Skip to main content
These concepts describe how your infrastructure, agents, and security workflows fit together. The platform and the Antigen SDK use the same vocabulary.

Your environment

Organization
Your team’s workspace in Antigen. It contains your Asset Map, agents, targets, vulnerabilities, and connected integrations.
Asset Map
A graph of your organization’s infrastructure. It shows services, resources, identities, and the relationships between them. Integrations keep the map current, and agents use it to understand your environment. See Asset Map.
Asset
An individual service, resource, or identity in the Asset Map, such as an application, database, or IAM role.
Target
A domain or IP address submitted for security testing. The Antigen team reviews and approves new targets before agents can test them. See Targets.
Expert
Your Antigen expert helps plan engagements, interpret results, and decide what to do next.

Agents and runs

Agent
A configuration that combines a model, skills, guardrails, and tools to perform work. You can use a pre-built agent, customize an existing one, or assemble your own through the SDK. Registering an agent saves its configuration so your team can retrieve it and assign vulnerabilities to it. See Agents.
tCell
Antigen’s pre-built offensive security agent. It tests approved targets for vulnerabilities and verifies deployed fixes. The Antigen team develops and improves tCell using the same SDK available to your team. See tCell.
Triage agent
Antigen’s pre-built triage-agent investigates a vulnerability and determines how remediation should proceed. It uses the evidence, infrastructure context, and available access to identify next steps or request help from your team. See How triage works.
Remediation agent
Antigen’s pre-built remediation-agent prepares steps to address a vulnerability. These can include a pull request or a recommended infrastructure change for your team to review and carry out. See How remediation works.
Run
One execution of an agent. The same agent can perform multiple runs, each with its own progress and results. A tCell run tests targets; a remediation-agent run prepares steps to address a vulnerability. See Runs.
Sandbox
An isolated environment where an agent executes a run. It provides the workspace and tools the agent uses, with network and target restrictions controlling which systems it can access.

Vulnerabilities and evidence

Vulnerability
A security weakness discovered by an agent, with supporting evidence. Its status and assignment track the work to investigate, remediate, and verify it. The same vulnerability remains available as agents and people add evidence and make progress. See Vulnerabilities.
Evidence
Artifacts that support a vulnerability or show the result of testing it. Evidence can include HTTP requests and responses, screenshots, network captures, and exploit recordings. Later runs can add evidence showing whether a fix worked. See Evidence.
Report
A summary of an engagement that captures the relevant vulnerabilities and evidence at the time it is written. The report preserves those results while the vulnerabilities continue through their lifecycle. See Reports.

Coordinating work

Status
A vulnerability’s position on the board: Open, In progress, Remediated, Verified, or Accepted risk. Status shows where the work stands; verification establishes whether a deployed fix resolved the issue. See Vulnerability lifecycle.
Assignment
The person or agent responsible for a vulnerability. Assigning a vulnerability to a custom agent can trigger a webhook that your service handles to launch it.
Hook
An action triggered when a vulnerability’s status or assignment changes. Preconfigured hooks coordinate triage, remediation, and verification. Custom webhooks deliver events to your service, which decides how to respond. See Hooks.
Human task
A request assigned to a person when an agent needs information, access, a decision, or an action. It explains what is needed and why, and reaches the person through connected messaging or issue-tracking tools. Completion lets the agent continue its work. See Team workflows.

Configuring agents

Model
The model an agent uses to reason and decide what to do. Agents access available models through Antigen’s model gateway. See Models.
Skill
Instructions that teach an agent a procedure or provide knowledge about your systems. Skills can describe authentication behavior, investigation methods, or how to prepare a particular kind of fix. See Skills.
Guardrail
An instruction that constrains an agent’s behavior, such as avoiding particular endpoints or stopping when it finds a critical vulnerability. Guardrails work alongside the platform’s enforced target and sandbox restrictions. See Guardrails.
Tool
A capability an agent can invoke, such as querying the Asset Map or creating a human task with human_tasks.
Steering
A message sent to an active run to adjust the agent’s focus or provide additional context. See Steering.