# Lexique

A–Z glossary of every term, parameter, product, protocol and principle that appears across the four Claude certification exams.

Every term below appears in at least one of the four exams. Each entry gives the definition, why it matters on the exam, and which courses lean on it most: **A** = CCAO-F, **D** = CCDV-F, **F** = CCAR-F, **P** = CCAR-P.

---

## A

**A/B testing (pairwise)** – Comparing two prompts/models head-to-head on the same inputs and testing whether the win rate differs from 50% with **statistical significance**. Eyeballing a few outputs is the distractor. *P*

**ADR (Architecture Decision Record)** – A short document capturing one decision, its context, the options considered and the consequences. The exam-correct artefact for communicating a trade-off to a non-technical sponsor, alongside a decision matrix, cost model and risk register. *P*

**Adaptive thinking** – `thinking: {"type": "adaptive"}`. The model decides how much reasoning to spend per request. The current default on Fable 5.1, Opus 5 and Sonnet 5; replaces fixed `budget_tokens` (which now returns 400 on those models and remains only on Haiku 4.5). *D F P*

**Agent** – A system where the model dynamically directs its own process and tool usage, deciding the next step from the environment's feedback, in a loop that ends when `stop_reason` is `end_turn`. Contrast **Workflow**. *D F P*

**Agent SDK (Claude Agent SDK)** – Anthropic's library (`pip install claude-agent-sdk`, `npm install @anthropic-ai/claude-agent-sdk`) that exposes the Claude Code agent harness programmatically: tools, hooks, permissions, subagents, MCP servers. Renamed from "Claude Code SDK". You host it. *D F P*

**Agent teams** – Claude Code feature for coordinating several agents with **named roles** collaborating on one shared task. Positioned above subagents (a few delegated tasks) and below dynamic workflows (scripted orchestration of dozens–hundreds). Choose when the work benefits from distinct personas working the same problem together, not independent fan-out. *F*

**Agentic loop** – `send → inspect stop_reason → if tool_use: execute tools, append tool_result, repeat → else stop`. Termination is driven by `stop_reason`, never by parsing prose or by an arbitrary iteration cap. *D F*

**Agentic RAG** – Retrieval performed as a tool call inside an agent loop so the model can reformulate queries, retrieve iteratively and decide when it has enough. *P*

**Aggregate metric masking** – Anti-pattern 10. A high overall accuracy hides a failing segment (e.g., one document type). Always report per-segment metrics. *D F P*

**Allowlist (tools, commands, domains)** – Explicit list of permitted actions; the default is deny. In Claude Code: `permissions.allow`; in the SDK: `allowed_tools`. Core least-privilege control. *D F P*

**Amazon Bedrock** – AWS-hosted access to Claude. Chosen for data residency, IAM integration, existing AWS commitments and FedRAMP High. *D P*

**Anti-pattern** – A plausible design that reliably fails. The Architect exams list ten; they appear as distractors. See the CCAR-F [Anti-Patterns](/ccar-f/anti-patterns/) page. *D F P*

**Answer relevance** – RAG generation metric: does the answer actually address the question asked? Distinct from **faithfulness** (is it grounded in context?) and retrieval **recall**. *P*

**Append-only history** – Fable 5.1 requirement: never edit, reorder or remove earlier turns because doing so invalidates later thinking blocks. Freeze `system` and `tools`; deliver mid-session changes as `role: "system"` messages; trim server-side (context editing / compaction). *D F P*

**Artifact** – A standalone, iterable deliverable rendered beside the chat in claude.ai (document, code, chart, mock-up). Choose for iterative deliverables; inline for conversation; structured data for machine consumption. *A*

**Augmented LLM** – The basic building block: a model plus retrieval, tools and memory. Workflows and agents are compositions of augmented LLMs. *F P*

**Auto memory** – Claude Code feature where the agent automatically records durable facts about a project into memory as it works; toggle and inspect via `/memory`. Distinct from the API **memory tool** and from the claude.ai product **Memory**. *F*

**Authentication vs authorisation (authn/authz)** – Who you are vs what you may do. Gap analysis on the Professional exam: does the tool layer propagate the *end user's* identity and enforce *their* permissions, or does the agent run with a shared super-user credential? *D P*

## B

**Backoff (exponential, with jitter)** – Retry strategy for 429, 500, 529 and network errors: wait `base × 2^n` plus randomness; honour `retry-after`. Do not retry 400/401/403/404. *D F P*

