Signature activation protocol (SAP)
The protocol that delivers signature activation data to the activation module, so a key on a server is only used under the signer's sole control.
The protocol that carries signature activation data from the signer's own environment to the signature activation module inside the server. It is the wire between "the signer approved this" and "the key may be used once, for exactly this document".
In the protection profile for a QSCD for server signing, CEN EN 419 241-2, the division of labour is explicit: the protocol delivers the SAD, and the module verifies its integrity and checks that it binds three things together - the signer's authentication, the data to be signed and the identifier of the signing key. Only then does the module activate the signature creation data in the cryptographic module. Module and cryptographic module together are the QSCD.
That is what makes remote signing defensible: without a protocol like this, a server holding your key would be signing on its own authority. With it, sole control survives the fact that the key never sits in your hands. The protocol is also where the assurance level shows: at SCAL2 the SAD has to be produced with something only the signer holds, so an operator cannot mint approvals.