Sailient/Sentinel
Demo estate
Preview·Not the final design·Synthetic dataWhat this means

This is a sketch, not a specification. The layout, the wording and the structure of these screens are a rough impression of what the product could look like — not what it will look like. All of it will change.

Every figure, record and name here is invented. There is no backend, no authentication, no stored state and no customer data, and no customer, certification, partnership or performance claim is made anywhere in these screens.

Separately: elsewhere on this site “pilot” means a pilot engagement with a customer. None has started. These are interface previews, which is a different thing. Background in the newsroom.

Sentinel

Security operations.

Fourteen alerts open, two of them critical. The estate is operational.

Active incidents

The incident is the object an operator works with. Alerts roll up into it; it does not roll up into a chart.

Credential reuse across sites
critical · INC-2418 · SOC shift A
opened 09:14
Outbound traffic to an unrecognised network
critical · INC-2417 · SOC shift A
opened 09:06
Repeated privilege escalation attempts
high · INC-2412 · contained
yesterday 21:48

State

Synthetic
Open alerts
14
two critical
Time to acknowledge
4 min
rolling seven days
Monitored assets
1,046
across four sites

The spike eight hours ago is the credential-reuse cluster that became INC-2418. Volume has since returned to its usual band.

Scope of this pilot

What is real on this page and what is not

Real: the interface and the operator workflow it implies — alert, correlation, incident, response — with keyboard navigation, focus states and reduced-motion support.

Not real: every alert, asset, hostname and count. No telemetry is collected and no system is monitored. No offensive capability is modelled here, and none is planned; remediation in the product design is an authorised workflow that a human approves.