Skip to main content

Glossary

The core concepts an administrator works with, defined briefly. For how they fit together, see How Cobalt works.
Cobalt’s primitive nouns are capitalized as proper concepts — Agent, Skillset, Skill, Channel, Integration. Sensitivity values are lowercase: standard and elevated.

Agent

The thing employees talk to. An Agent has an identity (name, role, personality, safety boundaries, languages) and a set of tools it can use. Everything else you configure attaches to an Agent.

Skillset

A self-contained domain of custom capability that an Agent owns — a small chapter of related work. A Skillset groups Skills and their configurations, and carries a sensitivity. Use one only when an Integration can’t do the job.

Skill

A single playbook within a Skillset: plain-language instructions for one job, optionally including shell or curl. A Skill has a name, a “use when / skip when” description, a content body, and a requires confirmation flag for actions that change data.

Skillset configuration

The credentials a Skillset’s Skills need — named variables like a URL and an API key. Values are encrypted and injected at run time as environment variables (<CONFIGURATION_NAME>_<KEY>, upper-snake-cased). Secrets never appear in Skill text or in anything the agent says. Add one from the Skillset with Add configuration.

Integration

A Cobalt-built connector to an external system (service desk, HRIS, identity provider, file store, collaboration tool). An Integration turns that system’s capabilities into tools, with guardrails and audit built in. This is the primary way an Agent gains capability. Most integrations are curated apps from the catalog; you can also bring your own MCP Server — any MCP-compliant server you host or trust, whose tools are discovered at connect time.

Tool

A single capability the Agent can invoke — a search, a lookup, an action. Tools come from Integrations, from Skillsets, or are built in. How a tool may behave is governed by rules and hooks.

Hook

A policy gate that runs at the moment a tool is called. A Hook can require confirmation, check an argument against an allowlist, rewrite a call, or deny it — with audit logging.

Custom knowledge

Reference material that doesn’t live in a connected system — an uploaded PDF or FAQ — organized into collections the Agent can search and cite. For content that does live in a connected system, prefer an Integration.

Channel

How employees reach an Agent: the web widget, Slack, and more. One Agent can serve many Channels. An Agent with no Channel is invisible.

Tenant

Your organization’s isolated space in Cobalt — every object belongs to exactly one Tenant, and isolation is enforced at the data layer — one Tenant can never see another’s data.

Sensitivity

A Skillset is standard (default) or elevated. Setting elevated — for PHI, compensation, credentials, or security operations — routes work only to models covered by a Business Associate Agreement, tightens PII handling and retention, and isolates memory under a separate key.

Conversation

An ordered exchange between one or more users, the Agent, and (where used) a human during handoff. Conversations are what you review in Conversations & tracing.

Preview

An internal test surface for trying an Agent before connecting a real Channel, optionally with your own site or a screenshot of it behind the widget. Preview conversations don’t reach employees and don’t count against usage.

Credit

The unit Cobalt meters usage in. One credit covers one end-user turn — an employee asks, the agent works and answers. Console activity (building, configuring, Preview) never consumes credits. See Billing & usage.

Identity provider

The system your people sign in with at work — Microsoft Entra ID, Google Workspace, Okta, or another OpenID Connect provider. Registered in Settings › Identity › Providers; each Agent picks one on its Identity › Provider tab. Only the Agent’s provider can vouch for who someone is. See Identity providers.

Directory

The system Cobalt reads groups from — Microsoft Entra ID, Google Workspace or ServiceNow. A directory is for groups, not sign-in. Connected in Settings › Identity › Directories; each Agent picks one on its Identity › Directory tab. See Directories.

Allowed groups

The groups from an Agent’s directory that may reach a capability — a tool, skill, skillset, app integration, knowledge collection or item, or live agent handoff. Anyone in any one of the groups (up to 10) may reach it; everyone else never sees it. See Allowed groups.

Anonymous

A web channel mode where nobody signs in. Cobalt remembers the browser but knows nothing about who the person is.

Embedded token

A web widget mode where your own server signs a short-lived token saying who the person is. No identity provider is involved. See Signing keys.

Provider token

A web widget mode where your page passes a token from your identity provider for a person who is already signed in. Cobalt checks it came from the Agent’s provider. SharePoint’s silent sign-in uses this mode.

Cobalt sign-in

A web channel mode where people sign in with the Agent’s identity provider — their normal work sign-in — and stay signed in for 90 days. See How end-user identity works.