home/glossary/active entity

active entity

nounverified·updated Sep 1, 2026

The subject role in an access control model — an entity (generally an individual, process, or device) that causes information to flow among objects or changes system state, as opposed to a passive entity that merely contains or receives information. It is distinguished from a passive object by being the initiating party that requests access to an object or the data within an object; it may be a user, program, or process acting to accomplish a task. The field uses the active/passive distinction to anchor access controls — the security features that govern how users and systems communicate and interact with other systems and resources. The contrast class is equally stable: an object (passive entity) contains information and may be a computer, database, file, program, directory, or field in a table.

MWELegacy lexicon import

Senses

NIST SP 800-171r3attested usage reviewer confirmed

No definition is given in NIST SP 800-171r3. The term is attested in use at 1 citation in that document; a definition is pending curation.

Classifications

Entity Type

Identity85%manual reviewllm:claude-haiku-4-5
?unassignedlast reviewed

Sensitivity

unclassified

Information Class

unclassified

Variants

plural
active entities
possessive
active entity's
pluralpossessive
active entities'