Advanced Search
Search Results
141 total results found
Lethal-trifecta enforcement
The one detector that is about a combination rather than a thing. Default: warn. The idea An AI agent becomes dangerous when three capabilities meet in the same context: Access to private data — your repository, your database, your issue tracker. Exposure to u...
The prompt-injection classifier
A model, rather than a pattern, judging whether a request is being manipulated. How it runs The classifier runs in parallel with the upstream call, so it does not add latency to your developers' requests. In Activity you can see how long it took — the millisec...
Connection modes
Per tool, whether requests run on the developer's own AI subscription or on your organization's provider key. The two modes Subscription — the developer's own plan pays. Sentilai governs and audits; billing is unchanged. Managed API key — the request goes out ...
Device sessions
How long a developer's machine may keep working without signing in again. The two settings Policy → Device sessions: Idle timeout (hours) — a device that has not been used for this long stops working. Max age (days) — a device stops working this long after enr...
Local MCP decision cache
Policy → Local MCP decision cache (seconds), from 0 to 3600. What it controls When an AI tool calls a local MCP server, the Sentilai shim on the developer's machine asks the Gateway whether to allow it. This setting is how long the shim may reuse that answer f...
Blocked conversations
When the classifier stops a conversation, it appears at the bottom of the Policy screen — and this is where you let it continue. What you see Each entry names the developer, the tool, the reason the classifier gave, the severity, and when it happened. Unblocki...
Log retention
How long Sentilai keeps your audit events, findings and any captured prompt content. Where it is Policy shows it as a read-only card. It is currently set by Sentilai support rather than by you — open a ticket from Support and tell us the number of days you nee...
Which provider key you need
A provider key is what lets Sentilai make the actual AI request on your behalf. You only need one for tools running in managed API key mode — tools on a developer subscription do not touch it. Matching keys to tools Claude Code in managed mode needs an Anthrop...
Two keys of the same type
You can have several keys of the same provider type — a cheap one for general use, an expensive one for a specific team. Sentilai picks between them using the enabled models list. The rule Sentilai looks at the model the request asks for and finds the key whos...
Set up an alert channel
Nobody watches a dashboard. Alerts put the findings that matter into the place your team already looks. Adding a channel Policy → Real-time alerts → add a channel: Kind — Slack, Microsoft Teams, or a generic JSON webhook. Name — how it appears in the list. Nam...
What alerts are for
The delivery guarantee Alerts are fire-and-forget. Delivery is attempted alongside the request, never in front of it: a Slack outage cannot slow down or fail your developers' AI traffic. The trade-off is that an alert can be lost if the destination is unreacha...
Glossary
Admin — someone who uses the console. Manages policy, people, providers and billing. Consumes a seat. Agent — an AI assistant that can act, not only answer, by calling tools. Blocked — a request or tool call your policy stopped. Not an error. Developer — someo...
All policy settings at a glance
Everything on the Policy screen, with its default. MCP Setting Default Notes MCP default action Warn Allow / Warn / Report / Block. Per-server rules override it Require approval for new MCP servers Off Unreviewed servers get the pending action Pending action W...
The four policy actions
Every rule in Sentilai resolves to one of four actions. They mean the same thing wherever they appear. Allow Nothing beyond the ordinary audit row. Use it to carve an exception out of a stricter default — for example, a default of Block with explicit Allow rul...
What Sentilai does not do
Reading a list of a security product's limits is a better use of five minutes than reading its feature list. Here is ours. It does not cover ungoverned machines A personal laptop with a personal API key never touches the Gateway and is invisible to Sentilai. W...
Open a support ticket
Support lives inside the console, so you do not have to prove who you are or which organization you belong to — we already know. Opening one Support → New ticket: Subject — specific beats polite. "Cursor requests failing with 424 since Tuesday" gets a faster a...
Ticket statuses and what happens next
The statuses Open — received, not yet picked up. In progress — someone is working on it. Waiting on customer — we have asked you something and are waiting. Resolved — we believe it is fixed. Closed — finished. The timeline A ticket shows messages and events to...
The SSO enrollment wizard
Connecting your identity provider is eight steps, and the wizard will not let you activate something that has not been proven to work. The steps Provider — Google Workspace, Microsoft Entra ID, generic OIDC, or generic SAML. (Password + MFA is shown for refere...