่สำคัญเมื่อสร้างระบบ AI work automation ที่รับผิดชอบได้

Agentic operations is the practice of running business operations with AI agents that plan and act — not just answer — under explicit governance. Agents triage intake, retrieve grounded evidence, propose actions, and execute approved ones in real systems, while approvals, policy checks, and an audit trail keep their activity safe. It pairs agent autonomy with operational controls so automation can run in production.

คำพ้องความหมาย: agentic workflow automation, AI operations automation, agent operations, AI ops

How is agentic operations different from a chatbot?
A chatbot answers messages. Agentic operations runs work: agents classify intake, ground answers in cited evidence, and execute governed actions in business systems, with approvals and an audit trail — the unit of value is completed, accountable work.
What keeps agentic operations safe in production?
Scoped credentials bound what agents can touch, policy overlays decide what needs human approval, evaluation gates test behavior before rollout, and every step is recorded — so autonomy never outruns accountability.

AI work automation is the use of AI models to turn unstructured requests — emails, chats, documents, forms — into completed work: grounded answers or actions executed in business systems. Unlike chat assistants, it operates on structured work items with evidence, approvals, and an audit trail, so every outcome is traceable and governed.

คำพ้องความหมาย: AI workflow automation, agentic workflow automation, AI work orchestration, intelligent work automation

How is AI work automation different from an AI chatbot?
A chatbot produces a reply and forgets the exchange. AI work automation converts each request into a structured work item, grounds answers in cited evidence, routes proposed actions through approvals, and records the outcome — the unit of value is completed work, not a message.
How does it relate to agentic workflow automation?
They describe the same category from different angles. Agentic framing emphasizes the model planning and acting; work-automation framing emphasizes the governance around it — structured intake, evidence, approval gates, and an audit trail that makes agent activity safe to run in production.

การปรับให้เหมาะกับระบบตอบคำถามคือการจัดโครงสร้างเนื้อหาเพื่อให้ระบบตอบคำถาม AI และผู้ช่วยแชตค้นหา อ้างอิง และสรุปได้อย่างถูกต้อง ในขณะที่ SEO มุ่งให้ลิงก์ติดอันดับ AEO มุ่งที่คำตอบที่ถูกสังเคราะห์ขึ้นเอง โดยปรับให้มีนิยามชัดเจน ข้อมูลมีโครงสร้าง และไฟล์ต้นทางอ่านได้ด้วยเครื่อง

คำพ้องความหมาย: AEO, generative engine optimization, GEO, การปรับแต่งการค้นหา AI

AEO ต่างจาก SEO อย่างไร?
SEO ปรับเพื่อให้หน้าเป็นลิงก์ที่คลิกได้บนหน้าผลลัพธ์ ส่วน AEO ปรับเพื่อให้ถูกเลือก อ้างอิง และให้เครดิตในคำตอบที่ AI สร้าง ซึ่งให้คุณค่ากับนิยามที่แม่นยำ ข้อมูลมีโครงสร้าง และฟีดที่เครื่องอ่านได้สะอาด
สัญญาณใดช่วยให้ระบบตอบคำถามอ้างอิงหน้าเว็บได้?
การเขียนโดยเริ่มจากนิยาม ข้อมูลโครงสร้าง schema.org ที่ถูกต้อง ดัชนี llms.txt, FAQ markup และ URL canonical ที่เสถียร ช่วยให้ระบบตอบคำถามดึงและให้เครดิตเนื้อหาได้ง่ายขึ้น

An audit trail is the tamper-evident record of everything that happened to a piece of work: what arrived, what the AI extracted and proposed, which evidence grounded each answer, who approved what, and which actions executed. It lets teams reconstruct and prove any outcome end to end — essential for compliance, debugging, and trust in automation.

คำพ้องความหมาย: audit log, activity log, execution history, decision log

What does an audit trail capture in AI work automation?
Each event in a work item's life: intake and its source channel, extracted fields, retrieved evidence and citations, the AI's proposals, every approval or rejection with actor and timestamp, and the executed actions with their results.
Why does an audit trail matter for AI specifically?
AI decisions are probabilistic, so accountability has to come from the record rather than the rule. A complete trail shows what the model saw, what it proposed, and who authorized the outcome — turning otherwise opaque automation into something reviewable and defensible.

Automated resolution is when an AI work platform completes a request end to end — understanding the intake, grounding an answer in cited evidence, or executing a governed action — without a person doing the work, while still leaving a full record. It is measured honestly: only requests closed correctly and within policy count, and anything uncertain is escalated rather than force-closed.

คำพ้องความหมาย: auto-resolution, automated containment, self-service resolution, deflection

How is automated resolution measured honestly?
Only requests resolved correctly, within policy, and without human intervention count toward the rate. Uncertain or low-confidence cases are escalated, not force-closed, so the metric reflects real outcomes instead of inflated deflection.
What happens when a request can't be resolved automatically?
It becomes a WorkItem routed to the right owner with full context — the intake, evidence, and reasoning attached — so a person picks up a complete case rather than starting from scratch.

