FAQ

Questions about AI-workforce governance, answered.

Everything security, engineering, and finance leaders ask about governing AI coding agents and desktop apps — coverage, cost, MCP, data protection, deployment, and price. Still have a question? Talk to us →

Product basics

What is Sentinel Telemetry, and what is AI-workforce governance?

Sentinel Telemetry is a sovereign AI-workforce governance platform. It gives you unified visibility, control, and data protection across the AI coding agents and desktop apps your people use — deployed entirely on your own infrastructure. "AI-workforce governance" means seeing what every AI agent and app costs and does, controlling what they're allowed to do, and protecting sensitive data from leaking into them — all from one dashboard.

What is ST Gate?

ST Gate is our in-house MCP (Model Context Protocol) gateway. Every MCP client — CLIs, desktop apps, Cursor, Windsurf, VS Code — routes through one governed door with an approved-server registry, full tool-call audit, and credential brokering. Read the ST Gate page →

What is ST Shield?

ST Shield is the detection engine that flags and blocks PII, secrets, keys, and sensitive data before they enter a prompt or a command. It runs at three enforcement points — prompt pre-send, command pre-execution, and hub ingest — with block, redact, or flag actions, and masks sensitive values in every record.

What's the difference between AI coding agents and AI desktop apps?

Coding agents are terminal/CLI tools — Claude Code, OpenAI Codex, Gemini CLI, Kimi — that run commands against your code; we get full token, context, activity, transcript, and approval coverage. Desktop apps are the Claude, ChatGPT, and Gemini apps; we get usage, plus prompt/response content for org-managed enterprise accounts via each vendor's compliance API, and MCP tool-call governance.

Coverage

Which AI coding agents and desktop apps do you cover?

Coding-agent CLIs: Claude Code, OpenAI Codex, Gemini CLI, and Kimi — with full token, context, activity, transcript, and approval coverage. AI desktop apps: Claude, ChatGPT, and Gemini — usage everywhere, plus prompt/response content for org-managed enterprise accounts via each vendor's compliance API.

Does it work with Cursor, Windsurf, and VS Code?

Yes. Those editors reach MCP tools through ST Gate, so their tool calls are governed and audited under the same approved-server registry as CLIs and desktop apps.

Which LLM providers and models are supported?

Coverage spans Claude (Anthropic), ChatGPT and Codex (OpenAI), Gemini (Google), and Kimi. Spend is normalized to API-equivalent cost so you can compare providers side by side.

Can you see AI desktop-app conversations like ChatGPT or Claude?

For org-managed enterprise accounts only, via each vendor's compliance API — OpenAI Compliance Logs Platform, Anthropic Compliance API, and Google Vault for Gemini. We deliberately never intercept personal accounts or scrape screens.

Visibility & cost

How do I track AI coding agent token usage and cost?

Sentinel Telemetry unifies token spend and API-equivalent cost by hour, day, model, project, developer/user, team, and cost center — with budgets and alerts at 80% and 100%.

Can I do chargeback or showback for AI spend across teams?

Yes. Department rollups and chargeback/showback exports let finance attribute AI spend to the right cost center — the view a FinOps lead actually wants.

How do I track Claude Code and AI coding agent costs?

Sentinel Telemetry does cost tracking for Claude Code, OpenAI Codex, Gemini CLI, and Kimi — token spend and API-equivalent cost by developer/user, team, project, and cost center, with budgets and alerts. It's unified AI cost tracking and chargeback for your whole coding-agent fleet, in one dashboard.

Do you provide AI observability for coding agents?

Yes. Sentinel Telemetry is self-hosted AI observability for coding agents and desktop apps: live activity, context usage, session history, full-text transcript search, and unified spend — one pane instead of four vendor consoles.

Governance & control

How does MCP governance work?

ST Gate, our MCP gateway, proxies every MCP client — CLIs, desktop apps, Cursor, Windsurf, VS Code — through one governed entry point. It enforces an approved-server registry, audits every tool call, and brokers credentials so secrets never land in client configs.

Can I approve or block an AI agent's commands?

Yes. Approve or deny an agent's next command from your dashboard or your phone, run per-session auto-mode for long unattended runs, and push org-wide guardrails — like "no agent may run curl | bash" — to every machine. Every path is fail-open, so an approval that can't reach you never hangs an engineer.

How do I detect shadow AI or unmanaged AI accounts?

Through endpoint presence and unmanaged-account detection, IdP/OAuth login discovery, and integration with your existing CASB and enterprise browser — so logins to AI services surface even when they're outside your managed accounts.

Security & privacy

Does any data leave our infrastructure?

No. Sentinel Telemetry runs entirely on infrastructure you own — on-prem or your own cloud. There is no vendor-hosted SaaS, no data processor, and no phone-home. Licensing is an offline signed file, so the product is fully functional air-gapped.

Can I block secrets and PII before they reach an AI model?

Yes. ST Shield detects cards (with Luhn validation), national IDs, keys, private keys, entropy-based secrets, and org-custom patterns, and can block, redact, or flag them before they enter a prompt or a command. Sensitive values are masked in every alert and log — the DLP system never becomes the leak.

What happens if your software is down or slow?

Your engineers keep working. Fail-open is a hard release gate: no hook, gateway, or scanner may ever hang or block an agent if our software is down, slow, or wrong. We are in the path, never in the way — tested against four distinct failure modes.

Will this pass a works-council or GDPR review?

Sentinel Telemetry supports GDPR-conscious deployment: data minimization, retention controls, source-side redaction, RBAC, and DPIA-ready transparency. The active reporting level is always visible to the employee — no stealth mode exists. Lawful basis and employee notification remain the deploying organization's responsibility; we provide the controls that make a compliant deployment practical.

How do you protect employee privacy?

Sentinel Telemetry is transparent by construction. The active reporting level on a machine is always visible to that employee on their own dashboard, deployments start at anonymous metrics, and personal accounts are never intercepted. It is a governance tool, not surveillance.

Can our security team audit the code?

Yes. Sentinel Telemetry is source-available: licensed customers get full source to read, audit, and build. Nothing is a black box next to your credentials.

Is there self-hosted AI DLP for prompts and commands?

Yes. ST Shield is a purpose-built AI DLP engine that detects and blocks PII, secrets, and keys before they enter a prompt or a command — self-hosted, with masked audit and SIEM export. Nothing leaves your infrastructure.

Deployment & pricing

How is it deployed and how long does it take?

Deploy ST Hub on your own infrastructure via Docker Compose, Helm, or Terraform — or an offline bundle for air-gapped networks. Enroll machines with the lightweight stl agent, set your policies, and connect your integrations. Most teams are running in an afternoon.

Does it support air-gapped deployment?

Yes. An offline bundle deploys ST Hub in fully air-gapped networks, with offline signed licensing and no phone-home.

How is Sentinel Telemetry different from CASB, DLP, or an enterprise browser?

CASB, DLP, and enterprise browsers are blind to terminal coding agents entirely, and none join CLI, desktop, and MCP activity to one employee. Sentinel Telemetry was built for coding agents first, covers both CLI and desktop, and integrates with your CASB and browser rather than replacing them.

What does it cost?

Two tiers. SMB (under 25 developers/users) is a flat monthly rate with unified visibility and control. Enterprise (25+ developers/users) is priced per developer/user and adds data protection (ST Shield), ST Gate MCP governance, SSO/SCIM, full audit, and enterprise deployment. We don't publish list prices — talk to us for a quote and a full-featured demo on your own infrastructure. See pricing →

Still weighing it up?

See Sentinel Telemetry running on infrastructure you own.