Where does Sentinel run, and where does our data live?

In your own tenant. Sentinel deploys into your Azure subscription - the web app, the worker, and a PostgreSQL database that holds the cached Microsoft 365 inventory. Sign-in runs through your Microsoft Entra ID. There is no shared multi-tenant backend, and your data is never used to train public models.

What permissions does it need to connect?

An Entra app registration with read-only Microsoft Graph permissions to enumerate SharePoint, OneDrive, sharing, and Copilot telemetry. Remediation actions such as revoking a sharing link or quarantining an agent use scoped permissions and only run when an admin approves them.

Does Sentinel change anything in our environment on its own?

No. Scanning and scoring are read-only. Every state-changing action - revoking a link, blocking or quarantining an agent - is admin-initiated and written to a full audit log with actor, target, and timestamp.

How are risk scores calculated?

Deterministically, from real exposure signals: sharing scope, anonymous links without expiration, external and guest access, dormancy, and sensitivity signals for data risk; reach, tool access, credential hygiene, and reliability for agent risk. An optional AI layer writes the plain-language executive summary on top of the numeric score.

What does Sentinel need - do we have to be on Microsoft 365 E5?

Sentinel works against standard Microsoft 365 SharePoint/OneDrive and Copilot Studio telemetry. Some Copilot adoption metrics depend on the reports your licensing exposes. Bring your environment to the demo and we'll confirm exactly what's covered.

Can we delegate cleanup to department owners instead of doing it all centrally?

Yes - that's what the Data Steward role is for. Members of a data-steward Entra ID group get a scoped 'Data Stewards Dashboard' that shows only their own department's oldest, most-shared files, with the sharing evidence for each, so they can remediate their team's exposure without ever touching the full admin console. Central security stays focused on tenant-wide risk while data owners handle their own.

What roles and access levels are there?

Three Entra ID groups you control: administrators (full console, job scheduling, and remediation), users (the posture, risk, and analytics dashboards), and data stewards (the department-scoped cleanup view). Access is least-privilege by default and every group is optional.

How is it licensed and deployed?

Per tenant, with signed license keys that gate features. It ships as containers you run on Azure Container Apps (or Docker), so upgrades are a redeploy. Pricing is scoped to your environment - talk to us and we'll map it to your tenant.

See Sentinel on your own tenant

A 30-minute walkthrough on your data: exposure scores, agent risk, and a rollout plan for your Azure environment.

Request a demo