Three planes. Two surfaces. One platform.
Sentinel Telemetry is one platform expressed as three planes — Visibility, Control, Protection — across two surfaces (coding-agent CLIs and AI desktop apps) and two scopes (the individual developer/user and the organization). Everything runs on your infrastructure.
- Claude Code
- OpenAI Codex
- Gemini CLI
- Kimi
- ChatGPT
Visibility
One pane instead of four vendor consoles — every coding agent, every seat, every dollar.
Unified spend
Token spend and cost tracking — API-equivalent cost by hour, day, week, model, project, and cost center.
Live sessions
Live context fill and activity per session, for every enrolled coding agent.
Search & recovery
Full-text search and transcript recovery across every session.
Budgets & alerts
Department rollups with budgets and alerts at 80% and 100%.
Chargeback exports
Chargeback and showback exports your finance team will actually trust.
Cross-agent comparison
"Claude vs Codex vs Gemini vs Kimi, this week" — real evidence for standardization decisions.
Control
Approvals, org-wide policy, and MCP governance — fail-open under every failure mode.
Remote approvals
Approve or deny an agent's tool call from your dashboard or your phone. Fail-open under every failure mode — an approval that can't reach you never hangs an engineer. Per-session auto-mode covers long unattended runs.
Central policy distribution
Standing rules — "no agent may run curl | bash" — pushed to every enrolled machine and enforced by local fail-open hooks. One policy, org-wide, no per-team engineering.
ST Gate — the MCP gateway
ST Gate proxies every MCP client — CLIs, desktop apps, Cursor, Windsurf, VS Code — through one governed entry point. An approved-server registry decides what your people can reach; every tool call is audited; credential brokering keeps secrets out of client configs.
Protection — ST Shield
A shared detection engine at three enforcement points: prompt pre-send, command pre-execution, and hub ingest.
Detection engine
Cards with Luhn validation, national IDs, keys and secrets, private keys, entropy heuristics, and org-custom patterns.
Policy actions
Block, redact, or flag — per pattern, per team, per enforcement point.
Shield dashboard
A disposition workflow for findings, with SIEM and webhook export.
Sensitive values are masked in every alert, log, and record. The DLP system never becomes the leak.
Desktop-app coverage: five layers.
Desktop AI apps can't run a local hook — so we cover them in depth, honestly.
| Layer | What it gives you |
|---|---|
| Compliance-API content | Prompt/response content for managed enterprise accounts via each vendor's compliance API — OpenAI Compliance Logs Platform, Anthropic Compliance API, Google Vault for Gemini. |
| MCP tool-call governance | Desktop apps that call MCP tools route through ST Gate, with the same registry and audit trail as CLIs. |
| Endpoint presence | Which AI apps are installed and running, including unmanaged-account detection. |
| IdP / OAuth discovery | Logins to AI services discovered through your identity provider. |
| Existing-stack integration | Works with your CASB (Netskope, Zscaler, Purview) and enterprise browser. We integrate — we don't rebuild. |
Honest limit: prompt content is available only for org-managed accounts. We deliberately never intercept personal accounts or scrape screens.
The identity graph.
All of it — CLI agents, desktop content, MCP tool-calls, endpoint signal, web/IdP — stitched to one employee identity in one RBAC dashboard. The view a department head actually wants, and the join nobody else does.