Ledger
Durable history
Every security-relevant event, written once and retained. Tamper-evident by construction: entries are appended with their hash chain, and there is no edit path from inside the product.
AXIS Sentinel
Continuous security, operational intelligence and evidence preservation across the AXIS ecosystem. Sentinel observes every service, verifies every signal, and keeps the record intact when something goes wrong.
01
Observe
Continuous telemetry from every AXIS service and edge.
02
Verify
Signed SCEF telemetry, checked before it is trusted.
03
Detect
Anomaly, policy violation, and absent signal alike.
04
Protect
Policy enforced at the identity and tenant boundary.
05
Preserve
Evidence written down before it can be lost.
06
Recover
Continuity coordinated, state restored, result verified.
The problem
Most monitoring treats silence as health. Sentinel does not. Expected telemetry is tracked against received telemetry, every signal carries a signature that is checked before it is trusted, and an absent source is raised as a finding in its own right.
Visibility is part of security.
Sample data. Sentinel never displays another organisation’s telemetry.
Capabilities
Enforcement, visibility, validation, record and recovery. Each is a distinct capability with its own telemetry and its own state, and each reports into the same command surface.
Enforcement
Security is active, continuous and policy-driven.
Guard enforces policy at the boundary: identity, tenant and workspace isolation, privileged activity control, secure execution limits and automatic response to anomalous behaviour.
Open Guard →
Visibility
Loss of visibility is itself a security event.
Watchtower tracks expected telemetry against received telemetry. A service that goes quiet is not assumed healthy — a coverage gap is raised, scored and worked like any other finding.
Open Watchtower →
Validation
Failure is tested before production finds it.
Range is the mandatory adversarial validation environment. Guard, recovery, tenant isolation, prompt-injection resistance, evidence integrity and Sentinel's own control plane are exercised against controlled scenarios.
Open Range →
Record
Evidence survives the incident.
Ledger, Trace and Pulse. A durable event history, the means to reconstruct how a decision propagated, and the current operational state — with raw evidence preserved separately from its searchable index.
Open Evidence →
Recovery
Security remains operational under pressure.
Safe Mode and COLOSSEUM coordination. Under a severe incident Sentinel preserves control, identity and evidence capture rather than shutting everything down, and verifies recovery once state is restored.
Open Continuity →
Architecture
Signed SCEF telemetry from AXIS services and the Cloudflare edge is verified on ingestion, indexed for search in PostgreSQL and preserved raw in R2. Ledger, Trace and Pulse are maintained from that record, and Sentinel Command presents the live state.
Every signal accounted for.
Read the architectureEvidence
Three distinct records: what happened, how it propagated, and what is true now. Kept separately because an investigation needs all three and they answer different questions.
Durable history
Every security-relevant event, written once and retained. Tamper-evident by construction: entries are appended with their hash chain, and there is no edit path from inside the product.
Reconstruction
How a decision propagated. Trace follows a single event across services, policy evaluations and boundaries, so an investigator can answer what happened rather than infer it.
Current state
What is true right now. Pulse carries live operational and security state — coverage, posture, active enforcement and open incidents — separate from the historical record.
Evidence survives the incident.
Incident
An unexpected privileged session, followed from first detection through to verified recovery. Sample data throughout.
Detect
A privileged session opened against the deployment service outside any change window, from an actor with no scheduled work.
event · guard.privileged-session · severity=high · confidence=94
Verify
Sentinel correlated edge access logs, identity provider records and service telemetry. Every contributing signal carried a valid SCEF signature.
trace · 6 spans · 3 sources · all signatures verified
Contain
The session crossed a tenant boundary its credential was not scoped for. Guard revoked the session and blocked further privileged issuance for that actor.
guard · session.revoke · tenant-boundary.enforce
Preserve
Raw request bodies, identity assertions and the full decision trace were preserved to R2 and indexed, ahead of any cleanup that could overwrite them.
ledger · 1 284 entries · evidence bundle 41.2 MB · hash recorded
Respond
High-risk writes, autonomous agents and new privileged sessions were paused for that tenant. Read access, identity and evidence capture stayed available.
safe-mode · scope=tenant:acme · duration=00:38:11
Recover
COLOSSEUM held a verified restore point throughout. Once the credential was rotated, Sentinel confirmed state integrity before Safe Mode was lifted.
continuity · restore-point verified · integrity check passed
Review
The sequence was converted into a Range scenario so the same control path is exercised on every release rather than re-learned during the next incident.
range · scenario added · gate=P0
Safe Mode
A security system that shuts down under pressure takes the investigation down with it. Safe Mode keeps identity, read access, evidence capture and incident response running while restricting the operations that could make things worse.
Security remains operational under pressure.
Degraded operation
Under a severe incident Sentinel preserves control, not comfort.
Remains available
Paused or restricted
Release validation
A numeric security rating compresses away the only thing worth knowing: whether this ships. Sentinel states release posture in operational language instead.
P0
Hard release blocker.
The release does not ship. There is no risk-acceptance path and no override.
P1
Ships only with documented risk acceptance.
A named owner, a written acceptance and a remediation date. Without all three it is treated as P0.
Failure is tested before production finds it.
Sentinel Command
Sentinel Command is the live operational surface: system status, security events, visibility coverage, evidence state and recovery readiness on one screen.