The CAIQ (Consensus Assessments Initiative Questionnaire) is a cloud-security self-assessment from the Cloud Security Alliance (CSA), aligned to the Cloud Controls Matrix (CCM). A provider answers each control question — typically yes/no with notes — to document its security posture, and CAIQ submissions can be published in the CSA STAR registry.

คำพ้องความหมาย: Consensus Assessments Initiative Questionnaire, CSA CAIQ, CAIQ questionnaire

How does CAIQ relate to the Cloud Controls Matrix (CCM)?
The CAIQ is the question form of the CCM: each CAIQ question maps to a CCM control, so answering the CAIQ documents how a provider meets the CCM's cloud-security control domains. They are maintained together by the Cloud Security Alliance.
What is the CSA STAR registry?
STAR (Security, Trust, Assurance and Risk) is the CSA's public registry where cloud providers can publish completed CAIQ self-assessments (and higher assurance levels). A published CAIQ lets customers review a provider's posture without sending a bespoke questionnaire.

Chunking คือกระบวนการแบ่งเอกสารต้นทางเป็นหน่วย retrieval ที่เล็กลงก่อนนำไปทำ embedding ขนาด chunk และกลยุทธ์การกำหนดขอบเขตเป็นตัวกำหนดว่า retriever จะค้นหาข้อเท็จจริงที่เกี่ยวข้องได้แม่นเพียงใด โดยสมดุล recall, precision และต้นทุน embedding ทั่วฐานความรู้

คำพ้องความหมาย: text chunking, การแบ่งเอกสาร, การแบ่ง passage, กลยุทธ์ chunk

chunk ที่ดีเป็นอย่างไร?
chunk ที่ดีต้องสมบูรณ์ในเชิงความหมาย มีขนาดที่ไม่ทำให้ข้อเท็จจริงเดียวถูกตัดข้ามขอบเขต และมี metadata เสถียรเพื่อให้กรอง รีเฟรช และอ้างอิงได้อย่างน่าเชื่อถือ
chunking ส่งผลต่อคุณภาพคำตอบอย่างไร?
chunk ที่ใหญ่เกินไปทำให้ความเกี่ยวข้องเจือจางและเปลือง token ส่วน chunk ที่เล็กเกินไปทำให้บริบทแตกและความหมายหายไป การเลือกขอบเขตส่งผลโดยตรงต่อ recall และความมีหลักฐานรองรับของคำตอบที่สร้างขึ้น

Embedding คือเวกเตอร์ตัวเลขที่แทนความหมายของข้อความ รูปภาพ หรือข้อมูลอื่นในพื้นที่มิติสูง รายการที่มีความหมายคล้ายกันจะสร้างเวกเตอร์ที่อยู่ใกล้กัน ทำให้ระบบเปรียบเทียบ จัดกลุ่ม และดึงเนื้อหาตามความคล้ายเชิงความหมายได้ แทนที่จะพึ่งการตรงกันแบบคำต่อคำ

คำพ้องความหมาย: vector embedding, text embedding, semantic vector, dense representation

ทำไมเวอร์ชันของ embedding model จึงสำคัญ?
เวกเตอร์จากโมเดลต่างกันเปรียบเทียบกันไม่ได้ การเก็บเวอร์ชันโมเดลไว้กับแต่ละ embedding ช่วยตรวจจับ drift และ reindex ได้อย่างปลอดภัยเมื่ออัปเกรด embedding model
embedding ย้อนกลับเป็นข้อความต้นฉบับได้หรือไม่?
ไม่ตรงทั้งหมด แต่ embedding อาจรั่วไหลข้อมูลอ่อนไหวได้ จึงควรสืบทอด tenant isolation และ access control เดียวกับเนื้อหาต้นทางที่มันแทน

An evaluation gate is an automated quality checkpoint that scores an AI workflow against curated test cases before a change ships. Prompts, retrieval settings, or pack updates must pass thresholds for accuracy, grounding, and safety; failing changes are blocked from release. Gates turn AI quality from a hope into an enforced, repeatable engineering practice.

คำพ้องความหมาย: eval gate, quality gate, release gate, evaluation harness

What does an evaluation gate measure?
Typically answer accuracy against expected outputs, grounding quality (are claims backed by retrieved evidence), intent-classification correctness, and safety checks — each scored over a curated dataset that reflects real production traffic.
When do evaluation gates run?
Before a configuration change is released: editing a prompt, swapping a model, tuning retrieval, or updating a pack triggers the evaluation suite, and the change only promotes if scores clear the configured thresholds.

A governed action is a system operation proposed by AI but executed only under explicit controls — scoped credentials, policy checks, and approval gates. Instead of letting a model act directly, the platform records the proposal, routes it for review when policy requires, and executes it with full attribution, so automation never outruns accountability.

