Each person can view and change only what their role allows.

Sentinel separates reading, operation and administration. Access can be protected with two-factor TOTP and sensitive actions are recorded so you can reconstruct who did what.

Viewer · Operator · Admin2FA TOTPAudit of operations
Identity

An account for each person.

No shared administrative credentials: users, passwords and second factor are handled separately.

Privileges

The role determines read and write access.

Users who only need visibility cannot change policies; those who work do not automatically access administrative secrets.

Traceability

Changes leave an audit trail.

Logins and API actions are associated with the user, the outcome and the source address.

Access control

Three roles, clear responsibilities.

The dashboard adapts to the user's role, both in pages and in APIs.

Viewer · read only

View servers, events, reports, rules, blocks and logs without changing the platform status or seeing agent credentials.

Operator · operational management

Operators can add servers, manage blocks and allowlists, start scans, edit rules and coordinate updates.

Admin · complete control

In addition to operational functions it manages users, roles, two-factor authentication, settings and integration secrets.

Authentication

Password and TOTP, in two separate steps.

The second factor uses temporary TOTP codes compatible with common authenticator apps. The administrator starts the setup via QR code and the code must be checked before activation.

  • Login rate limiting against repeated attempts.
  • Optional reCAPTCHA when you choose to use the Google service.
  • Secure session cookies and temporary flow dedicated to the second factor.
  • Personal password change after verifying the current password.
Central dashboard of the Sentinel platform

Audits

Security actions must be traceable.

The operations that modify the platform are recorded with actor, action, resource, outcome, date and IP source. Login, 2FA, logout and access to the administrative audit log are also tracked.

  • Success, denied or error outcomes outcomes: not only successful operations are recorded.
  • Audit append-only: The application log is designed not to be modified by the normal panel functions.
  • Admin-only access: Audit information is restricted to the highest role.
Sentinel/audit
Recent activitiesTRACCIATO
operator@azienda.it
block_ip · 10.0.0.24
SUCCESS
viewer@azienda.it
update_rule · access denied
DENIED
admin@azienda.it
login_2fa · 192.0.2.10
SUCCESS

Application Protection

The APIs apply the same boundaries as the panel.

01

CSRF protection for changes

Requests that change status require a valid token linked to the session.

02

Role-based access control

Control is not only visual: the server rejects API operations that the role does not allow.

03

Administrative secrets

Sensitive settings and integrations are separated from normal operational functions.

04

Security headers

Responses include protections against MIME sniffing, unauthorised framing and referrer policies too permissive.

Want to see the panel with different roles?

During the demo we show the real stream from viewer, operator and administrator.