Start here About 3 min read
Glossary and conventions
A camera vendor, an access control engineer and a developer can use the same word differently. These definitions explain how terms are used throughout the wiki.
Sources and scopeSource record 25 August 2026
Technical source record: 25 August 2026. Check the linked documentation for current product requirements.
Core cross domain terms only; protocol specific glossaries remain on protocol pages.
On this page
Core terms#
| Term | Meaning in this library |
|---|---|
| Actuation | A request or signal capable of changing a physical or security relevant state. |
| API | A defined software interface. “REST API” does not by itself specify authentication, schema, or delivery semantics. |
| Command | An expression of requested intent; not proof of acceptance or physical completion. |
| Conformance | Evidence that an implementation satisfied a named test/claim for a specific standard edition, profile, role, and version. |
| Controller | A component that evaluates logic and/or drives field outputs. Context must say camera, access, industrial, or other controller. |
| Credential | Data or an artefact presented in an authentication process; not automatically a person or authorisation. |
| Device identity | Identity of hardware/software in a protocol or trust system. It is distinct from operator, user, credential, and workload identity. |
| Event | An immutable report that something was observed or decided at a time; delivery may be repeated, delayed, reordered, or lost. |
| Fail safe | Failure leads toward the defined safer condition. This is a hazard decision, not synonymous with electrically unlocked. |
| Fail secure | Failure preserves the defined security condition. It does not override life safety and egress requirements. |
| Gateway | A boundary component translating transport, protocol, data model, trust, or policy. State what it translates. |
| Integration | A designed exchange between systems, including ownership, semantics, security, failure and lifecycle. |
| Interoperability | Two implementations perform the intended use case together. It is narrower than “both support protocol X.” |
| Metadata | Data describing or accompanying other data, such as video analytics objects or provenance. It can itself be sensitive. |
| Observation | Data received without an intended control effect. Subscription setup or acknowledgement may still create a control path. |
| Profile | A selected, testable set of requirements from one or more specifications. Profile names are not protocol versions. |
| Restore | A report that a previously active condition is no longer active; not deletion or negation of the original event. |
| State | The current model of a property, usually reconstructed from snapshots, events, polling, and local assumptions. |
| Supervision | Detection of path/device/circuit conditions such as open, short, substitution, loss, or timeout. |
| Trust boundary | A point where identity, administration, exposure, or assurance changes and policy must be enforced. |
| VMS / VSaaS | Video management system / video surveillance as a service. Deployment model does not determine interface openness. |
Protocol and layer conventions#
- Ethernet, RS485, RS232, radio, and dry contacts are media/electrical or physical interfaces, not interchangeable application protocols.
- TCP, UDP, TLS, HTTP, RTP, MQTT, OSDP, and ONVIF occupy different layers or define different sets of behaviour. Avoid “runs over IP” as a complete architecture description.
- A registered port is a default or service convention, not evidence that traffic is present, authentic, or safe.
- “Secure” is qualified: confidentiality, integrity, peer authentication, user authorisation, replay resistance, key management, secure update, and audit are separate properties.
Naming and files#
- Files and folders use lowercase ASCII
kebab-case. - Acronyms are expanded on first use in prose unless universally clear in the immediate context.
- Dates use ISO
YYYY-MM-DD; times should include an offset orZand identify source clock. - Byte and bit positions start at zero only when the source convention is stated.
- Network examples use RFC 5737 IPv4, RFC 3849 IPv6,
.example, or loopback space. - Secrets use descriptive placeholders such as
${DEVICE_TOKEN}; never plausible sample secrets.
Requirement language#
Uppercase MUST, SHOULD, MAY, and related terms are used only in attributed summaries of a normative document that defines those terms. Knowledge base advice uses “require,” “prefer,” “consider,” and “avoid,” with rationale.
Status language#
| Label | Meaning |
|---|---|
| current | Final and supported in the stated ecosystem |
| release candidate | Not final; details and conformance availability may change |
| legacy | Deployed and relevant, but generally not preferred for new design |
| deprecated | Publisher has announced withdrawal/end of support or replacement |
| historical | Retained to understand installed systems, not current implementation guidance |
| mixed | Depends materially on edition, profile, product, or deployment mode |
See the metadata schema for controlled values.