คำพ้องความหมาย: governed execution, approval-gated action, policy-gated action, controlled action

What controls apply to a governed action?
Scoped connector credentials limit what the action can touch, policy rules decide whether it needs human approval, and execution is attributed and logged — so each action carries who proposed it, who approved it, and exactly what changed.
Do all governed actions require human approval?
No. Policies can auto-approve low-risk, well-grounded actions and reserve human review for sensitive ones — by action type, monetary threshold, or risk class — so oversight concentrates where it matters.

Grounding คือการจำกัดผลลัพธ์ของ AI model ให้อยู่กับหลักฐานแหล่งที่มาที่ตรวจสอบได้ แทนที่จะพึ่งพา parametric memory ของโมเดล คำตอบที่ grounded จะได้รับการสนับสนุนจาก passage ที่ดึงมา ซึ่งอ้างอิงและตรวจสอบได้ เป็นแนวป้องกันหลักต่อคำตอบที่แต่งขึ้นหรือผิดอย่างมั่นใจ

คำพ้องความหมาย: grounded AI, evidence grounding, source grounding, factual grounding

grounding ถูกบังคับใช้จริงอย่างไร?
retrieval ส่งเฉพาะ passage แหล่งที่มาที่เกี่ยวข้องให้โมเดล prompt สั่งให้ตอบจากหลักฐานนั้น และขั้นตอน verification ปฏิเสธ claim ที่ไม่มี citation สนับสนุน
เกิดอะไรขึ้นเมื่อไม่มีหลักฐานสำหรับ grounding?
ระบบ grounded ที่ออกแบบดีจะปฏิเสธการตอบหรือ escalate ไปยังคน แทนที่จะสร้างคำตอบขึ้นเอง โดยแสดงช่องว่างอย่างชัดเจนแทนการเดาอย่างมั่นใจ

Hallucination คือผลลัพธ์จาก language model ที่มั่นใจแต่ไม่มีหลักฐานรองรับหรือถูกแต่งขึ้น เป็น claim ที่ฟังดูเป็นไปได้แต่ไม่มีฐานในหลักฐานที่ให้มาหรือความจริง Hallucination เป็นความเสี่ยงหลักในการทำให้งานความรู้เป็นอัตโนมัติ และ grounding ด้วยหลักฐานที่อ้างอิงได้คือวิธีลดความเสี่ยงสำคัญ

คำพ้องความหมาย: AI hallucination, การแต่งข้อมูล, confabulation, ผลลัพธ์ที่ไม่มี grounding

ทำไม language model จึง hallucinate?
โมเดลทำนายข้อความที่น่าจะเป็น ไม่ใช่ข้อเท็จจริงที่ตรวจสอบแล้ว เมื่อไม่มีหลักฐานที่ดึงมาเพื่อจำกัด มันจะเติมช่องว่างด้วยข้อความที่ดูเป็นไปได้ทางสถิติแต่ยังไม่ถูกยืนยัน
จะลด hallucination ได้อย่างไร?
ground คำตอบด้วยแหล่งข้อมูลที่ดึงมา บังคับใช้ citation ตรวจสอบ claim กับหลักฐาน และส่งกรณีความมั่นใจต่ำหรือไม่มีหลักฐานไปยังคนแทนที่จะส่งคำเดากลับมา

Human-in-the-loop คือรูปแบบการออกแบบที่ให้คนตรวจทาน อนุมัติ หรือแก้ไขข้อเสนอของระบบ AI ก่อนที่ข้อเสนอนั้นจะมีผลจริง รูปแบบนี้รักษาการตัดสินใจของมนุษย์ไว้บนเส้นทางสำคัญสำหรับการตัดสินใจความเสี่ยงสูงหรือความมั่นใจต่ำ ขณะที่ automation จัดการงานประจำจำนวนมาก

คำพ้องความหมาย: HITL, human in the loop, การกำกับดูแลโดยมนุษย์, การตรวจทานโดยมนุษย์

เมื่อใดขั้นตอนควรเป็น human-in-the-loop?
เมื่อการตัดสินใจมีความเสี่ยงสูง ย้อนกลับไม่ได้ ความมั่นใจต่ำ หรือถูกกำกับด้วยนโยบาย ขั้นตอนประจำที่มีหลักฐานดีและความเสี่ยงต่ำสามารถทำอัตโนมัติ โดยให้มนุษย์ตรวจทานข้อยกเว้น
ต่างจาก automation เต็มรูปแบบอย่างไร?
automation เต็มรูปแบบดำเนินการโดยไม่มีการตรวจทาน Human-in-the-loop ใส่จุดตรวจที่ชัดเจนให้คนอนุมัติ แก้ไข หรือปฏิเสธข้อเสนอ เพื่อรักษาความรับผิดชอบต่อผลลัพธ์อ่อนไหว

Hybrid retrieval ผสาน semantic vector search กับ lexical keyword search เพื่อดึง passage ที่เกี่ยวข้อง Vector search จับความหมายและการถอดความ ส่วน keyword search จับคำและ identifier ที่ตรงเป๊ะ และขั้นตอน fusion รวมชุดผลลัพธ์ทั้งสองเพื่อไม่ให้พลาดทั้ง token ที่เฉพาะเจาะจงและการตรงกันเชิงแนวคิด

