System Brief // 2026
Sentinel Engine.
An autonomous SOC analyst for the Microsoft cloud. A language model reads the evidence; deterministic code computes the verdict. Every call is cited, reconstructable, and safe to put in front of an auditor — and it runs multi-tenant across live MSP clients today.
10–20%
of alerts ever reach a person
<5 min
average time to review an alert
24/7
always on, no gaps
Section
The short version
Four things to know before you read further.
Clears 80–90% of alerts on its own
Without waking anyone up, on a five-minute cadence against the live tree.
The model never decides
The LLM scores evidence against a fixed taxonomy. Deterministic code resolves the verdict from a matrix — the same inputs always produce the same call.
Every verdict cites its evidence
No "the model decided." Each call points back to the exact Microsoft source fields it was built from, and can be reconstructed line by line.
Sits on the Microsoft stack
Reads Sentinel, Defender XDR, Defender for Cloud Apps, Purview, Intune and Entra directly. No new agent to deploy.
Section
The problem it solves
Security teams are buried, and the work never stops.
1,000s
Volume
Alerts a week for a typical mid-sized company.
80%+
False alarms
Most are routine business activity that just looks suspicious.
3am
Coverage gap
A real attack at 3am still needs an answer at 3am.
Section
How it works
The same careful pipeline, on every alert, around the clock — with a hard line between what the model does and what only code does.
Every alert. Same pipeline.
01
Capture
Pull the alert and its raw source fields.
02
Context
Identity, devices, behavior, history.
03
Score (LLM)
Evidence weighed against a fixed taxonomy.
04
Decide (Code)
Deterministic matrix · cited verdict.
05
Write up
Plain-English finding + recommended fix.
06
Audit trail
Every weight and source logged.
The model reads the evidence. The verdict is math. The verdict is reconstructable — "the model decided" doesn't pass an audit, a reconstructable verdict does.
— Core design principle
Section
Three layers, one brain
Sentinel Engine is the reactive layer of a larger system: respond now, remember forever, prevent next time.
● LIVE
Respond — Reactive engine
Detect, investigate, score, compute a cited verdict, route. Live across multiple MSP tenants on different Microsoft tiers today.
◐ PARTIAL
Remember — god's Eye
A reputation memory that grades every entity it has ever seen by how unspoofable and how established the match is. Every tenant-day makes the next verdict sharper.
○ ROADMAP
Prevent — Proactive engine
Goal-driven hardening against Secure Score, HIPAA, CMMC. Reads the tenant's actual state, finds gaps, proposes graded fixes through the same safety gate.
Neither engine acts on its own. Every proposed action — respond or harden — passes one policy gate first and defaults to report-only. Autonomy without a blast radius.
Section
What makes it trustworthy
An automated analyst is only worth trusting if it's honest about its own limits. This one is built to be.
It tells the truth about what it knows
If it couldn't verify a detail, it labels it unverified rather than guessing. A confident wrong answer is worse than an honest "couldn't confirm".
It checks more than one source
If one of Microsoft's systems is slow, the engine has another way to get the answer instead of going blind.
It never goes silent
If it genuinely can't be sure, it hands the alert to a person with everything it found and a clear request to confirm.
It shows its work
Every decision — including every alert it closed on its own — is documented and explained.
It doesn't repeat itself
When one issue triggers a burst of alerts, they collapse into a single ticket instead of flooding the queue.
Section
What it watches
Three areas — the places attackers actually try to get in.
Identities
People's accounts
Suspicious logins, misuse of admin access, attempts to slip past security rules.
Data
Email & files
Sneaky mailbox forwarding rules, mishandled sensitive information, data-loss violations.
Devices
Laptops & phones
Signs of an attack on a machine, devices falling out of compliance, known security gaps.
Connects the dots. A small signal on an account plus an odd signal on a device get stitched into one clear story — not three disconnected alerts.
Section
What it decides
Every alert is scored on four orthogonal axes — Threat (how dangerous if it succeeds), Detection Confidence (did it actually happen), Maliciousness (hostile or expected), and Impact (how protected the target, how wide the blast radius). The language model scores each individual piece of evidence against a fixed taxonomy. It never emits a verdict. Deterministic code reads those scores and computes the verdict from a Threat x Maliciousness matrix. Benign evidence can never reduce Threat. Any signal without a real Microsoft source is dropped before scoring. Ambiguity does not get guessed — it routes to a human.
Low
Closed automatically
Matrix outcome: benign or expected activity, documented and reconstructable.
Medium
Queued for a quick human look
Matrix outcome: ambiguous or policy-sensitive, handed off with a suggested fix.
High
Escalated immediately
Matrix outcome: confirmed malicious or high blast radius, full picture attached.
Every ticket arrives with a fix
Every ticket — at every level — arrives with a recommended next step: the specific change to make, where to make it, and why.
Section
What changes
A typical mid-sized company, before and after.
Consistency
Every alert handled the same way.
Audit-ready
Every verdict reconstructable from its cited signals. Posture measured against CIS benchmarks.
Retained knowledge
What it learns about your environment stays.
It doesn't replace your people. It takes the repetitive work off their plate — so your senior staff focus on real threats and the genuinely tricky calls.
Section
Who it's for
Primary
Managed Service Providers
Offer security monitoring as a service — where every new client adds revenue, not another body to hire.
Secondary
Mid-sized companies
Running on Microsoft 365 with a small, stretched security team.
Strong-fit checklist
- Microsoft 365 Business Premium or above
- Ticketing system in place (Jira, ConnectWise, Autotask)
- Staff losing hours to alert triage
- Needs consistent compliance documentation
- Wants native integration — nothing to install
- Ready to free senior staff for real work
Machines handle the repetitive work. People handle the judgment.
A real step-change in how security alerts get handled — not a minor tune-up.
Start a deployment evaluation