Help

Glossary

Common Tahr terms used across applications, assessments, routines, and findings.

Last updated July 28, 2026
On this page

Use this page when a term in the Tahr interface is unfamiliar.

#Application

An application is a target Tahr can assess, including its URLs, access details, repository settings, and testing context.

#Assessment

An assessment is one execution of a Tahr testing workflow against an application. It may be started manually, scheduled, triggered from CI/CD, or run in a routine.

#Authenticated testing

Authenticated testing uses test users to exercise functionality unavailable to anonymous visitors.

#Finding

A finding is a security issue or observation produced by an assessment, with severity, evidence, affected areas, status, and review controls.

#Authorization finding

An authorization finding concerns access-control behavior, such as a user viewing or changing data they should not access.

#Attack path

An attack path connects observations into a larger exploitation chain and explains how smaller issues can combine into greater risk.

#Routine

A routine is an ordered set of assessment steps used to repeat a standard workflow.

#Portfolio

A portfolio groups applications by product, team, business unit, or environment.

#Verified domain

A verified domain proves that an organization controls a hostname and helps prevent accidental testing of assets it does not own.

#Reserved IP

A reserved IP is a dedicated IP useful when a target requires IP allowlisting.

#Assistant

Assistant is a planned organization-scoped chat for reviewing findings and assessment information. It is coming soon and is not currently available.

#Threat Modeling

Threat Modeling is an assessment and workspace for threats, attack paths, assets, assumptions, evidence, and recommended mitigations.

#Tahr context

Testing instructions is the application-level base field. A finding, authorization finding, or authorization matrix comment can be marked with Add this comment to testing instructions for future assessments. The saved comment has a Tahr context badge and remains attached to its finding or authorization review item. Tahr merges marked comments into effective instructions for future assessments without rewriting the application's Testing instructions field.

#Application Document

An application document is an uploaded file that adds context to supported workflows, especially Threat Modeling.

#Assessment Credit

An assessment credit is a unit used when Tahr starts an assessment type that shows a credit requirement.

#Source Code Diff Review

Source Code Diff Review examines repository changes since a selected source analysis commit.

#Routine Template

A routine template is a provided starting workflow that teams can copy when its assessment types are available.

Image preview