คำพ้องความหมาย: hybrid search, dense-sparse retrieval, vector plus keyword search, fusion retrieval

ทำไมต้องรวม vector search กับ keyword search?
Vector search อาจพลาดคำเฉพาะที่หายาก เช่น SKU หรือ error code ส่วน keyword search พลาดการถอดความ Fusion ช่วยดึงจุดแข็งของทั้งสองกลับมาและเพิ่ม recall ใน query จริง
ชุดผลลัพธ์สองชุดถูกผสานอย่างไร?
วิธี fusion เช่น reciprocal rank fusion หรือ weighted score blend จะ rerank ผู้สมัครที่รวมแล้ว และมักตามด้วย cross-encoder reranker เพื่อ precision ขั้นสุดท้าย

Intake automation คือกระบวนการเปลี่ยนคำขอขาเข้าที่ไม่มีโครงสร้างให้เป็น record ที่มีโครงสร้างและเครื่องอ่านได้ โดยไม่ต้องป้อนข้อมูลด้วยมือ ระบบจะจำแนกคำขอ ดึงฟิลด์สำคัญ และ route ผลลัพธ์เข้าสู่ workflow เพื่อให้งานถูกตอบหรือดำเนินการได้อย่างสม่ำเสมอ

คำพ้องความหมาย: request intake, automated triage, intake processing, request normalization

intake แบบใดทำอัตโนมัติได้?
อีเมล ข้อความแชต เว็บฟอร์ม เอกสารที่อัปโหลด และ record ที่ซิงก์จากระบบที่เชื่อมต่อ ล้วน normalize เป็นรูปแบบมีโครงสร้างเดียวกันสำหรับการจัดการ downstream ได้
intake automation แทนที่คนหรือไม่?
ไม่ มันลดภาระการป้อนข้อมูลและ triage ด้วยมือ เพื่อให้คนมุ่งกับข้อยกเว้นที่ต้องใช้วิจารณญาณ การอนุมัติ และการตัดสินใจความเสี่ยงสูงที่นโยบาย route ไปหา

Model Context Protocol เป็นมาตรฐานเปิดที่ให้ผู้ช่วย AI เชื่อมต่อกับเครื่องมือและแหล่งข้อมูลภายนอกผ่านอินเทอร์เฟซเดียวกัน MCP server เปิดเผยเครื่องมือและทรัพยากรแบบ typed ที่ model client ค้นพบและเรียกใช้ได้ ทำให้เพิ่มความสามารถได้โดยไม่ต้องเขียนโค้ดเฉพาะต่อ integration

คำพ้องความหมาย: MCP, model context protocol, MCP server, tool protocol

MCP server เปิดเผยอะไร?
เครื่องมือแบบ typed ที่โมเดลเรียกใช้ได้ และ resource ที่อ่านได้ โดยแต่ละรายการมี schema และ annotation เพื่อให้ client ค้นพบความสามารถและเรียกใช้อย่างปลอดภัย
ทำไม MCP จึงสำคัญต่อ automation ที่มี governance?
มันให้วิธีมาตรฐานแบบอธิบายด้วย schema แก่ผู้ช่วยภายนอกในการทำงานบนแพลตฟอร์ม ทำให้ tool call ถูกตรวจสอบ จำกัด tenant และ route ผ่านนโยบายอนุมัติเดียวกับการกระทำอื่นได้

A policy overlay is the layer of governance rules a platform applies on top of AI work — deciding what an agent may answer or do, when human approval is required, and which guardrails bind each action. Policies are versioned and evaluated at runtime against each WorkItem, so the same request is handled consistently and every decision traces back to the policy version that produced it.

คำพ้องความหมาย: policy layer, governance overlay, policy controls, guardrail policy

What does a policy overlay control?
It controls what an AI agent is allowed to answer or execute: which actions are auto-approved, which require human approval, what grounding or evidence is required, and which connectors and data a WorkItem may touch — all evaluated per request rather than hardcoded.
Why version policies instead of hardcoding rules?
Versioned policies make governance auditable and reversible. Each decision records the policy version that produced it, so you can see why an action was allowed or held, roll a change back, and prove consistent handling during a review.

Questionnaire automation is the use of AI to draft answers to recurring questionnaires — security questionnaires, SIG and CAIQ workbooks, RFP sections, and due-diligence forms — from an organization's own approved sources. Done accountably, each questionnaire becomes a tracked work item whose answers are grounded in cited evidence, routed for approval, and exported with an audit trail.

คำพ้องความหมาย: security questionnaire automation, RFP response automation, AI questionnaire response

How is questionnaire automation different from a chatbot writing answers?
A chatbot generates plausible text and forgets it. Accountable questionnaire automation turns each questionnaire into a structured work item, draws answers from your approved sources with citations, routes sensitive answers for approval, and records who answered what and on what basis — so the output is defensible, not just fluent.
How does questionnaire automation stay accurate?
Answers are grounded in retrieval over sources you approve and cite the evidence behind each one. When the evidence does not support an answer, a well-designed system flags it for a human instead of guessing, and sensitive answers wait for a named owner before they are sent.

