An account for each person.
No shared administrative credentials: users, passwords and second factor are handled separately.
Sentinel separates reading, operation and administration. Access can be protected with two-factor TOTP and sensitive actions are recorded so you can reconstruct who did what.
No shared administrative credentials: users, passwords and second factor are handled separately.
Users who only need visibility cannot change policies; those who work do not automatically access administrative secrets.
Logins and API actions are associated with the user, the outcome and the source address.
Access control
The dashboard adapts to the user's role, both in pages and in APIs.
View servers, events, reports, rules, blocks and logs without changing the platform status or seeing agent credentials.
Operators can add servers, manage blocks and allowlists, start scans, edit rules and coordinate updates.
In addition to operational functions it manages users, roles, two-factor authentication, settings and integration secrets.
Authentication
The second factor uses temporary TOTP codes compatible with common authenticator apps. The administrator starts the setup via QR code and the code must be checked before activation.

Audits
The operations that modify the platform are recorded with actor, action, resource, outcome, date and IP source. Login, 2FA, logout and access to the administrative audit log are also tracked.
Application Protection
Requests that change status require a valid token linked to the session.
Control is not only visual: the server rejects API operations that the role does not allow.
Sensitive settings and integrations are separated from normal operational functions.
Responses include protections against MIME sniffing, unauthorised framing and referrer policies too permissive.
During the demo we show the real stream from viewer, operator and administrator.