**Batch (Message Batches API)** – Submit up to thousands of requests asynchronously; 50% price discount; results within 24 h (usually far faster). Signal words: "overnight", "cost matters, latency does not", "10,000 documents". *D F P*

**Bias** – Systematic skew in framing, examples or treatment. Mitigated by neutral prompts, symmetric structures and human review; never fully eliminated by prompting alone. *A P*

**Baseline** – A measured reference (accuracy, latency p95, cost per 1k) captured before a change, so regressions are detectable. SLOs and A/B claims must be anchored to a baseline, not to expectation. *D P*

**Blast radius** – The scope of damage an action can cause. Minimise it: least-privilege tools, sandboxes, human gates on irreversible actions, and narrow permission patterns. *D F P*

**BM25 / sparse retrieval** – Keyword-based ranking. Strong on exact terms, IDs and rare words; weak on paraphrase. Combine with dense retrieval in **hybrid search**. *P*

**Bi-encoder** – Retrieval model that embeds queries and documents **separately** (document vectors precomputed), enabling fast index-time search. High recall, lower precision than a **cross-encoder** reranker; the two form the retrieve-then-rerank pipeline. *P*

**budget_tokens** – Legacy fixed thinking budget. Only Haiku 4.5 still uses it; 400 on Fable 5.x, Opus 5, Sonnet 5, Opus 4.7/4.8. *D F P*

## C

**cache_control** – Marks a content block as a cache breakpoint: `{"type": "ephemeral"}` (5-minute TTL; 1-hour option). Place stable content first. *D F P*

**Cache read / cache write** – Read ≈ 0.1× base input price; write ≈ 1.25× (5-min) or 2× (1-hour). Break-even after roughly two reads. Minimum cacheable prefix ≈ 1024 tokens (2048 on Haiku). *D F P*

**Canary release** – Rolling a change out to a small slice of live traffic first, watching metrics, then widening. The online counterpart to an offline golden-set eval; catches regressions the golden set missed. *P*

**Capability negotiation** – MCP `initialize` handshake where client and server declare supported features (tools, resources, prompts, sampling, logging). *D F*

**Cascade routing** – Sending traffic to a cheap model first and escalating only the hard cases (flagged by an **external validator**, not self-report) to an expensive one. Cost-effective while the escalation rate stays below the break-even point; above it, route everything to the expensive model. *D F P*

**Cohen's κ (kappa)** – Agreement statistic (correcting for chance) used to calibrate an LLM-as-judge against human labels; κ ≥ 0.6 is a common "trust it" bar. *P*

**Confidence (self-reported)** – A model's stated certainty. **Unreliable** as a control signal; routing/escalation on it is anti-pattern 4. Use an external validator or downstream check instead. *D F P*

**Context precision** – RAG metric: what fraction of retrieved chunks were actually relevant/used. Low context precision means the retriever is feeding the model noise. *P*

**Chain-of-thought (CoT)** – Asking the model to reason step by step in the visible output. Distinct from **extended/adaptive thinking**, which reasons in dedicated thinking blocks. *A D F P*

**Chunking** – Splitting documents for indexing. Strategies: fixed-size, recursive, semantic, structural/document-aware, parent-child (small-to-big), late chunking. Match to data shape and query pattern. *P*

**Citations** – API feature and RAG practice of attaching source spans to claims. Enables the **provenance test**. *A D P*

**claude.ai / Claude Desktop / Claude Code** – Consumer-and-team chat product; desktop app with local MCP integration; terminal-based agentic coding tool. Instructions are interpreted differently across surfaces – the Developer exam tests this. *A D*

**CLAUDE.md** – Claude Code's project memory file. Hierarchy: managed policy → user `~/.claude/CLAUDE.md` → project `./CLAUDE.md` → subdirectory. `CLAUDE.local.md` is git-ignored personal memory; `@path` imports other files. Keep concise; it is loaded every session. *D F P*

**Compaction** – Server-side summarisation of a long conversation that preserves the narrative while shrinking tokens. Use for long sessions that need their history; use **context editing** to drop verbose tool results. In Claude Code: `/compact`; hook event `PreCompact`. *D F P*

**Computer use** – Server-side tool family letting Claude operate a GUI via screenshots and actions. Sandbox it. *D F*

**Connector** – Integration that lets Claude read/act on external data (Google Drive, Gmail, Calendar, Slack, GitHub…). Governance question: what data becomes reachable and under whose permissions. *A*

**Context editing** – API capability to clear or trim earlier tool results/content server-side, keeping the conversation valid (and Fable-5.1-safe). *D F P*

