Sentinel is the enforcement layer between your agents and everything they touch. Your security team watches every action, blocks what crosses policy before it runs, and proves every decision on a signed, tamper-evident record.
Deterministic, no model in the decision. Non-bypassable. In your own boundary.
Turn Sentinel on in alert mode and it takes no action. It watches every agent, builds a behavioral baseline, and hands your security team a record of what your agents actually did, with no developer friction and nothing blocked. When you have seen enough, move the controls to block mode and out-of-bounds actions are stopped at the pre-execution gate, before the side effect lands.
A few teams are building in this lane. Sentinel is the one that runs in process, stays deterministic, and gives the security team the console. Here is where the tools you already own fall short.
They can tell you Claude is installed. They cannot tell you what the agent did, and they go blind the moment it runs inside a container.
A proxy sits outside the agent. Put a model in the block path and it inherits the same prompt injection surface as the agent it is judging.
Claude Code's own hooks are the strongest free primitive, and Sentinel builds on them. What they lack: learned policy, a fleet console, a behavioral baseline, a signed trail, and a recovery loop.
Same enforcement underneath, two surfaces on top. The security owner sees the whole fleet and gets to the five things that need a human in ten seconds. The developer sees only their own work.
The console is the security team's surface. The developer sees one card: what stopped, why, and one button to release it. Hard rules stay locked.
Each enforcement decision is written to a per-project, Ed25519 signed, tamper-evident audit trail. Which agent, which action, which policy, and why. Running in process gives you provenance a proxy cannot reconstruct.
And when a stop is wrong, recovery is built in. At fleet scale false positives dominate over attacks, so the recovery loop is a first-class feature, not an apology.
Article 12 of the EU AI Act requires providers of high-risk AI systems to keep automatic records of events across the system's lifetime. Sentinel writes a signed, tamper-evident record of every agent action, allowed or denied, per project. It is designed to produce the records Article 12 describes, in place before the requirement lands.
Yes. Start in alert mode and Sentinel takes no action. It watches every agent, builds a behavioral baseline, and gives your security team a record of what your agents actually did, with zero developer friction. When you have seen enough, move the controls to block mode and out-of-bounds actions are stopped before they run.
Endpoint tools detect presence. They can tell you Claude is installed, not what the agent did, and they go blind when it runs in a container. A gateway sees traffic, not intent, and a model in the block path inherits the same prompt injection surface as the agent it is judging. Sentinel runs in process, at the semantic layer, deterministically, with no model in the decision.
The core is deterministic and runs in process, with no model on the block path. Credentials and hard rules are always decided that way. Only genuinely ambiguous cases can escalate to a model, and you choose which one. It runs in your boundary, never on Tuent's.
Sentinel builds on them. Native hooks are the strongest free primitive, and they are the floor we stand on. What they do not give you: policy that learns itself from your team's approvals and denials instead of hand-written shell commands, an operations console a security admin can run across the whole fleet, a behavioral baseline that catches intent drift rather than only static allow and deny, a signed tamper-evident audit trail, and a recovery loop for the false positives that dominate at scale.
Claude Code today, through a native hook. That is the only live integration to start. Support for additional runtimes is on the roadmap, and the policy model is built to extend without forking per tool.
No. Sentinel runs on-prem. Even model escalation uses an endpoint you bring, inside your own boundary, so nothing about your agents, code, or actions reaches Tuent.