Skip to main content

Allowlist

An enforced list of the only permitted targets for a tool (vendors it may buy from, addresses it may email, records it may touch), so the agent can act only within a pre-approved set. An allowlist turns an open-ended judgment ("only buy what is necessary") into an enforced scope the machinery can check.

Defined in 2 GAGE programs, which carry 3 distinct definitions of it. The wording above is taught in Certified AI Governance Professional (CAIGP).

How each discipline defines it

The same term does different work depending on who is using it. These are the definitions as each program teaches them, unedited.

Certified AI Governance Professional (CAIGP)

An enforced list of the only permitted targets for a tool (vendors it may buy from, addresses it may email, records it may touch), so the agent can act only within a pre-approved set. An allowlist turns an open-ended judgment ("only buy what is necessary") into an enforced scope the machinery can check.

Certified Agentic AI Governance Professional (CAAGP)

A control that permits only a defined, approved set of commands or actions to execute, blocking or flagging anything not on the list; in Section 3, an allowlist that validated external commands but not certain shell built-ins.

Certified AI Governance Professional (CAIGP)

A named list of permitted destinations (recipients, systems, domains) an agent may reach, with everything else blocked by default. An allowlist fails safe: anything you did not consider is blocked. It is preferred over a blocklist, which fails open by allowing anything you forgot to prohibit.

Where it is taught

The exact lessons this term appears in. The first module of every program is free with a free account.

Terms it appears with

Not an alphabetical neighbourhood: these are the terms taught in the same lessons, ranked by how often they appear together.