**Context window** – Maximum tokens (input + output) the model can attend to. 1M on Fable 5.1 / Opus 5 / Sonnet 5; 200k on Haiku 4.5. Consumed by system prompt, tools, history, tool results and thinking. *A D F P*

**Correlation ID** – A unique identifier threaded through a request's logs, traces and tool calls so an incident or bug can be reconstructed end-to-end. *D F P*

**Credly** – Issuer of the digital badge you receive on passing. *A D F P*

**Criterion-referenced** – Scoring against a fixed standard (720/1000) set by a standard-setting study, not a curve. *A D F P*

**Cross-encoder** – A model that reads the query and a candidate document **together** to score relevance, giving higher precision than the bi-encoder used for first-stage retrieval, at higher cost. The standard **reranker** architecture: retrieve broadly with a bi-encoder, rerank the top-k with a cross-encoder. *P*

## D

**Data classification** – Public / internal / confidential / restricted; special categories PII, PHI, PCI. Drives what may be pasted into which tool. *A P*

**Decision matrix** – A table scoring options against weighted criteria, used to communicate a trade-off to stakeholders alongside an ADR, cost model and risk register. *P*

**Disclosure** – Telling users when AI is involved, especially in external communications and decisions about people. A governance requirement, not optional polish. *A P*

**defer_loading** – Tool definition flag that keeps a tool out of the initial prompt until **tool search** surfaces it. Use beyond ~10 tools or with multi-server MCP. *D F P*

**Dense retrieval** – Embedding-based semantic search. Strong on paraphrase; weak on exact identifiers. *P*

**Deprecation (model)** – The lifecycle stage where a model is announced for retirement but still callable, before a published **retirement floor** date. Treat it as a planned, eval-gated migration event, not an emergency; the floor is the *earliest* date, often extended. *D P*

**Distractor** – A wrong option engineered to look right. Common types: constraint-blind, over-engineered, prompt-as-enforcement, self-report reliance, silent failure, recall-only, aggregate metric. *A D F P*

**DPIA** – Data Protection Impact Assessment (GDPR). Required for high-risk processing; often triggered by AI systems handling personal data. *P*

**Dynamic workflows** – Claude Code capability where a script drives the runtime to launch and coordinate many agents. For dozens–hundreds of agents; subagents for a few. *F*

## E

**Effort** – Request-level parameter `low | medium | high (default) | xhigh` trading reasoning depth for latency/cost. `xhigh` for the hardest coding/agentic work on Opus 5 / Fable 5.1; `low`/`medium` for mechanical subagents. Not available on Haiku 4.5. *D F P*

**Embedding** – Vector representation of text used for dense retrieval. *P*

**Embedding dimensions** – The length of an embedding vector (e.g., 256, 768, 1024, 1536). Higher dimensions can capture more nuance but cost more storage/compute and can add noise; the number must match between indexing and query time or retrieval breaks silently. *P*

**end_turn** – `stop_reason` meaning the model finished naturally. The correct loop-termination signal. *D F*

**Escalation** – Handing a case to a human or higher tier. Correct triggers: explicit customer request (immediate) or task exceeding capability (after attempting). Wrong triggers: sentiment, self-reported confidence. *A D F P*

**Eval (evaluation)** – Systematic measurement of system output against a golden dataset using exact match, rubric grading, LLM-as-judge (separate model/session) or pairwise A/B. Report per-segment. *D F P*

**Evaluator-optimizer** – Workflow pattern: one call generates, another evaluates against criteria, loop until pass. Use a different session/model for the evaluator to avoid same-session bias. *D F P*

**Exit criteria** – Explicit, measurable conditions that define "done" for a phase or handoff in the solution lifecycle (e.g. eval score, runbooks delivered, monitoring live). A handoff without exit criteria and runbooks is the distractor. *P*

**Extended thinking** – Dedicated reasoning blocks before the answer. Now "adaptive" on current models. Thinking blocks on Fable 5.1 are bound to the producing model and history. *D F P*

## F

**Fable 5.1 (`claude-fable-5-1`)** – Most capable released model (Sept 2026), 1M/128k, $10/$50. Breaking changes: no forced `tool_choice`, thinking-block binding, append-only history; 30-day retention required (no ZDR); not in Priority Tier. *D F P*

**Faithfulness** – RAG metric: is the answer supported by the retrieved context? Distinct from **answer relevance** and **retrieval recall**. *P*