Retrieval-augmented generation เป็นเทคนิคที่ ground ผลลัพธ์ของ language model ไว้กับเอกสารต้นทางที่ดึงมา แทนที่จะพึ่ง parametric memory อย่างเดียว ระบบจะดึง passage ที่เกี่ยวข้องจากฐานความรู้ ส่งเป็นบริบท และขอให้โมเดลตอบโดยใช้เฉพาะหลักฐานนั้น

คำพ้องความหมาย: RAG, retrieval augmented generation, grounded generation, context augmentation

ทำไมใช้ RAG แทน fine-tuning?
RAG เก็บความรู้ไว้ใน store ภายนอกที่อัปเดตได้ทันที ทำให้คำตอบเป็นปัจจุบันและทุก claim สืบกลับถึงแหล่งที่มาได้ Fine-tuning ฝังความรู้ไว้ใน weight ซึ่งรีเฟรชช้ากว่าและให้ที่มายากกว่า
pipeline RAG มีอะไรบ้าง?
โดยทั่วไปมี ingestion และ chunking, embedding, index สำหรับ vector หรือ hybrid search, retriever และขั้นตอน generation ที่ condition โมเดลด้วย passage ที่ดึงมาและคืนหลักฐานอ้างอิง

A security questionnaire is a structured set of questions one organization sends another — usually a customer to a vendor — to assess how it protects data and systems. Common formats include the SIG, CAIQ, RFP security sections, and custom spreadsheets, and answers must be consistent, evidence-backed, and reviewed before they are returned.

คำพ้องความหมาย: vendor security questionnaire, third-party security questionnaire, security assessment questionnaire, due diligence questionnaire

What formats do security questionnaires come in?
Common formats include standardized frameworks like the SIG (Standardized Information Gathering) and CAIQ (Consensus Assessments Initiative Questionnaire), the security section of an RFP, and custom spreadsheets a customer sends. The underlying questions overlap heavily, which is why past answers are the main source for new ones.
How do teams answer security questionnaires efficiently?
The fastest, safest approach reuses approved prior answers and source documents — previous questionnaires, security policies, SOC 2 reports, DPAs — retrieved and cited per answer, with sensitive answers routed to a named owner for approval before the completed workbook is returned.

The SIG (Standardized Information Gathering) questionnaire is a standardized third-party risk assessment maintained by Shared Assessments. It provides a common library of questions across security, privacy, and resilience domains, and ships in scoped variants (such as SIG Core and SIG Lite) so assessors can right-size the depth of a vendor review.

คำพ้องความหมาย: SIG questionnaire, Standardized Information Gathering questionnaire, Shared Assessments SIG

What is the difference between SIG Core and SIG Lite?
SIG Lite is a shorter, higher-level set for lower-risk vendors or a first pass; SIG Core is the deeper, more comprehensive set for higher-risk or in-depth reviews. Both draw from the same Shared Assessments question library, so answers map across variants.
Who maintains the SIG?
The SIG is maintained by Shared Assessments, an industry member organization, and is updated periodically to track regulations and control frameworks. It is widely used so vendors can reuse consistent answers across many customers.

SSO รวมศูนย์การลงชื่อเข้าใช้และช่วยให้ IdP บังคับใช้นโยบาย เช่น MFA และการเข้าถึงแบบมีเงื่อนไข การเข้าถึง Threada ยังต้องใช้ผู้ใช้และบทบาทผู้เช่าที่มีอยู่ซึ่ง Admin เป็นผู้จัดการ

คำพ้องความหมาย: saml, federated login, enterprise sso

ทำไม SSO สำคัญต่อแพลตฟอร์ม shell-and-pack?
SSO รวมศูนย์การลงชื่อเข้าใช้และช่วยให้ IdP บังคับใช้นโยบาย เช่น MFA และการเข้าถึงแบบมีเงื่อนไข การเข้าถึง Threada ยังต้องใช้ผู้ใช้และบทบาทผู้เช่าที่มีอยู่ซึ่ง Admin เป็นผู้จัดการ

Tenant isolation คือการรับประกันว่าข้อมูลและการตั้งค่าของลูกค้าแต่ละรายในระบบ multi-tenant จะถูกแยกเชิงตรรกะและไม่เข้าถึงได้โดย tenant อื่น การแยกนี้ถูกบังคับใช้ทุกชั้น ทั้ง storage, retrieval และ access control เพื่อให้องค์กรหนึ่งไม่สามารถเห็นหรือมีผลต่อการทำงานของอีกองค์กรได้

