Glossary
Subsystem and category
The reverse-DNS subsystem and the category an os_log message is logged under, such as com.apple.TCC and access.
Code that logs with os_log can create a log object with a subsystem (reverse-DNS, for example com.apple.TCC or com.apple.DiskArbitration.diskarbitrationd) and a category within it (access, default…). They are stored in the catalog of each tracev3 file and are the most reliable way to filter logs, because they change far less than message wording.
In log show predicates they are subsystem == "…" and category == "…". See triage queries.