**Fallback model** – A secondary model used when the primary returns repeated 529/overload. Fall back only to a **newer-or-equal** model; falling back from Fable 5.1 to an older model silently drops thinking blocks and forces a re-plan. *D F P*

**Fast mode** – Latency-optimised inference option for time-sensitive interactions. *D*

**FedRAMP High** – US federal authorisation level; Claude available via Bedrock / Vertex AI deployments. *P*

**Few-shot** – Providing worked examples in the prompt. Choose examples that cover edge cases and the exact output format; keep them stable for caching. *A D F P*

**Few-shot selection** – Choosing *which* examples to include, often by retrieving the k most similar labelled examples to the current input (dynamic few-shot). Improves coverage of a large label space but breaks prompt caching (the prefix changes each call) and propagates any wrong neighbour into the answer. *D F P*

**Files API** – Upload files once and reference them across requests. *D*

**Function calling** – Synonym for **tool use**. *D F*

## G

**GDPR** – EU data-protection regulation: lawful basis, data-subject rights, minimisation, residency, DPIA. *A P*

**Golden dataset** – Curated input/expected-output pairs used for evals and regression tests. *D P*

**Golden set** – Synonym for **golden dataset**. Design it to cover the input distribution and hard/adversarial cases; version and freeze it (changing it invalidates comparisons); keep a separate holdout to detect overfitting to the eval. *D P*

**Guardrail layering** – Defence in depth: input classification → system-prompt rules → tool permission hooks → output validation → human review. No single layer is sufficient. *D F P*

**Grader** – The mechanism scoring an eval output: exact/normalised match, regex/structural, heuristic, rubric, LLM-as-judge or human. Use the cheapest sufficient grader for the task. *D P*

## H

**Haiku 4.5 (`claude-haiku-4-5`)** – Fastest/cheapest current model, 200k/64k, $1/$5; still uses `budget_tokens`; no `effort`. Ideal for classification, routing, extraction at scale. *A D F P*

**Hallucination** – Fluent, plausible, ungrounded content. Clusters in numbers, citations, proper nouns and long-tail facts. *A D F P*

**Headless mode** – `claude -p "prompt" --output-format json|stream-json` for CI and scripts, with `--allowedTools` and `--permission-mode`. *D F P*

**HIPAA / BAA** – US health-data rules; a Business Associate Agreement is required before processing PHI. *A P*

**Hooks** – Deterministic shell/HTTP handlers triggered at lifecycle events (`PreToolUse`, `PostToolUse`, `UserPromptSubmit`, `Stop`, `SessionStart`, `SubagentStop`, `PreCompact`, `Notification`). Exit code 2 blocks the action. The correct enforcement mechanism for critical business rules. *D F P*

**Human-in-the-loop (HITL)** – A mandatory human decision gate for irreversible, regulated, external or high-uncertainty actions. *A D F P*

**Hybrid search** – Dense + sparse retrieval fused (e.g., reciprocal rank fusion), often followed by a reranker. *P*

**HyDE** – Hypothetical Document Embeddings: generate a hypothetical answer, embed it, retrieve by similarity. A query-rewriting technique. *P*

**Holdout set** – A slice of labelled data never used for tuning, kept to detect overfitting to the golden/eval set. If tuned and holdout scores diverge, you have overfit the eval. *D P*

## I

**Idempotency** – Repeating an operation produces the same result. Essential for retried tool calls and batch jobs; design tools with idempotency keys. *D F P*

**Idempotency key** – A caller-supplied unique token (HTTP header `idempotency-key`, or a tool argument) reused on retries so a duplicate delivery is de-duplicated rather than executed twice — the mechanism that makes retrying a side-effecting request (e.g. a charge) safe. *D F P*

**Indirect prompt injection** – Malicious instructions arriving through tool results, documents, web pages or emails rather than the user turn. Treat all tool output as untrusted data. *D F P*

**Incident response** – The runbook for a security/reliability event: detect → contain (revoke tokens, disable tools) → assess (traces) → eradicate (add the missing control) → recover (rotate, re-enable) → learn (add a regression eval, notify if regulated). *P*

**input_schema** – JSON Schema describing a tool's parameters. Use descriptions, enums, `required`; enable `strict: true` for schema-guaranteed calls. *D F*

**ITPM / OTPM / RPM** – Input tokens per minute, output tokens per minute, requests per minute – the rate-limit dimensions. *D P*

## J

**Jailbreak** – Attempt to make the model violate its policies via role-play, encoding or incremental pressure. Mitigate with system-prompt rules, classifiers and tool-level enforcement. *D P*

