Skip to content
Stackship documentation Svenska

SentinelUsers

The Sentinel page

What the Overview, Findings, Runs and Platform tabs of the Sentinel page show.

Requires: sentinel/read

Open Sentinel under Quick Access in the sidebar; the entry is there when you hold sentinel/read in the selected boundary. The page covers that boundary and has a tab per view:

Tab Shows
Overview The boundary's findings at a glance
Findings Every finding in the boundary, with search and filters
Runs The boundary's analysis runs
Platform Platform findings together with every boundary's open findings — only with sentinel/admin at the platform root

Overview

Time range — 7d, 30d, 90d, 6 mo or 1 yr — sets what Activity, Weekly Trend and Recently resolved cover. The counts at the top, Active alerts and Active by Category always describe the findings as they are now.

  • Last run — the latest run's status (Running, Completed, Failed or Cancelled), when it started, how long it took and, for a failed run, the error. Before the boundary's first run it says No Sentinel runs recorded yet. Run history opens the Runs tab.
  • Active alerts — how many Open and Acknowledged findings there are per severity, and the five most urgent.
  • Recently resolved — how many findings were fixed in the time range, the Median time to resolve, and the five most recent.
  • Active by Category — open and acknowledged findings split into Security, Performance, Reliability and Code.

Findings

The list has search and filters on Status, Type (the category), Severity, Suggested Owner, First Seen, Last Seen, Resource and Resource Type. Open a finding to read it — see Findings — and to act on it — see Work with findings.

A link from a resource's Sentinel card opens this list filtered to that resource.

Runs

Up to the 50 most recent runs, with Status, Started, Finished, Duration and Error. Runs from before run history was recorded do not appear, and neither do runs Sentinel skipped because no language model was available.

Platform

The Platform tab is shown to principals with sentinel/admin at the platform root — Platform Owner and Platform Contributor. It lists, read-only:

  • platform findings — the 500 most recently seen, about the platform itself;
  • the Open findings of every boundary — up to 50 per boundary, most severe first.

Scope shows Platform or the boundary's name. Each boundary is read with your own permissions; a boundary you cannot read is left out, and a note says how many were. Search, and filter on scope, severity, category and status. A platform finding opens on this tab; a boundary finding opens on that boundary's Sentinel page.

With the CLI

bash
stsh sentinel overview --boundary my-boundary
stsh sentinel alerts --boundary my-boundary

overview prints the boundary's counts; alerts lists its open and acknowledged findings, most severe first.