CCAR-P · Study Guide

← Glossary

Domain 3: Integration

Integration terms: tool scoping, auth gaps, RAG, protocols, and context strategy.

  • Capability bloat

    An oversized tool or agent surface — unused, overlapping, or role-mixed capabilities — that raises mis-selection risk and blast radius.

    Exam Fix by remove/merge/split before longer prompts or more tools.

    See also: 3.1 Capability bloat
  • Least privilege

    Grant each agent, credential, and tool only the actions and resources required for its role; remove unused capability rather than merely logging it.

    Exam Least privilege removes unused tools — confirmation dialogs are not a substitute.

    See also: 3.1 Capability bloat
  • Tool scope

    The bounded set of tools (and permissions) attached to an agent role. Narrow scopes improve selection and security reviews.

    Exam Split write/admin tools off customer-facing read agents when scopes collide.

    See also: 3.1 Capability bloat
  • AuthN vs AuthZ

    Authentication verifies identity; authorization decides what that identity may do to which resource. Both are required on agent tool paths.

    Exam If login works but admin tools still run, the gap is AuthZ.

    See also: 3.2 Auth security gaps
  • Accuracy–latency trade-off

    Configuration choices (model, retrieval depth, tool fan-out) move quality and speed together; architects quantify both against an SLA.

    Exam Accuracy gains that break a hard p95 without a waiver are no-ship.

    See also: 3.3 Accuracy–latency
  • Observability sampling

    At high volume, keep aggregates always-on and sample detailed traces with boosts on errors, outliers, and canary failures — with redaction.

    Exam Prefer strategic sampling over tracing everything or tracing nothing.

    See also: 3.4 Observability at scale
  • Chunking

    Splitting source documents into retrieval units. Structure-aware boundaries (clauses, Q+A, tables) beat blind fixed token windows.

    Exam One-size chunks that break clause meaning are a classic trap.

    See also: 3.5 RAG chunking & indexing
  • Embedding index

    The searchable vector (and often hybrid) store built from chunk embeddings. Upload to object storage is not the same as a live index.

    Exam After a corpus refresh, verify re-embed and index promote before blaming the model.

    See also: 3.5 RAG chunking & indexing
  • Provenance metadata

    Fields on chunks and citations (source URI, section, version, date, hash) that enable filters, audits, and grounding checks.

    Exam Metadata supports filtering and provenance — not optional decoration.

    See also: 3.5 RAG chunking & indexing
  • Hybrid retrieval

    Combining sparse/keyword and dense semantic signals (often with structured filters) so exact tokens and paraphrases both rank well.

    Exam SKU/error-code traffic that fails under dense-only usually needs hybrid or sparse.

    See also: 3.6 Retrieval strategies
  • MCP (Model Context Protocol)

    A shared protocol for exposing tools and resources to hosts/clients so multiple products can reuse one integration surface.

    Exam High reuse of tools/resources → MCP; narrow owned path → API/CLI may suffice.

    See also: 3.7 Connection protocols
  • Agent-to-agent

    Integration pattern where specialist agents communicate via explicit handoffs, keeping separate contexts and tool scopes.

    Exam Use for role isolation — not as a substitute for a shared tool catalog.

    See also: 3.7 Connection protocols
  • Progressive discovery

    Load only the files, chunks, or symbols needed for the next step (search → open → extract → summarize) instead of dumping a whole corpus.

    Exam Default for multi-GB or unknown corpora that cannot fit.

    See also: 3.8 Progressive vs monolithic
  • Monolithic context

    Packing a bounded, usually small and stable corpus into the prompt (often cached). Requires an honest token budget and headroom.

    Exam Fine for tiny stable packs; wrong as an every-turn strategy for huge repos.

    See also: 3.8 Progressive vs monolithic
  • Stable prefix caching

    Caching unchanging system/tool instruction prefixes to cut latency and cost on repeated calls without changing behavior.

    Exam Often the first latency win before upgrading model tier when accuracy already clears the floor.

    See also: 3.3 Accuracy–latency
  • Confused deputy (agent tools)

    Risk where an authenticated agent uses overly broad credentials or free-form IDs to act beyond the end-user’s entitlements.

    Exam Bind actions to verified session context and scoped credentials.

    See also: 3.2 Auth security gaps