**JSON-RPC 2.0** – The message format MCP uses over its transports. *D F*

**Judge calibration** – Measuring an **LLM-as-judge** against human labels (e.g., Cohen's κ or % agreement) before trusting it, then tightening the rubric, adding graded exemplars or shrinking the scale until agreement meets a bar. Counters leniency, run-to-run inconsistency, position bias (randomise A/B order) and verbosity bias. *D P*

## L

**Late chunking** – Embed the full document first, then pool embeddings per chunk so each chunk carries document-level context. *P*

**Least privilege** – Grant only the tools/permissions the task needs. Exam-correct move: **remove** an unneeded `delete`/`refund` tool rather than log or confirm its use. *D F P*

**LLM-as-judge** – Using a model to grade outputs against a rubric. Must be a **different session (ideally different model)** and calibrated against human labels. *D F P*

**Logging (safe)** – Record `request-id`, model, `stop_reason`, `usage`, latency, tool outcomes and correlation IDs; **never** log secrets, tokens or raw PII/PHI. Redact at the logging boundary. *D F P*

**Long-context ordering** – Put large documents first and the question/instructions last; improves recall and keeps the stable prefix cacheable. *D F P*

## M

**Managed Agents** – Anthropic-hosted agent runtime (loop + sandbox). Choose when you do not want to operate the harness; choose Agent SDK / Tool Runner when you need to host. *D F P*

**Map-reduce (summarisation)** – Summarise each chunk (map), then answer or summarise from the summaries (reduce). Handles corpora larger than the window but loses detail; prefer RAG when precise retrieval matters. *D P*

**Migration (model)** – Deliberately moving production traffic from one model ID to another behind an eval gate. Safe when migrating to a newer-or-equal model; per-model checklists differ (e.g. remove forced `tool_choice` when moving to Fable 5.1, drop `budget_tokens` when leaving Haiku). *D P*

**max_tokens** – Output cap. `stop_reason: max_tokens` means truncation – handle by continuing or raising the cap; never treat as a complete answer. *D F*

**MCP (Model Context Protocol)** – Open standard for connecting models to tools and data. Host ↔ client ↔ server over JSON-RPC; primitives Tools (model-controlled), Resources (application-controlled), Prompts (user-controlled); transports stdio and Streamable HTTP; OAuth 2.1 for remote auth. *D F P*

**MCP connector** – Messages API feature that lets Claude call remote MCP servers directly without a client harness. *D F P*

**Memory (product)** – claude.ai feature retaining user preferences/context across chats. Governance: know what is remembered and how to clear it. *A*

**Memory tool** – API tool giving the model a persistent file-like store across sessions. Use for state that must survive compaction. *D F P*

**Mid-conversation system message** – `role: "system"` message inserted between turns to change instructions without editing history (Fable 5.1 pattern). Not supported on Sonnet 5. *F P*

**MMR (Maximal Marginal Relevance)** – Retrieval re-ranking that balances relevance and diversity to avoid redundant chunks. *P*

**Multi-query retrieval** – Generating several paraphrases of a question, retrieving for each and unioning the results. A query-rewriting technique for vague or broad questions. *P*

**Model pinning** – Using a specific model ID snapshot in production and migrating deliberately; IDs from 4.6 onward are dateless but still pinned. *D P*

**Multi-response item** – Exam question requiring N answers; each must be independently correct. *A D F P*

**Multi-pass review** – Reviewing a large PR in several focused passes (security, correctness, style) rather than one; single-pass for small PRs. *F P*

## N

**nDCG@k (normalised discounted cumulative gain)** – A rank-weighted retrieval metric that rewards placing relevant chunks near the top of the top-k. More sensitive to ordering than recall@k; pair with MRR when rank matters. *P*

## O

**Observability** – Traces per agent/tool call, correlation IDs, token and cost telemetry, latency p50/p95, error rates, cache hit rate. *D F P*

**OAuth 2.1 / PKCE** – The authorisation standard for remote MCP servers: a browser-based code flow with mandatory PKCE (no implicit flow), short-lived tokens and refresh. Tokens carry the **end user's** identity so tools enforce that user's permissions. *D F P*

**OnVUE** – Pearson VUE's online-proctored delivery platform. *A D F P*

**Opus 5 (`claude-opus-5`)** – Default for complex agentic coding and enterprise work; 1M/128k; $5/$25. *A D F P*

**Orchestrator-workers** – Pattern where a central model decomposes a task, delegates to workers (subagents) with explicit context, and synthesises results. *D F P*