คำพ้องความหมาย: multi-tenant isolation, tenant scoping, data partitioning, tenancy boundary

tenant isolation ถูกบังคับใช้ระหว่าง retrieval อย่างไร?
ทุก query ถูก scoped ไปยัง tenant ที่ร้องขอ และเนื้อหาที่เก็บไว้มี tenant identifier เพื่อให้ vector และ keyword search คืนได้เฉพาะหลักฐานของ tenant นั้นเอง
isolation เกี่ยวกับข้อมูลอย่างเดียวหรือไม่?
ไม่ มันครอบคลุม configuration, policy, embeddings และ audit logs ด้วย เพื่อไม่ให้ส่วนใดของงาน tenant หนึ่งรั่วไปยังอีก tenant แม้ใช้โครงสร้างพื้นฐานร่วมกัน

A vendor security review is the process by which an organization evaluates the security and compliance posture of a third-party supplier before onboarding and periodically afterward. It typically combines a security questionnaire, evidence collection (SOC 2, ISO, pen-test summaries), and a documented risk decision with an owner and an audit trail.

คำพ้องความหมาย: vendor security assessment, third-party security review, third-party risk assessment, vendor risk review

What is the difference between a vendor security review and a security questionnaire?
The questionnaire is one input; the review is the whole process. A vendor security review gathers questionnaire responses plus supporting evidence, assesses residual risk, records a decision and its owner, and schedules re-review — so the questionnaire is the data, the review is the governed workflow around it.
How often should vendor security reviews happen?
Most programs review a vendor at onboarding and then on a risk-based cadence — annually for higher-risk vendors, or when scope, data access, or the vendor's controls change. Keeping each review as an auditable record makes the next cycle a re-check rather than a restart.

Vertical pack คือ configuration แบบแพ็กที่ปรับแพลตฟอร์มให้เข้ากับโดเมนงานเฉพาะ เช่น intents, extraction fields, evidence sources, policies และ actions Packs ช่วยให้ทีมเปิด workflow ที่เจาะจง เช่น IT access หรือ vendor security ได้โดยไม่ต้องสร้าง engine พื้นฐานใหม่

คำพ้องความหมาย: pack, vertical pack, solution pack, domain pack

vertical pack ตั้งค่าอะไร?
intents ที่รับรู้ fields ที่ extract หลักฐานที่ใช้ ground คำตอบ policies การอนุมัติที่บังคับใช้ และ actions ที่มี governance ซึ่งเสนอได้สำหรับโดเมนงานนั้น
ปรับแต่ง packs ได้หรือไม่?
ได้ Pack เป็น configuration ตั้งต้นที่ทีมปรับใน Studio โดยปรับ intents, prompts, evidence sources และ policies เพื่อให้เข้ากับกระบวนการจริงของตน

WorkItem คือหน่วยงานใน Threada: คำขอขาเข้าเดียวจากอีเมล แชต เอกสาร หรือฟอร์ม ที่ถูก normalize เป็น record มีโครงสร้างและติดตามได้ WorkItem แต่ละรายการมี intent, fields ที่ extract, หลักฐาน และประวัติครบถ้วนของทุกการตัดสินใจและการกระทำที่เกิดขึ้นกับมัน

คำพ้องความหมาย: work item, task record, tracked request, unit of work

WorkItem ต่างจาก support ticket อย่างไร?
ticket มักติดตามบทสนทนา WorkItem ติดตามตัวงานเอง: intent ที่ classify แล้ว fields ที่ extract หลักฐานที่ ground คำตอบ และ actions ที่มี governance ทั้งหมดตรวจสอบได้ end-to-end
WorkItem เคลื่อนผ่าน lifecycle ใด?
Intake normalize คำขอ intent classification route งาน evidence retrieval ground คำตอบที่เสนอ และ action ใด ๆ ผ่านนโยบายอนุมัติก่อนที่ WorkItem จะถูก resolve และบันทึก

การจำแนก intent คือขั้นตอนที่ระบุว่าคำขอขาเข้ากำลังขออะไรจริง ๆ โดยแมปข้อความไร้โครงสร้างเข้ากับหมวดงานที่กำหนดไว้ การจำแนกที่แม่นยำจะ route แต่ละ WorkItem ไปยัง workflow แหล่งหลักฐาน และนโยบายที่ถูกต้อง จึงเป็นฐานของ automation ที่เชื่อถือได้

คำพ้องความหมาย: intent detection, request classification, intent recognition, routing classification

ทำไมการจำแนก intent จึงสำคัญ?
มันตัดสินเส้นทาง downstream ทั้งหมด คำขอที่จำแนกผิดจะดึงหลักฐานผิดและใช้นโยบายผิด ดังนั้นความแม่นยำของ classification จึงเป็นด่านของคุณภาพทุกอย่างที่ตามมา
วัดความแม่นยำของ classification อย่างไร?
ผ่าน evaluation gate บนชุดข้อมูลที่ติดป้ายกำกับ โดยติดตาม precision และ recall ต่อ intent และเฝ้าดูความสับสนระหว่างหมวดที่คล้ายกันก่อน workflow ขึ้น live

