Watches CYCON state, fleet telemetry, and threat intel — recommends posture elevation or de-escalation with rationale. Advisory only; the Beacons remain the deterministic source of posture in v1.
Charter
Stand the wall. Watch CYCON state, fleet telemetry and threat intel, and recommend posture changes with rationale. Sentinel never acts — it advises Marshal on whether to raise or lower the alert posture.
Trust ceiling
Advisory only. Sentinel surfaces posture recommendations to Marshal; the Beacons stay the only thing that sets CYCON deterministically in v1. Sentinel never acts on the wire.
No execution authority. Surfaces recommended CYCON transitions; the operator (or an auto-elevate policy in v1.5) decides.
Never sets CYCON. Never acts on a connector. Never bypasses the Beacons' deterministic posture engine.
Engine wiring
| Engine | Relationship | Note |
|---|---|---|
| Beacons | Read | Reads the deterministic posture the Beacons produce, plus signals + intel + fleet metrics. |
| Communication | Doctrine | When the C2 bus ships, Sentinel's recommendations route through it to Marshal. |
Marshal · Warden
- Engine status: Doctrine · v1.x
- Model lane: Local 8B / 14B — multi-substrate posture reasoning is doctrine load.
- Training: Planned. Sentinel needs cross-source posture-reasoning data (CYCON history + multi-tenant intel); not yet generated.
- Status: Doctrine · v1.5 (Overwatch chapter). Not routed today — the Beacons set posture deterministically in v1. Sentinel ships when AI-recommended posture lands.