mcp_policy
Real-time MCP policy
Allow, warn, report or block — per MCP server and per tool, enforced in the request path. The inventory fills itself from what your developers actually run, new installs can require admin approval before first use — and a tool whose description quietly changes after approval gets flagged. That's the MCP rug-pull, caught.
secrets · pii · trifecta
Secrets blocked mid-flight
An AWS key pasted into a prompt never reaches the model. Detectors for secrets, personal data, prompt injection and lethal-trifecta exfiltration paths run inline, not in a nightly report.
ungoverned_agents
Shadow agents, surfaced
OpenClaw and agents like it are detected on every governed device and logged as a durable episode history. Set your policy to warn and the device shows non-compliant; set it to block and the device's governed AI access stops until the agent is gone.
autonomy_posture
Auto-approve, governed
Most agent incidents start with a setting: auto-approve, sandbox off, "act without asking". Sentilai reads the AI-tool configuration on every device, shows who runs which posture, rewrites it to the one you chose — and re-governs it when it drifts back.
device_identity
Device-bound identity
Every machine gets a hardware-backed key in the OS keychain. Access is per person and per device — and dies the moment either is revoked.
offboarding
One-click AI offboarding
When someone leaves, their devices, tokens and passkeys go with them — in one action, with a receipt. Classic checklists never reach AI tooling.
provider_routing
Your models, your choice
Route each tool to the provider you pick — Anthropic, OpenAI, Azure, Gemini, or any OpenAI-compatible endpoint, your own self-hosted vLLM included. Per tool, with identical governance on every path.
evidence
Audit trail and evidence pack
Every request, decision and policy change: real-time alerts to Slack or Teams, SIEM export, and an evidence pack for the day a customer, an auditor or a regulator asks what your developers' AI tools actually did. From August 2026 the EU AI Act's enforcement machinery can ask exactly that — the wrong answer is having no record.
supply_chain
Hallucinated packages, caught
AI invents package names; attackers register them and wait. Every AI-suggested dependency is checked against the real npm and PyPI registries first — and a confirmed fake is quarantined for every tenant at once.