Developers
Integrate a service in four steps.
A service that cannot be observed cannot be defended.
Sentinel integration is deliberately small: emit signed events, declare what you expect to emit, carry the actor and tenant, and read state back from Pulse rather than reconstructing it.
Emit signed events
A service emits SCEF events over the ingestion endpoint, signed with its service key. The signature is verified before the event is trusted; unsigned or unverifiable events are retained and reported rather than accepted.
Declare expected coverage
Register what your service should emit and how often. Watchtower reconciles received against expected, which is what allows silence to be detected instead of assumed benign.
Carry the actor
Include the authenticated actor and tenant scope on every event. Guard resolves policy against these, and Trace uses them to reconstruct how a decision propagated.
Read state, do not poll logs
Pulse exposes current operational and security state. Ledger and Trace answer historical questions. Reading these is cheaper and more accurate than re-deriving state from raw logs.
Event shape
What an event looks like on the wire.
A verified ingestion window. Each line carries its source, action, scope and signature state.
Illustrative shape only. Signing keys, endpoints and credentials are issued per deployment and are never published here.
Validation
Your integration is exercised in Range.
A new source is not considered integrated when it first delivers an event. It is integrated when Range has confirmed that its telemetry survives queue failure, that its silence is detected, and that its tenant scope holds under a forged claim.