Skip to main content

Policy and risk detection

Risk detectors, AI classifier, blocking, sensitivity.

Overview

Policy & risk detection Every outbound AI request is scanned before it leaves, by layered detecto...

MCP default action

This is the rule the Gateway applies to an MCP server that has no explicit rule of its own. Set i...

Approval for new MCP servers

Turn on Require approval for new MCP servers when you want unknown servers held back until someon...

Risk classifier sensitivity

The risk classifier inspects outbound prompts for things that shouldn't leave — secrets, personal...

Prompt capture

Off by default, and the setting that deserves the most thought before you turn it on. What it doe...

Egress blocklist

Policy → Egress blocklist controls which network destinations the Endpoint Suite allows AI tools ...

How a policy decision is made

Several things can have an opinion about a single request. This is the order they are consulted, ...

Secret scanning

Stops credentials from leaving your organization inside a prompt. Default: warn. This is the dete...

Credentials in context

Catches credentials that do not match a known vendor format — internal tokens, database passwords...

Personal data (PII)

Flags personal data appearing in prompts. Default: report. What it detects Email addresses Intern...

Lethal-trifecta enforcement

The one detector that is about a combination rather than a thing. Default: warn. The idea An AI a...

The prompt-injection classifier

A model, rather than a pattern, judging whether a request is being manipulated. How it runs The c...

Connection modes

Per tool, whether requests run on the developer's own AI subscription or on your organization's p...

Device sessions

How long a developer's machine may keep working without signing in again. The two settings Policy...

Local MCP decision cache

Policy → Local MCP decision cache (seconds), from 0 to 3600. What it controls When an AI tool cal...

Blocked conversations

When the classifier stops a conversation, it appears at the bottom of the Policy screen — and thi...

Log retention

How long Sentilai keeps your audit events, findings and any captured prompt content. Where it is ...

Ungoverned-agent policy

On Policy → Ungoverned AI agents you choose what happens when an autonomous AI agent Sentilai doe...