---
title: Glossary
description: The terms used in Advisor and in the documentation, with the definition of each one.
updated: 2026-09-27
---

The Portuguese term used in the interface is shown in parentheses.

| Term | Meaning |
|---|---|
| **Analysis agent** | The Advisor component that analyzes every spike incident and issues a verdict: **Ataque** (Attack), **Benigno** (Benign) or **Inconclusivo** (Inconclusive). |
| **Baseline** | A spike rule's normal volume: the median of the same time of day over the last days. |
| **Collection** (coleta) | The periodic read of the Cloudflare account. It runs every day at 02:00 (Brasília time). |
| **Connection** (conexão) | The read-only link between the tenant and a Cloudflare account. |
| **Domain** (domínio) | A DNS name, such as `example.com`. In Advisor, "domain" is never a synonym for pillar. |
| **Impact** (impacto) | How many points the score gains when a risk is resolved. |
| **Incident** (incidente) | The record opened when a spike rule detects abnormal traffic. |
| **Knowledge base** (base de conhecimento) | Context about your business that the analysis agent reads, such as allowed origins and maintenance windows. |
| **Maturity Score** (Score de Maturidade) | A 0 to 100 score, with an A to F grade, summarizing security posture. Refer to [Maturity Score](/en/advisor/conceitos/score-de-maturidade/). |
| **Observation mode** (modo observação) | A spike rule state that records incidents without sending alerts. Used for calibration. |
| **Penalty** (penalidade) | A rule that takes points away from the score. It cannot be accepted and only stops counting once the configuration is fixed. |
| **Pillar** (pilar) | A group of score rules: Transport/TLS, WAF & Rules, Edge & Bots, Identity & Access. |
| **Playbook** | The defined reaction to an attack verdict from the analysis agent: record the action or propose it for approval. |
| **Risk** (risco) | A score rule the zone does not meet (**Não conforme** or **Parcial**). |
| **Risk acceptance** (aceite de risco) | A record that a risk is known and tolerated. It removes the rule from the score, with a justification and an optional expiry. Refer to [Risks and acceptance](/en/advisor/conceitos/riscos-e-aceite/). |
| **Rule (score)** (regra) | A configuration item Advisor checks in each zone. |
| **Severity** (criticidade) | How serious a risk is: **Crítica** (Critical), **Alta** (High), **Média** (Medium) or **Baixa** (Low). |
| **Spike rule** (regra de pico) | A traffic condition Advisor watches, opening incidents when volume breaks the normal pattern. |
| **Tenant** | Your organization's space in Advisor, with its own members, connection and settings. |
| **Window** (janela) | The 5-minute interval used to measure traffic in spike rules. |
| **Zone** (zona) | A domain set up in Cloudflare. It is the unit the score evaluates. |

---

> Guardnet Docs · https://docs.guardnet.com.br/en/advisor/referencia/glossario/
> Documentation index: https://docs.guardnet.com.br/en/llms.txt