**output_config.format** – Structured-output parameter taking a JSON Schema; the preferred route to guaranteed-shape output (and the Fable-5.1-compatible alternative to forced `tool_choice`). *D F P*

**Over-engineering** – Distractor pattern: choosing a multi-agent system where a prompt chain suffices. Prefer the simplest design that meets constraints. *D F P*

## P

**p50 / p95 / p99** – Percentile latencies: p95 is the value 95% of requests come in under. Report percentiles, not just the average — an acceptable mean can hide a p95/p99 tail that breaches the SLO. *D F P*

**Parent-child chunking** – Small-to-big retrieval: index small **child** chunks (150–300 tokens) for precise matching, but return the larger **parent** section (800–1200 tokens) to the model for context. Balances retrieval precision with answer context. *P*

**Parallel tool use** – Model emits several `tool_use` blocks in one turn; execute concurrently and return all `tool_result` blocks in the next user message. *D F*

**Parallelization (sectioning / voting)** – Workflow pattern: split independent subtasks or run the same task several times and aggregate. *D F P*

**Partner Academy** – `anthropic-partners.skilljar.com`; where exams are registered. Requires a partner-domain work email. *A D F P*

**pause_turn** – `stop_reason` indicating a long-running server-side tool turn paused; continue by re-sending. *D F*

**Permission mode** – Claude Code/SDK setting governing whether actions run automatically, ask, or are denied; plus `permissions.allow/deny/ask` lists. *D F P*

**PKCE (Proof Key for Code Exchange)** – The OAuth 2.1 mechanism (`code_verifier` + `code_challenge`) that secures the authorization-code flow for public clients; mandatory for remote MCP auth. *D F P*

**Position bias** – Tendency of an LLM-as-judge to favour the first (or last) option in a pairwise comparison. Counter by randomising order and averaging both orderings. *P*

**PII / PHI / PCI** – Personally identifiable information / protected health information / payment-card data. Minimise, redact, and control tool access. *A D F P*

**PII redaction** – Masking or removing personal data **before** it reaches the prompt (and at the logging boundary), rather than trusting the model to avoid it. Combine with data minimisation, classification-driven tool access and residency/ZDR controls. *A P*

**Plan mode** – Claude Code read-only exploration that produces a plan before executing; use for multi-file or architectural changes; direct mode for single-file obvious edits. *D F*

**Plugins** – Packaged bundles of Claude Code commands, agents, hooks and MCP servers for distribution. *D F*

**Prefill** – Starting the assistant turn with text (e.g., `{`) to steer format. Useful but superseded by structured outputs for guarantees. *D F*

**Priority Tier** – Capacity/latency tier for eligible models; Fable 5.1, Opus 5 and Sonnet 5 are excluded. *P*

**Programmatic tool calling** – Letting Claude write code that calls tools in a sandbox, reducing round trips for multi-step tool logic. *D F*

**Progressive disclosure** – Loading capability on demand (Skills, tool search) instead of monolithic upfront context. *D F P*

**Projects** – claude.ai workspaces with custom instructions and knowledge files; the Associate's primary configuration surface. *A*

**Prompt caching** – See cache_control. Architecture rule: stable prefix first, dynamic content last. *D F P*

**Prompt chaining** – Workflow pattern: sequential calls with programmatic gates between steps. *D F P*

**Prompt injection** – Untrusted input that tries to override instructions. Direct (user turn) or indirect (tool/document). *D F P*

**Provenance test** – "Where did this claim come from?" Supplied doc → check text; citation → open it; model knowledge → verify independently. *A P*

## Q

**Query rewriting** – Transforming a user's question before retrieval (normalisation, expansion, pronoun resolution, decomposition, HyDE, multi-query) to improve recall on vague or multi-intent queries. *P*

## R

**RAG (Retrieval-Augmented Generation)** – Retrieve relevant chunks at query time and ground the answer in them. Debug confident-but-wrong answers after a document refresh by suspecting **retrieval/indexing first**. *P*

**Rate limit (429)** – Exceeding RPM/ITPM/OTPM; back off and honour `retry-after`. *D P*

**Risk register** – A living list of identified risks with likelihood, impact, owner and mitigation. Part of the stakeholder-communication toolkit (with ADRs, decision matrix, cost model) and governance evidence. *P*

**Retention (data)** – How long prompts/outputs are stored. Default is a retention window (30 days for Fable 5.1); **ZDR** contracts store nothing. Regulated data drives the choice; Fable 5.1 cannot be ZDR. *D P*

