Working on AI agents as a PM meant learning a new vocabulary pretty quickly, often mid-meeting and occasionally by nodding like I understood something and Googling it five minutes later.
These are the ones that stuck.
The basics
Agent. Software that can take actions for you. A chatbot tells you how to fix a bug. An agent opens the file and tries to fix it.
Agentic. Usually means the AI is doing multi-step work with some independence. This word gets stretched, so I usually ask what the thing actually does.
Tool call. When an agent reaches outside the model to do something: read a file, search the web, create a ticket, run a test.
MCP. A standard way for agents to connect to tools and data. Increasingly the plumbing behind “Claude can use our product now.”
CLI. A command-line tool. Suddenly cool again because agents are very comfortable in terminals.
Context window. How much information the model can work with at once. Long sessions make this painfully tangible.
How agents get work done
Skill. Instructions for doing a specific job the way you want it done. Basically onboarding docs for a very fast new coworker.
Subagent. A helper agent spun up to handle one part of a larger task.
Orchestration. Coordinating those agents and pulling their work back together. Sounds fancier than “who is doing what?”
Routine. An agent running on a schedule with nobody watching it.
Harness. Everything wrapped around the model: tools, instructions, memory, checks, permissions. Same model, very different product depending on the harness.
How I check the work
Hallucination. The model confidently makes something up. Always fun.
Grounding. Giving it real sources so you can check where the answer came from.
Evals. Repeatable tests for AI behavior. Useful when “it feels better” stops being a satisfying metric.
Adversarial review. Asking another agent to poke holes in the first agent’s work. Surprisingly effective.
Where things get spicy
Guardrails. Rules around what an agent is allowed to do.
Authorization. Whether you can do something.
Delegation. Whether you’re happy letting an agent do it while you’re off making coffee.
Human in the loop. A person has to approve before the agent continues. Add too many and everyone starts clicking yes without reading.
Elicitation. The system asking a person for information or confirmation.
Prompt injection. Instructions hidden inside something the agent reads. A webpage can basically whisper bad ideas to your agent.
Lethal trifecta. Simon Willison’s term for an agent that can see private data, read untrusted content, and send information somewhere else.
What I ask now
Knowing the vocabulary makes technical conversations easier to follow.
When someone says something is “agentic,” I want to know what the agent can actually do, what it can touch, and when it has to ask a human.
That usually tells me more than the fancy word.
