Product

Three planes. Two surfaces. One platform.

Sentinel Telemetry is one platform expressed as three planes — Visibility, Control, Protection — across two surfaces (coding-agent CLIs and AI desktop apps) and two scopes (the individual developer/user and the organization). Everything runs on your infrastructure.

  • Claude Code
  • OpenAI Codex
  • Gemini CLI
  • Kimi
  • ChatGPT
See it

Visibility

One pane instead of four vendor consoles — every coding agent, every seat, every dollar.

Unified spend

Token spend and cost tracking — API-equivalent cost by hour, day, week, model, project, and cost center.

Live sessions

Live context fill and activity per session, for every enrolled coding agent.

Search & recovery

Full-text search and transcript recovery across every session.

Budgets & alerts

Department rollups with budgets and alerts at 80% and 100%.

Chargeback exports

Chargeback and showback exports your finance team will actually trust.

Cross-agent comparison

"Claude vs Codex vs Gemini vs Kimi, this week" — real evidence for standardization decisions.

Govern it

Control

Approvals, org-wide policy, and MCP governance — fail-open under every failure mode.

Remote approvals

Approve or deny an agent's tool call from your dashboard or your phone. Fail-open under every failure mode — an approval that can't reach you never hangs an engineer. Per-session auto-mode covers long unattended runs.

Central policy distribution

Standing rules — "no agent may run curl | bash" — pushed to every enrolled machine and enforced by local fail-open hooks. One policy, org-wide, no per-team engineering.

ST Gate — the MCP gateway

ST Gate proxies every MCP client — CLIs, desktop apps, Cursor, Windsurf, VS Code — through one governed entry point. An approved-server registry decides what your people can reach; every tool call is audited; credential brokering keeps secrets out of client configs.

Protect it

Protection — ST Shield

A shared detection engine at three enforcement points: prompt pre-send, command pre-execution, and hub ingest.

Detection engine

Cards with Luhn validation, national IDs, keys and secrets, private keys, entropy heuristics, and org-custom patterns.

Policy actions

Block, redact, or flag — per pattern, per team, per enforcement point.

Shield dashboard

A disposition workflow for findings, with SIEM and webhook export.

Sensitive values are masked in every alert, log, and record. The DLP system never becomes the leak.

Desktop-app coverage: five layers.

Desktop AI apps can't run a local hook — so we cover them in depth, honestly.

LayerWhat it gives you
Compliance-API content Prompt/response content for managed enterprise accounts via each vendor's compliance API — OpenAI Compliance Logs Platform, Anthropic Compliance API, Google Vault for Gemini.
MCP tool-call governance Desktop apps that call MCP tools route through ST Gate, with the same registry and audit trail as CLIs.
Endpoint presence Which AI apps are installed and running, including unmanaged-account detection.
IdP / OAuth discovery Logins to AI services discovered through your identity provider.
Existing-stack integration Works with your CASB (Netskope, Zscaler, Purview) and enterprise browser. We integrate — we don't rebuild.

Honest limit: prompt content is available only for org-managed accounts. We deliberately never intercept personal accounts or scrape screens.

The identity graph.

All of it — CLI agents, desktop content, MCP tool-calls, endpoint signal, web/IdP — stitched to one employee identity in one RBAC dashboard. The view a department head actually wants, and the join nobody else does.

The identity graph CLI agents, desktop content, MCP tool-calls, endpoint signal, and IdP/OAuth logins are all stitched to one employee identity in one RBAC dashboard. CLI agents Desktop content MCP tool-calls Endpoint signal IdP / OAuth logins identity graph one employee RBAC dashboard

See the whole platform on your infrastructure.