Glossary

The agent-era B2B glossary

Model Context Protocol (MCP)

The Model Context Protocol (MCP) is an open standard, introduced by Anthropic in November 2024, that defines how AI applications connect to external tools and data sources. It gives models a uniform way to call functions and read resources, replacing the bespoke integration each vendor previously wrote for every tool.

Vendor evaluation

Vendor evaluation is the structured process of assessing candidate suppliers against defined requirements — capability, pricing, integrations, security, compliance and support — before selecting one. In B2B software it typically runs from a longlist through demos and questionnaires to a scored shortlist that justifies the final decision internally.

Total cost of ownership (TCO)

Total cost of ownership (TCO) is the full lifetime cost of a software purchase, not just its licence fee: implementation, data migration, integrations, training, internal administration, support tiers and the cost of eventually leaving. In SaaS evaluations, TCO is what makes two similar list prices resolve very differently.

Electronic Bookkeeping Act (電子帳簿保存法)

The Electronic Bookkeeping Act (電子帳簿保存法) is the Japanese law governing how tax-related books and documents may be kept electronically. It sets conditions for scanned documents and, since a phased tightening completed in January 2024, requires that data received electronically be retained in electronic form.

Japan's Invoice System (インボイス制度)

Japan's Invoice System (インボイス制度) is the qualified-invoice regime that took effect on 1 October 2023. To claim a consumption-tax input credit, a business must hold a qualified invoice issued by a registered invoice issuer, showing that issuer's registration number and tax amounts by rate.

Agent-to-agent commerce

Agent-to-agent commerce is a B2B transaction model in which AI agents representing a buyer and a seller exchange information — requirements, capabilities, pricing, compliance — and negotiate early deal stages autonomously, before humans meet. Humans keep final decision authority; the agents remove the repetitive discovery and qualification meetings that precede it.

A2A Protocol (Agent2Agent)

The Agent2Agent (A2A) Protocol is an open standard, announced by Google in April 2025 and later contributed to the Linux Foundation, that lets AI agents built on different frameworks and by different vendors discover each other, exchange messages securely, and collaborate on tasks — regardless of the underlying model or stack.

RFP automation

RFP automation is the use of software — increasingly AI agents — to compress the request-for-proposal cycle: generating requirement documents from plain-language needs, distributing them to qualified vendors, collecting structured responses, and scoring fit. It replaces weeks of manual document exchange and follow-up meetings with a parallel, structured process.

Ringi (稟議)

Ringi (稟議) is the Japanese corporate approval process in which a written proposal (ringi-sho) circulates among stakeholders and managers, each affixing an approval seal, before a decision — such as purchasing software — is finalized. It builds consensus before commitment, but adds significant lead time to B2B buying cycles in Japan.

RFI, RFP and RFQ

RFI, RFP and RFQ are the three sequential procurement documents buyers send to vendors. An RFI (request for information) surveys who exists and what they broadly do. An RFP (request for proposal) asks a shortlist how they would solve a defined problem. An RFQ (request for quotation) asks for firm pricing on an already-specified scope.

Security questionnaire

A security questionnaire is a structured set of questions a buyer sends a prospective vendor to assess how it protects data — covering access control, encryption, subprocessors, incident response, certifications and data residency. It is typically required before procurement approval, and answering it is a recurring cost for every vendor that sells to enterprises.

SOC 2

SOC 2 is an audit report, defined by the AICPA, on how a service organisation implements controls against the Trust Services Criteria: security, availability, processing integrity, confidentiality and privacy. A Type I report assesses control design at a point in time; a Type II report tests operating effectiveness across a period, commonly three to twelve months.

ISO/IEC 27001 (ISMS)

ISO/IEC 27001 is the international standard for an information security management system (ISMS) — a documented framework for identifying security risks and applying controls to them. Unlike SOC 2, it produces a certificate issued by an accredited certification body, valid for a fixed term with periodic surveillance audits.

Electronic Signature Act (Japan)

The Electronic Signature Act (電子署名法, Act No. 102 of 2000) is the Japanese law giving electronic signatures legal effect. Its Article 3 grants a presumption of authenticity to an electronic document signed by the principal using a signature only that person can perform — the provision that determines whether an electronic contract holds up in a Japanese court.

Certified timestamp (認定タイムスタンプ)

A certified timestamp (認定タイムスタンプ) is a time-attestation issued by a time-stamping operator accredited by Japan's Minister for Internal Affairs and Communications. It evidences that electronic data existed at a given moment and has not been altered since, and it is required for scanner-based retention of national-tax documents under 電子帳簿保存法.

Proof of concept (PoC)

A proof of concept (PoC) is a time-boxed trial run before purchase, in which a buyer tests whether a product actually works against its own data, systems and users. Unlike a demo, which the vendor controls, a PoC is designed to answer specific questions the buyer wrote down in advance.

Vendor lock-in

Vendor lock-in is the condition where switching away from a supplier costs more than staying, regardless of whether a better alternative exists. In SaaS it arises from data that is hard to extract, workflows built on proprietary features, integrations that would need rebuilding, and staff trained on one interface.

Agent Payments Protocol (AP2)

The Agent Payments Protocol (AP2) is an open, payment-agnostic standard, announced by Google in September 2025, that lets an AI agent prove a real user authorized a specific purchase. It uses cryptographically signed digital contracts called mandates to create a tamper-proof audit trail between agents, merchants and payment networks.

x402

x402 is an HTTP-native payment protocol, introduced by Coinbase in 2025, that revives the reserved HTTP status code 402 Payment Required. When an agent requests a paid resource, the server answers 402 with machine-readable payment instructions; the agent attaches signed payment proof (typically stablecoins) and retries — no account, card or human checkout involved.

llms.txt

llms.txt is a proposed web standard — published by Jeremy Howard in September 2024 — for a markdown file at a site's root that gives language models a concise, curated map of the site: what it is, and which pages matter, with links. It addresses LLMs' limited context windows the way robots.txt addresses crawler permissions.

Agentic Commerce Protocol (ACP)

The Agentic Commerce Protocol (ACP) is an open standard, maintained by OpenAI and Stripe, for connecting buyers, their AI agents and businesses to complete purchases. Live since September 2025, it powers ChatGPT's Instant Checkout: merchants expose structured catalogs and a checkout flow that an assistant can complete on the user's behalf.