Sentinel
Status: v1.0.0 shipped (2026-08-08), monitor-only, Windows (amd64). Access is by request at griff.run/contact?interest=sentinel.
Page updated 2026-08-10 against the live platform.
You cannot govern what you cannot see. Agents act fast and leave thin trails. Sentinel watches agent activity where it happens — locally — and turns it into an evidence-grade record you control, without touching the agents themselves.
What v1.0.0 does
- Observes agent activity on the workstation and assembles a signed, tamper-evident record of what ran.
- Monitor-only by design: Sentinel changes nothing about the agents it observes. See everything; change nothing.
- Evidence-grade output: the record is provable — if it were altered, verification fails loudly.
What ships with the release
| Artifact | Purpose |
|---|---|
| Signed archive | The distributable itself is signature-verified. |
| SBOM | Full software bill of materials for the release. |
| License evidence | Licensing recorded with the release, not implied. |
| Provenance checks | Provenance is re-verified at deploy and on every managed start. |
Boundaries are the feature
A security monitor must not be another risk. v1.0.0 is deliberately scoped: monitor-only, single-platform (Windows amd64), verified end to end before it runs. Broader platform coverage and response capabilities are roadmap, not current claims.