**Retirement floor** – The published earliest date a model may be retired. It is a floor, not a promise; migrate behind an eval before it, and keep the old ID available for rollback until then. *D P*

**Recall@k / MRR** – Retrieval metrics: fraction of relevant docs in top-k; mean reciprocal rank of the first relevant hit. *P*

**Reciprocal rank fusion (RRF)** – Method for combining ranked lists (e.g., dense + BM25 in hybrid search): a document's score is the sum over lists of `1 / (k + rank)`, with `k` typically 60. Needs no score calibration between systems because it ranks by position, not raw score. *P*

**refusal** – `stop_reason` when safety systems decline; handle explicitly with a fallback path, never as a generic error. *D F*

**Reranker** – Cross-encoder that re-scores top-k candidates for precision. Retrieve broadly, rerank to a small top-n; improves ordering/precision and MRR, not recall. *P*

**Research mode** – claude.ai capability that performs multi-step web research with citations. Audit citations. *A*

**retry-after** – Response header (seconds) on a 429/529 telling you how long to wait before retrying. Honour it instead of your own backoff when present. *D F P*

**Routing** – Workflow pattern: classify input, dispatch to a specialised prompt/model. Cheap model as router, expensive model for hard cases (cascade). *A D F P*

**Routines** – Claude Code scheduled/recurring cloud automations (`/schedule`). Use for recurring jobs; subagents/workflows for one-off orchestration. *F*

**Rubric** – An explicit, criteria-based scoring guide used for grading subjective output, by humans or an LLM-as-judge. A calibrated rubric sits between exact-match graders and free-form judging. *D F P*

## S

**Same-session self-review** – Anti-pattern 9: asking the same conversation to check its own work retains its bias. Use a fresh session or a different model. *A D F P*

**Sandbox** – An isolated execution environment for tools (code execution, computer use) and for `bypassPermissions` CI runs, limiting blast radius. Sandbox untrusted or destructive capability rather than granting it directly. *D F P*

**Sampling (temperature, top_p)** – Controls randomness. Temperature 0 reduces variance but does not guarantee determinism or truth. *A D*

**Sampling (MCP)** – Distinct from decoding sampling: an MCP capability where a **server** asks the host's model to complete something (e.g., summarise before returning). The host stays in control and can deny, redact or rate-limit — a trust boundary, never auto-approved for untrusted servers. *D F*

**Scenario** – CCAR-F items are drawn from 4 of 6 published business scenarios. *F*

**Sectioning** – A parallelization pattern: split a task into independent sub-parts, run them concurrently and combine. Contrast **voting** (same task run several times and aggregated). *D F P*

**Signal word** – A phrase in a stem (BEST, FIRST, MOST cost-effective, "at scale", "must never", "confidence") that points to the intended principle. Mapping signal words to principles is the fastest route to the correct option. *A D F P*

**Sentiment-based escalation** – Anti-pattern 5. Anger is not complexity. *D F P*

**settings.json** – Claude Code configuration: user `~/.claude/settings.json`, project `.claude/settings.json`, local `.claude/settings.local.json`, managed policy. Holds permissions, hooks, env, model. *D F P*

**Skills** – Reusable procedures in `SKILL.md` files (name + description frontmatter) loaded progressively when relevant. Skill vs CLAUDE.md vs slash command vs subagent vs MCP is a recurring decision. *A D F P*

**Slash command (custom)** – `.claude/commands/<name>.md` with `$ARGUMENTS`; invoked as `/name`. *D F*

**SLO / SLA** – Service-Level Objective (an internal target, e.g. p95 latency < 2s, 99% availability) vs Service-Level Agreement (a contractual commitment with consequences). Set them against **measured baselines**; the exam-correct answer to "executives expect 100% accuracy" is to align expectations to an achievable SLO. *P*

**Sonnet 5 (`claude-sonnet-5`)** – Best speed/intelligence balance; 1M/128k; $2/$10; no mid-conversation system messages or task budgets. *A D F P*

**SSE (Server-Sent Events)** – Streaming transport for the Messages API (`message_start`, `content_block_start/delta/stop`, `message_delta`, `message_stop`) and MCP's legacy remote transport. *D F*

**stdio / Streamable HTTP** – MCP transports: local subprocess vs remote HTTP. *D F P*

**Statistical significance** – In A/B/eval comparisons, evidence that an observed difference is unlikely to be chance (e.g., p < 0.05, or a confidence interval excluding 50%). Shipping a "better" prompt/model on a handful of outputs without a significance test is the eyeballing distractor. *P*

