AXIS Sentinel

Always on guard.Always watching.

Continuous security, operational intelligence and evidence preservation across the AXIS ecosystem. Sentinel observes every service, verifies every signal, and keeps the record intact when something goes wrong.

01

Observe

Continuous telemetry from every AXIS service and edge.

02

Verify

Signed SCEF telemetry, checked before it is trusted.

03

Detect

Anomaly, policy violation, and absent signal alike.

04

Protect

Policy enforced at the identity and tenant boundary.

05

Preserve

Evidence written down before it can be lost.

06

Recover

Continuity coordinated, state restored, result verified.

The problem

A system that stops reporting looks exactly like a system that is fine.

Most monitoring treats silence as health. Sentinel does not. Expected telemetry is tracked against received telemetry, every signal carries a signature that is checked before it is trusted, and an absent source is raised as a finding in its own right.

Visibility is part of security.

09:41:02.118axis-7d · policy.evaluate · tenant=acme · allowSIG OK
09:41:02.940cloudflare-edge · waf.challenge · ray=8f2c…a19SIG OK
09:41:03.406axis-core · session.privileged.open · actor=svc-deploySIG OK
09:41:04.771axis-ark · replication.lag · 240msSIG OK
09:41:05.233watchtower · source.silent · axis-telesis · 00:04:12UNVERIFIED
09:41:06.019evidence · ledger.append · seq=48 812 · sha256=c1f0…7b2SIG OK

Sample data. Sentinel never displays another organisation’s telemetry.

Capabilities

Five surfaces, one operating loop.

Enforcement, visibility, validation, record and recovery. Each is a distinct capability with its own telemetry and its own state, and each reports into the same command surface.

Enforcement

Guard

Security is active, continuous and policy-driven.

Guard enforces policy at the boundary: identity, tenant and workspace isolation, privileged activity control, secure execution limits and automatic response to anomalous behaviour.

  • policy-evaluation
  • tenant-boundary
  • privileged-session
  • execution-limit

Open Guard →

Visibility

Watchtower

Loss of visibility is itself a security event.

Watchtower tracks expected telemetry against received telemetry. A service that goes quiet is not assumed healthy — a coverage gap is raised, scored and worked like any other finding.

  • coverage-ratio
  • signal-gap
  • ingestion-lag
  • source-health

Open Watchtower →

Validation

Range

Failure is tested before production finds it.

Range is the mandatory adversarial validation environment. Guard, recovery, tenant isolation, prompt-injection resistance, evidence integrity and Sentinel's own control plane are exercised against controlled scenarios.

  • scenario-result
  • control-efficacy
  • regression
  • coverage-delta

Open Range →

Record

Evidence

Evidence survives the incident.

Ledger, Trace and Pulse. A durable event history, the means to reconstruct how a decision propagated, and the current operational state — with raw evidence preserved separately from its searchable index.

  • ledger-write
  • trace-span
  • pulse-sample
  • integrity-check

Open Evidence →

Recovery

Continuity

Security remains operational under pressure.

Safe Mode and COLOSSEUM coordination. Under a severe incident Sentinel preserves control, identity and evidence capture rather than shutting everything down, and verifies recovery once state is restored.

  • safe-mode-state
  • preservation-job
  • recovery-drill
  • restore-verification

Open Continuity →

Architecture

Sentinel FIRST LIGHT

Signed SCEF telemetry from AXIS services and the Cloudflare edge is verified on ingestion, indexed for search in PostgreSQL and preserved raw in R2. Ledger, Trace and Pulse are maintained from that record, and Sentinel Command presents the live state.

Every signal accounted for.

