Sentinel watches every financial event, scores it against 18 deterministic rules and each actor's own learned statistical baseline, and never moves money without a human at the irreversibility points. It learns what "normal" is for every employee, vendor and customer — and adjusts when a reviewer tells it so.
Every detection — from a tiny write-off anomaly to a full ghost-vendor scheme — runs the same loop. Four bounded agents own it end to end. Hover a stage.
Watches everything, scores everything. Never writes alerts, never speaks. Full autonomy — no human in the loop.
Composes scores into verdicts and packages evidence. Bounded by the Verdict Gate ceiling on every alert.
The only agent that touches host systems or can halt money movement. Most legal weight, tightest authority.
Speaks to the owner under the Graded Language Protocol and records every outcome back into the baseline.
Logs & scores; updates the profile; surfaces in the next briefing. Fully reversible — no action taken.
Surfaces as a proposal and pauses the workflow. Owner confirms or rejects. Nothing irreversible yet.
Holds the workflow; routes to a second actor in the approval chain who approves or denies.
Halts the workflow, opens a case, alerts the owner. Reversible only with explicit human override.
No black box. Sentinel compares a transaction to the actor's own history with one robust statistic. Drag the write-off amount and watch the math, the severity, and the plain-language verdict update live.
Baseline shown is the design-doc worked example: employee E-481, a stable history of $50–$300 discretionary write-offs. Try sliding to $847.
Sentinel keeps two baselines. The LEARNING baseline drives detection and only absorbs events a human has cleared. The SHADOW baseline absorbs everything — its job is to reveal drift the alerts are holding back. This is the defense against a fraudster slowly normalising their own behaviour.
Feed E-481 events. Normal ones are absorbed automatically. A flagged one is quarantined and waits for your call — clear it as normal and watch Sentinel learn, or confirm fraud and watch it refuse to.
Mechanism shown: HIGH/CRITICAL alerts are held from the LEARNING baseline (QUARANTINE_HELD) until a case is dispositioned. RESOLVED_LEGITIMATE → replay-on-release inserts the event into the learning baseline in canonical order. RESOLVED_FRAUD_CONFIRMED → LEARNING_EXCLUSION, permanently kept out. The SHADOW baseline takes every event regardless, so the gap between the two surfaces systematic drift.
Tier 1. Every rule runs synchronously on every event inside a 50 ms budget, is replay-testable, and is never subject to warm-up suppression — they fire from Day 1. Click any rule.
Real schemes fire several rules in sequence. The orchestrator recognises these and escalates.
An actor creates & self-approves a fake vendor whose address matches their own, then changes its banking. Two+ firing within 30 days → CRITICAL.
A banking-change at the vendor plus a payment landing on the wrong destination. Both on one chain → CRITICAL + SMS.
Same-actor SoD violations on each roll-forward plus the lapping detector. 3+ within 90 days → auto UNDER_REVIEW.