Skip to content
Browse docs

Glossary

Agent — The lightweight software Vigil deploys into your AWS, Azure, or GCP account to collect metrics, inventory, cost, and security data. Uses keyless, least-privilege access.

Agentless — A connection that uses a scoped API token or admin-consented app instead of deployed software. Used for DigitalOcean, Microsoft 365, and Google Workspace.

Asset — A monitored cloud resource (e.g. a compute instance, database, load balancer, bucket). Your asset count determines your tier.

CIS Benchmark — Center for Internet Security configuration standards. Vigil’s security scans check your environment against them.

Collector — The scheduled part of the agent (roughly hourly) that discovers resources and gathers cost and inventory data.

DORA metrics — Four measures of software delivery performance: deployment frequency, lead time for changes, change-failure rate, and mean time to recovery (MTTR).

Finding — A single issue Vigil detects (security, cost, compliance). Has a severity and a status; findings auto-resolve when fixed.

Framework (compliance) — A standard Vigil maps evidence against — SOC2, GDPR, HIPAA, PCI-DSS, ISO 27001.

ISPM — Identity Security Posture Management. The category Access Governance belongs to.

Managed identity — Azure’s keyless identity mechanism; how the Vigil agent authenticates in Azure.

MCSB — Microsoft Cloud Security Benchmark. The security framework Vigil uses for Azure.

Observe vs ManageObserve = the platform, operated by you. Manage = the platform plus dedicated Vigil engineering, on-call, and SLAs.

Security score — A 0–100 summary of your security posture; higher is better.

SRA — AWS Security Reference Architecture. Vigil’s SRA Verify checks your AWS environment against it.

Tenant — Your isolated space on the Vigil platform. Your data is never mixed with another customer’s.

Uptime check — A periodic test that an endpoint (URL) is responding, used for availability monitoring.

User Access Review (UAR) — A periodic check of who has access to what, required by SOC2/ISO. Access Governance can export one as CSV/PDF.

Was this page helpful?

Your response helps us improve this page.