การมอบหมายสิทธิ์ให้เอเจนต์คือการให้สิทธิ์แบบควบคุม มีขอบเขต และมีระยะเวลาแก่ AI agent เพื่อดำเนินการแทนผู้ใช้หรือเอเจนต์อีกตัวหนึ่ง การมอบหมายระบุอย่างชัดเจนว่าความสามารถ tenant และการกระทำใดได้รับอนุญาต เพื่อให้เอเจนต์ทำงานภายใต้ขอบเขตที่ชัดเจน เพิกถอนได้ และตรวจสอบย้อนหลังได้

คำพ้องความหมาย: สิทธิ์ที่มอบหมาย, การมอบหมายแบบมีขอบเขต, การอนุญาตเอเจนต์, สิทธิ์เอเจนต์

ขอบเขตของการมอบหมายกำหนดอะไร?
กำหนดความสามารถที่เอเจนต์ใช้ได้ tenant ที่เอเจนต์ทำงานได้ การกระทำที่เสนอหรือดำเนินการได้ และเวลาหมดอายุ เพื่อให้สิทธิ์แคบ มีระยะเวลา และเพิกถอนได้
การมอบหมายยังรับผิดชอบตรวจสอบได้อย่างไร?
ทุกการกระทำที่ถูกมอบหมายจะถูกระบุทั้งตัวเอเจนต์และ principal ผู้มอบหมาย และบันทึกใน audit trail โดยการกระทำอ่อนไหวยังต้องผ่านนโยบายอนุมัติ

การละเมิด SLA เกิดขึ้นเมื่องานพลาดข้อผูกพันที่กำหนดใน service-level agreement เช่นกำหนดเวลาตอบกลับหรือแก้ไข การตรวจจับและ escalate การละเมิดโดยอัตโนมัติทำให้ความรับผิดชอบมองเห็นได้ และทำให้งานที่มีความเสี่ยงไปถึงคนที่เหมาะสมก่อนพลาดข้อผูกพัน

คำพ้องความหมาย: service level breach, SLA violation, missed SLA, deadline breach

ตรวจจับการละเมิด SLA อัตโนมัติได้อย่างไร?
แต่ละ WorkItem มี timer ของข้อผูกพัน ระบบจะดูเวลาที่ผ่านไปเทียบกับ threshold ยก escalation เมื่อ deadline ใกล้เข้ามา และบันทึก breach หากพลาด
เกิดอะไรขึ้นเมื่อ breach ใกล้จะเกิด?
นโยบายสามารถ escalate WorkItem แจ้ง owner หรือจัดลำดับคิวใหม่ เพื่อให้ความสนใจย้ายไปยังงานเสี่ยงก่อนที่ข้อผูกพันจะถูกพลาดจริง

การอ้างอิงหลักฐานคือการแนบแหล่งอ้างอิงที่ตรวจสอบได้กับทุก claim ที่ระบบ AI สร้างขึ้น แต่ละ passage ที่ถูกอ้างอิงจะลิงก์กลับไปยังเอกสาร record หรือ knowledge asset ที่เป็นที่มา เพื่อให้คนยืนยันได้ว่าคำตอบมีหลักฐานรองรับก่อนจะเชื่อหรือดำเนินการตาม

คำพ้องความหมาย: citation, source attribution, การเชื่อมโยงหลักฐาน, ที่มาของคำตอบ

citation ควรมีอะไรบ้าง?
อย่างน้อยต้องมีตัวระบุแหล่งที่มาและ passage ที่ใช้จริง โดยควรมีลิงก์เสถียรและ timestamp เพื่อให้ reviewer ยืนยันได้ว่าหลักฐานยังเป็นปัจจุบันเมื่อสร้างคำตอบ
ทำไม citation จึงจำเป็นต่อ automation ที่มี governance?
citation ทำให้คำตอบตรวจสอบได้ หากไม่มี citation คำตอบอัตโนมัติจะรับผิดชอบตรวจสอบไม่ได้ แต่เมื่อมี citation reviewer สามารถตรวจสอบ grounding และ audit trail สามารถพิสูจน์ได้ว่าหลักฐานใดขับเคลื่อนการตัดสินใจ

ข้อเสนอการดำเนินการคือคำแนะนำแบบมีโครงสร้างและตรวจทานได้สำหรับเปลี่ยนระบบธุรกิจที่เชื่อมต่ออยู่ ซึ่งสร้างโดยระบบอัตโนมัติแต่ยังไม่ถูกดำเนินการจริง ข้อเสนอนี้ระบุระบบเป้าหมาย การทำงาน และพารามิเตอร์ที่แน่นอน เพื่อให้บุคคลหรือนโยบายอนุมัติ แก้ไข หรือปฏิเสธได้ก่อนเกิดผลใด ๆ

คำพ้องความหมาย: การดำเนินการที่เสนอ, คำแนะนำการดำเนินการ, ร่างการดำเนินการ, การดำเนินการที่รอดำเนินการ

