Passive Observer — An entity that sees data during normal operation without acting maliciously (e.g., LLM providers receiving tool I/O over the API, log aggregators, analytics pipelines, training-data collectors). Used to frame confidentiality harms that arise from visibility, not attack. Every SD involving a secret that crosses an external-service trust boundary should include at least one passive-observer framing.
Dominated Threat — A threat whose attacker capabilities are strictly weaker than those of another threat already accepted as out-of-scope. Dominated SDs are pruned because their residual-risk statements collapse to tautologies (e.g., “equivalent to full user-account compromise”). They contribute no new information and dilute the signal of the SD document.
Exposure Window — The bounded duration a secret is accessible in a less-protected context (e.g., a password held in child-process environment variables during an unlock operation). When Accepted Goal Status justifies residual risk on the grounds that exposure is “brief” or “short-lived”, the window MUST be quantified (typical and worst-case duration).