# Glossary

1. [Home](https://www.agilicus.com/)
2. [Agilicus AnyX Administrative Web Interface](https://www.agilicus.com/anyx-guide/agilicus-anyx-administrative-web-interface/)
3. [Concepts](https://www.agilicus.com/anyx-guide/agilicus-anyx-administrative-web-interface/concepts/)
4. Glossary

![](https://www.agilicus.com/www/3f7269e8-featured-anyx-admin-conceptsglossary.png)## Glossary

[CONTACT](/contact-us/)

Terms used throughout the portal and this guide. Where a term has a dedicated guide page, the entry links to it.

| Term | Meaning |
|---|---|
| **Organisation** | The top-level administrative unit in the portal. It owns users, resources, connectors, policies, and billing. Administrators belong to an organisation. See [Organisation overview](/anyx-guide/agilicus-anyx-administrative-web-interface/organisation/overview/). |
| **Sub-organisation** | A child organisation under a parent. Useful for separating departments, tenants, or partners while keeping central administration. See [Sub-organisations](/anyx-guide/agilicus-anyx-administrative-web-interface/organisation/sub-organisations/). |
| **User** | A person (or service account) that can authenticate and access resources. See [Users](/anyx-guide/agilicus-anyx-administrative-web-interface/access/users/). |
| **Group** | A collection of users used to grant permissions and policies in bulk. See [Groups](/anyx-guide/agilicus-anyx-administrative-web-interface/access/groups/). |
| **Resource group** | A grouping of resources, used with permissions and policies so you can control access to many resources at once. See [Resource groups](/anyx-guide/agilicus-anyx-administrative-web-interface/access/resource-groups/). |
| **Service account** | A non-human identity used by software, automation, or the API. See [Service accounts](/anyx-guide/agilicus-anyx-administrative-web-interface/access/service-accounts/). |
| **Resource** | Anything you expose through the platform: a web application, file share, desktop, database, SSH service, launcher, or network. See [Resources](/anyx-guide/agilicus-anyx-administrative-web-interface/concepts/resources/). |
| **Application** | A web application exposed through the identity-aware proxy. See [Applications](/anyx-guide/agilicus-anyx-administrative-web-interface/resources/applications/). |
| **Connector** | Software at your site that links your local resources to the Agilicus cloud over an outbound-only connection. See [Connectors](/anyx-guide/agilicus-anyx-administrative-web-interface/concepts/connectors/). |
| **Identity-aware proxy** | The cloud component that authenticates users and forwards requests to the right connector. See [Zero trust architecture](/anyx-guide/agilicus-anyx-administrative-web-interface/concepts/zero-trust-architecture/). |
| **Identity provider** | An external service that authenticates your users (Google, Microsoft, Apple, Active Directory, Yahoo, or a custom OpenID Connect provider). See [Identity and authentication](/anyx-guide/agilicus-anyx-administrative-web-interface/concepts/identity-and-authentication/). |
| **Shared identity** | A built-in identity provider shared across Agilicus organisations. |
| **Custom identity** | A custom identity provider you register with a third party (for example an Azure application registration). |
| **Onsite identity** | An identity provider you run on your own site, used when user credentials must not leave your network. |
| **Application identity** | An identity provider scoped to a specific application. |
| **Authentication policy** | Rules that control which identity providers may be used, and which authentication methods (including multi-factor authentication) are required. See [Authentication policy](/anyx-guide/agilicus-anyx-administrative-web-interface/authentication/authentication-policy/). |
| **Single sign-on** | Users authenticate once with their existing corporate credentials and are recognised across resources. |
| **Multi-factor authentication** | An authentication method requiring more than one factor (for example a password plus a one-time code). |
| **Policy** | A set of rules (for example geolocation or firewall rules) applied to users or resources. See [Policies](/anyx-guide/agilicus-anyx-administrative-web-interface/access/policies/). |
| **Permission** | A specific right granted to a user or group for a resource or application (for example read-only, read/write, or a named application role). See [Permissions](/anyx-guide/agilicus-anyx-administrative-web-interface/access/application-permissions/). |
| **Label** | A tag you can attach to resources and other objects to organise them and drive policies and permissions. See [Labels](/anyx-guide/agilicus-anyx-administrative-web-interface/organisation/labels/). |
| **API key** | A credential for programmatic access to the Agilicus API. See [API keys](/anyx-guide/agilicus-anyx-administrative-web-interface/access/api-keys/). |
| **Launcher** | A small application installed on a user's desktop that enables access to resources (for example SSH, databases, or file shares) outside the browser. See [Launchers](/anyx-guide/agilicus-anyx-administrative-web-interface/resources/launchers/). |
| **Share** | A directory exposed over HTTPS and WebDAV for browsers and desktops. See [Shares](/anyx-guide/agilicus-anyx-administrative-web-interface/resources/shares/). |
| **Desktop** | A remote desktop exposed through the platform as a remote desktop gateway. See [Desktops](/anyx-guide/agilicus-anyx-administrative-web-interface/resources/desktops/). |
| **Network** | A global resource (usually a TCP service such as a database or an internal service) available to applications running on the platform. See [Networks](/anyx-guide/agilicus-anyx-administrative-web-interface/resources/networks/). |
| **Audit** | The record of authentication events, authorisation decisions, and sessions. See [Audit and diagnostics](/anyx-guide/agilicus-anyx-administrative-web-interface/concepts/audit-and-diagnostics/). |
| **Audit destination** | Where audit events are delivered (for example a SIEM or a log service). See [Audit destinations](/anyx-guide/agilicus-anyx-administrative-web-interface/organisation/audit-destinations/). |
| **Session** | An authenticated period of access by a user or token. See [Sessions](/anyx-guide/agilicus-anyx-administrative-web-interface/organisation/sessions/). |
| **CNAME** | A DNS record type used to point your own domain at the Agilicus service. |
| **Outbound-only connection** | A connection initiated by your connector to the cloud; nothing is initiated inbound. |
| **SIEM** | Security information and event management: a service that collects logs for security analysis. |

## See also

- [What is Agilicus AnyX](/anyx-guide/agilicus-anyx-administrative-web-interface/concepts/what-is-agilicus-anyx/)
- [Zero trust architecture](/anyx-guide/agilicus-anyx-administrative-web-interface/concepts/zero-trust-architecture/)
- [Resources](/anyx-guide/agilicus-anyx-administrative-web-interface/concepts/resources/)

## Web guide

- [Agilicus AnyX Product Guide](https://www.agilicus.com/product-guide/)