**Streamable HTTP** – The current MCP remote transport: a single endpoint supporting request/response and server-streamed messages, fronted by OAuth 2.1 (PKCE). Supersedes the older HTTP+SSE two-endpoint transport; use for remote, multi-user servers. *D F P*

**stop_reason** – Why generation stopped: `end_turn`, `tool_use`, `max_tokens`, `stop_sequence`, `pause_turn`, `refusal`. The one field every loop must branch on. *D F P*

**strict: true** – Tool-schema flag guaranteeing arguments conform to `input_schema`. *D F P*

**Structured output** – Guaranteed JSON shape via `output_config.format` (or tool-use-as-schema). Always validate and retry with the error fed back. *D F P*

**Subagent** – A delegated agent with an isolated context window, its own system prompt, tool allowlist and model. Pass context **explicitly**; never rely on inheritance. *D F P*

**Sycophancy** – Model agreement with the user's stated view. Counter with neutral prompts and fresh-session critique. *A*

**System prompt** – Top-level instructions (`system` parameter). Treat as a governed, versioned asset; keep stable for caching. *A D F P*

## T

**Task budgets** – Token/turn budgets for agentic tasks; not supported on Sonnet 5. *F*

**Threat model** – A structured enumeration of who might attack a system, how (direct/indirect injection, excessive agency, authz gaps, secret leakage, supply chain, data poisoning) and the impact, used to choose layered controls. *D P*

**Tier (rate-limit)** – Usage/spend level (Tier 1–4, custom, Priority) that sets your RPM/ITPM/OTPM ceilings. Priority Tier excludes Fable 5.1, Opus 5 and Sonnet 5. *D P*

**Temperature** – See Sampling. *A D*

**Token** – Unit of text the model processes (~¾ of an English word). Billing and context limits are in tokens. *A D F P*

**Tokenizer** – The component that splits text into tokens. Token counts (hence cost and context usage) depend on it; non-English text and code often tokenise less efficiently than English prose, so budget accordingly. *A D F P*

**tool_choice** – `auto` (default), `any` (must call some tool), `{"type":"tool","name":…}` (forced), `none`. **`any` and forced return 400 on Fable 5.1**; use `auto` + instruction, `strict: true` or structured outputs. *D F P*

**Tool description** – The single most important lever for correct tool use: say what the tool does, when to use it, when not to, and what it returns. *D F P*

**Tool result** – `tool_result` content block returned in the next user message, matched by `tool_use_id`; set `is_error: true` with structured diagnostic content on failure. Never return empty success. *D F*

**Tool Runner** – Self-hosted harness executing the agent loop and tools. Contrast Managed Agents. *F*

**Tool search** – Server-side tool that lets Claude discover deferred tools on demand from a large catalogue. *D F P*

**Trace** – Ordered record of a request's calls, tool invocations, tokens and stop reasons; primary debugging artefact. *D F P*

## V

**Validation-retry loop** – Parse → validate against schema/business rules → on failure, resend with the specific error → cap attempts → escalate. *D F P*

**Vertex AI** – Google Cloud-hosted access to Claude. *D P*

**Vision** – Image (and PDF) inputs as content blocks (base64 or URL). *D*

**Voting** – A parallelization pattern: run the same task several times (possibly with varied prompts) and aggregate by majority or consensus to raise reliability. Contrast **sectioning** (independent sub-parts). *D F P*

## W

**Workflow** – System where LLM calls and tools are orchestrated through **predefined code paths**. Predictable, testable, cheaper. Prefer when the steps are known. Contrast **Agent**. *D F P*

**Worktree** – A git working tree checked out from the same repository into a separate directory, letting parallel agents/tasks edit isolated copies without colliding. Used by fan-out patterns (e.g. `/batch`) so each unit works in its own worktree and opens its own PR. *F*

## X

**XML tags** – `<document>`, `<instructions>`, `<example>` used as content boundaries so the model can distinguish data from instructions – also a prompt-injection mitigation. *A D F P*

**xhigh** – Highest effort level for the hardest coding/agentic tasks on Opus 5 / Fable 5.1. *D F P*

## Z

**Zero Data Retention (ZDR)** – Contractual option where prompts/outputs are not retained. Not available for Fable 5.1 (30-day retention required). *D P*

**Zero-shot** – Prompting without examples. Fine for simple, well-specified tasks; add few-shot for format-sensitive or ambiguous ones. *A D F P*