ทำไมต้องเสนอการดำเนินการก่อน แทนที่จะดำเนินการทันที?
การเสนอก่อนแยกเจตนาออกจากผลลัพธ์ ทำให้นโยบายอนุมัติและผู้ตรวจทานตรวจดูการทำงานและพารามิเตอร์ที่แม่นยำได้ ป้องกันไม่ให้ความผิดพลาดจากระบบอัตโนมัติไปถึง system of record
ข้อเสนอการดำเนินการมีอะไรบ้าง?
การเชื่อมต่อเป้าหมาย การทำงานที่จะทำ พารามิเตอร์ที่แก้ครบแล้ว หลักฐานสนับสนุน และการตัดสินใจตามนโยบายว่าต้องอนุมัติก่อนดำเนินการหรือไม่

โปรโตคอล Agent2Agent เป็นมาตรฐานเปิดที่ช่วยให้เอเจนต์อัตโนมัติค้นพบกัน แลกเปลี่ยนงาน และประสานงานข้ามขอบเขตองค์กรได้ โปรโตคอลนี้กำหนดว่าเอเจนต์ประกาศความสามารถของตนอย่างไร และเอเจนต์อีกตัวหนึ่งมอบหมายงานและติดตามจนเสร็จอย่างไร

คำพ้องความหมาย: A2A, agent2agent, โปรโตคอลเอเจนต์ถึงเอเจนต์, การทำงานร่วมกันของเอเจนต์

A2A ต่างจาก MCP อย่างไร?
MCP เชื่อมโมเดลกับเครื่องมือและข้อมูล ส่วน A2A เชื่อมเอเจนต์เข้าหากัน โดยกำหนดว่าเอเจนต์หนึ่งส่งต่องานให้อีกเอเจนต์และติดตามสถานะอย่างไร ไม่ใช่ว่าโมเดลเรียกเครื่องมือเดี่ยวอย่างไร
งาน A2A ถูกติดตามอย่างไร?
งาน A2A ถูกแมปกับบันทึกงานที่ติดตามได้ เพื่อให้ lifecycle หลักฐาน และผลลัพธ์ตรวจสอบย้อนหลังได้ เช่นเดียวกับงานที่เริ่มจากคนหรือฟอร์ม

แพ็กเก็ตงานคือชุดบริบทที่ประกอบรอบ WorkItem เพื่อให้ reasoning และดำเนินการได้: คำขอต้นฉบับ fields ที่ extract หลักฐานที่ดึงมา นโยบายที่ใช้ได้ และ actions ที่เสนอ เป็น briefing ที่ครบถ้วนและพึ่งตัวเองได้สำหรับงานหนึ่งชิ้น

คำพ้องความหมาย: work bundle, context packet, task packet, work context

แพ็กเก็ตงานต่างจาก WorkItem อย่างไร?
WorkItem คือ record ที่ติดตามคำขอเอง ส่วนแพ็กเก็ตงานคือบริบทที่ประกอบขึ้น เช่น evidence, policy และ proposals ที่รวบรวมรอบ record นั้นเพื่อขับเคลื่อนคำตอบหรือ action
ทำไมต้องรวมบริบทเป็น packet?
packet ที่พึ่งตัวเองได้ช่วยให้โมเดลหรือ reviewer ตัดสินใจโดยไม่ต้องไล่ค้นข้ามระบบ และเก็บไว้ชัดเจนว่าหลักฐานใดพร้อมใช้งานในเวลาตัดสินใจสำหรับ audit trail

เวิร์กโฟลว์การอนุมัติคือชุดจุดตรวจแบบมี governance ที่การกระทำที่เสนอจะต้องผ่านก่อนดำเนินการ แต่ละขั้นส่งการตัดสินใจไปยังผู้ตรวจทานที่เหมาะสมตามความเสี่ยง บทบาท หรือนโยบาย พร้อมบันทึกว่าใครอนุมัติอะไร เพื่อให้ผลลัพธ์รับผิดชอบตรวจสอบได้ครบถ้วน

คำพ้องความหมาย: โฟลว์อนุมัติ, เวิร์กโฟลว์ตรวจทาน, เวิร์กโฟลว์อนุญาต, กระบวนการลงนามอนุมัติ

อะไรสามารถทำให้ต้องมีการอนุมัติ?
ข้อกำหนดสามารถใช้ตาม workflow, channel, ระดับความเสี่ยง, เพดานจำนวนเงิน หรือประเภทการกระทำ เพื่อให้เฉพาะขั้นตอนที่ต้องการการกำกับดูแลจริง ๆ เท่านั้นที่หยุดรอผู้ตรวจทาน
เวิร์กโฟลว์การอนุมัติยังตรวจสอบย้อนหลังได้อย่างไร?
ทุกคำขอ การอนุมัติ การแก้ไข และการปฏิเสธถูกบันทึกพร้อม actor และ timestamp สร้างร่องรอย end-to-end ที่พิสูจน์ว่าใครอนุญาตการกระทำที่มี governance แต่ละครั้ง