Read the architecture
Sentinel FIRST LIGHT data flowAXIS services and the Cloudflare edge emit signed SCEF telemetry. Sentinel ingestion verifies each signature, writes a searchable event index to PostgreSQL and preserves raw evidence in R2. Ledger, Trace and Pulse are maintained from that record, and Sentinel Command presents the resulting live state.AXIS Services7D · Core · ARK · Telesis · EliteCloudflare EdgeWorkers · Pages · WAF · AccessSigned SCEF Telemetrysignature required before trustIngestion + VerificationSentinel control planeEvent IndexPostgreSQL · searchableRaw EvidenceR2 · preserved intactLedger · Trace · Pulsehistory · reconstruction · stateSentinel Commandlive operational surface
Sentinel FIRST LIGHT — observation to command surface

Evidence

Ledger, Trace and Pulse.

Three distinct records: what happened, how it propagated, and what is true now. Kept separately because an investigation needs all three and they answer different questions.

Ledger

Durable history

Every security-relevant event, written once and retained. Tamper-evident by construction: entries are appended with their hash chain, and there is no edit path from inside the product.

Trace

Reconstruction

How a decision propagated. Trace follows a single event across services, policy evaluations and boundaries, so an investigator can answer what happened rather than infer it.

Pulse

Current state

What is true right now. Pulse carries live operational and security state — coverage, posture, active enforcement and open incidents — separate from the historical record.

Evidence survives the incident.

Incident

A worked sequence, end to end.

An unexpected privileged session, followed from first detection through to verified recovery. Sample data throughout.

  1. Detect

    Unexpected privileged session

    A privileged session opened against the deployment service outside any change window, from an actor with no scheduled work.

    event · guard.privileged-session · severity=high · confidence=94

  2. Verify

    Telemetry correlated across sources

    Sentinel correlated edge access logs, identity provider records and service telemetry. Every contributing signal carried a valid SCEF signature.

    trace · 6 spans · 3 sources · all signatures verified

  3. Contain

    Policy violation confirmed, Guard responded

    The session crossed a tenant boundary its credential was not scoped for. Guard revoked the session and blocked further privileged issuance for that actor.

    guard · session.revoke · tenant-boundary.enforce

  4. Preserve

    Evidence written before remediation

    Raw request bodies, identity assertions and the full decision trace were preserved to R2 and indexed, ahead of any cleanup that could overwrite them.

    ledger · 1 284 entries · evidence bundle 41.2 MB · hash recorded

  5. Respond

    Safe Mode invoked for the affected tenant

    High-risk writes, autonomous agents and new privileged sessions were paused for that tenant. Read access, identity and evidence capture stayed available.

    safe-mode · scope=tenant:acme · duration=00:38:11

  6. Recover

    COLOSSEUM state protected, recovery verified

    COLOSSEUM held a verified restore point throughout. Once the credential was rotated, Sentinel confirmed state integrity before Safe Mode was lifted.

    continuity · restore-point verified · integrity check passed

  7. Review

    Scenario added to Range

    The sequence was converted into a Range scenario so the same control path is exercised on every release rather than re-learned during the next incident.

    range · scenario added · gate=P0

Safe Mode

Degrade deliberately, not accidentally.

A security system that shuts down under pressure takes the investigation down with it. Safe Mode keeps identity, read access, evidence capture and incident response running while restricting the operations that could make things worse.

Security remains operational under pressure.

Degraded operation

Under a severe incident Sentinel preserves control, not comfort.

Remains available

  • Critical read access
  • Identity and authentication
  • Evidence capture and Ledger writes
  • COLOSSEUM preservation
  • Incident response tooling

Paused or restricted

  • High-risk writes
  • Autonomous agent execution
  • Deployments and releases
  • Bulk export
  • New privileged sessions
  • Nonessential integrations

Release validation

Two gates. No invented scores.

A numeric security rating compresses away the only thing worth knowing: whether this ships. Sentinel states release posture in operational language instead.

P0

Hard release blocker.

The release does not ship. There is no risk-acceptance path and no override.

P1

Ships only with documented risk acceptance.

A named owner, a written acceptance and a remediation date. Without all three it is treated as P0.

Failure is tested before production finds it.

Sentinel Command

See the operating picture.

Sentinel Command is the live operational surface: system status, security events, visibility coverage, evidence state and recovery readiness on one screen.