Not demos. Real operations.
Four of these are measured in live Tier-1 deployments, three telecom and one enterprise, and each links to the case study that records it. The rest are platform capabilities: the same governed patterns, applied to a domain we have not yet published a deployment for. Every card says which it is, and every timeline says whether it was measured or modelled.
- 38
- Documented use cases
- 9
- Domains covered
- 4
- Measured in production
- 3
- Proactive voice / chat use cases
- ObserveIngest all signals
- InvestigateCorrelate & root cause
- ActExecute or escalate
- OptimizeLearn & improve
Use cases show what Sentinel is built to do. Case studies show what it has done. Cards marked Production pattern reflect capability running in live enterprise deployments and link to the case study. Cards marked Platform capability are modelled on those same governed patterns, applied to a domain we have not yet published a deployment for.
SRE Agent · Flagship use case · Every domain
Production pattern · governed MOP execution · closed-loop RCA
Every alert gets a full SRE investigation. Then the risk decides who presses go.
This is not a separate product. “SRE Agent” is simply what Sentinel, ProcBot and Sherlock do together when an alert arrives. It is the job title, not a new licence. It is the pattern underneath all 38 use cases below. It does not care whether the alert came from a core banking batch, a fibre uplink or a Kubernetes pod. An alert arrives, Sentinel investigates it the way a senior SRE would, and what happens next is decided by blast radius, not by confidence.
Signal
Any alert, from any connected source. No pre-classification, no routing rules to maintain.
Correlate
Traces, metrics, logs, topology, the database queries underneath, recent changes, and every dependent service in the blast path, queried together rather than tab by tab.
Diagnose
Hypotheses raised and eliminated against evidence. Probable cause with a confidence score and the affected-service map attached.
Decide
Sentinel scores the impact of the fix, not just the fault. That score, not the model's certainty, chooses the path below.
The governance gate: two paths, one policy
No service impact → Sentinel acts
ProcBot opens a reversible Action Ticket and executes the approved MOP with pre-checks, post-checks and an automatic rollback trigger. Sherlock verifies the fix against live metrics before the incident closes. Nobody is paged.
Service impact → a human presses go
Sentinel raises the ticket with the proposed MOP, the blast radius and the rollback path already written, notifies the owning team and change stakeholders, and stops. Nothing executes until a named human approves it.
- Output:RCA with citations to the evidence it was drawn from
- Output:Blameless postmortem, generated as the incident runs
- Output:Full audit trail: who, what, when, why, reversible
- Works across:Telco · Fiber · Banking · Fintech · IT Support
Telco & Network Operations
4 use casesEvery figure in this section is measured in a live Tier-1 deployment and links to the case study that records it. Three are telecom operators and one is an enterprise, on two continents, and each card names which. These are not modelled scenarios, and they are not one customer.
Production pattern
Twenty-seven thousand devices, no single place to look
Fault data arrived faster than any team could read it. There was no central real-time view at all.
SNMP traps, Kafka streams and polled counters each lived in their own pipeline. Root-causing a fault meant hopping between element managers, device by device.
- Telemetry Ops
- Service Ops
- Sentinel
Measured in production · Tier-1 telecom operator, India
Production pattern
The server estate nobody could see inside
Every HPE iLO interface was a disconnected island. Hardware failed before anyone knew it was degrading.
Thousands of servers running heavy data workloads, with no unified view of temperature, power or component health. Failures were discovered by outage, not by trend.
- Infra Ops
- Telemetry Ops
- Sherlock
Measured in production · Tier-1 telecom operator, North America
Production pattern
Patching two thousand nodes without a war room
Mass patching meant a scheduled outage, a bridge call and a long night.
Health checks, log capture, SSH access and patch rollout all ran by hand across the estate. Every cycle consumed engineers who should have been building.
- Managed Ops
- ProcBot
- DevSec Ops
Measured in production · Tier-1 enterprise, North America
Production pattern
The same fault, every week, forever
Recurring network faults were fixed and forgotten, then fixed again by whoever was on call.
Symptoms surfaced across seven data domains with no memory between incidents. Nobody connected this week’s outage to last month’s identical one.
- Service Ops
- AI Ops
- Sherlock
Measured in production · Tier-1 telecom operator, North America
Business & Back-Office Operations
7 use casesThese are platform capabilities: the same governed patterns that run in our production estates, applied to back-office processes. Every timeline on the detail pages is labelled illustrative, not measured.
Platform capability
The reconciliation job failed and told nobody
Finance found out when the numbers did not match, and the pipeline was already corrupted.
A batch process exits without alerting. By the time the team notices, downstream reporting is corrupted too, and the recovery is twice the work it should have been.
- Data Ops
- Process Ops
- Copilot
What changes when Sentinel is on it
- Designed for minutes, not hours
- ↓ finance team impact
- Auto-notified stakeholders
Platform capability
The quote is stuck and sales does not know why
The deal is waiting on a system nobody in the room owns.
A quote-to-cash flow stalls between CRM and ERP. Sales chases support, support chases finance, and the record sits untouched in a queue neither team monitors.
- Service Ops
- Process Ops
What changes when Sentinel is on it
- CRM + ERP correlation
- Sales unblocked faster
Platform capability
Day one, and the new starter cannot log in
Their manager spends the first morning raising tickets instead of onboarding them.
Access provisioning spans HR, identity and a dozen applications, each with its own request path. Nothing is wrong; it is just slow, manual and easy to miss a step.
- Security Ops
- Process Ops
What changes when Sentinel is on it
- HR ↔ Identity ↔ Apps
- Day-1 ready
Platform capability
The batch failed and took eleven jobs with it
Nobody knows yet which downstream systems are now holding bad data.
One job fails and the dependency chain behind it stalls or, worse, runs on partial input. Working out the blast radius takes longer than fixing the original failure.
- Managed Ops
- Process Ops
What changes when Sentinel is on it
- Ranked by business impact
- Escalate only when SLA at risk
Platform capability
Payroll ran short and nobody found out until Friday
The run reported success. The people it missed found out on payday.
A group added since the last cycle was silently excluded by the extract. Payroll processed everyone it could see, which is not the same as everyone.
- Process Ops
- Data Ops
- ProcBot
What changes when Sentinel is on it
- Population checked, not just the run
- Payment file held before release
- Nobody is paid short
Platform capability
The customer exists twice and both records are wrong
Credit exposure sits on one record. The orders are placed against the other.
Two systems created the same customer under near-match names. Both accumulate updates from different teams, so the truth is split rather than duplicated.
- Data Ops
- Process Ops
- Sherlock
What changes when Sentinel is on it
- Matched on likeness, not on key
- Caught while the merge is cheap
- Merge is reversible by default
Platform capability
The stock said available. The warehouse disagreed.
Orders kept being promised against a number that stopped being true that morning.
One message type starts failing validation, so outbound movements stop syncing. The figure keeps updating, so every freshness check passes while it drifts.
- Data Ops
- Service Ops
- ProcBot
What changes when Sentinel is on it
- Promise reconciled to the ledger
- Affected SKUs held, not oversold
- Replay stays under approval
Banking & Core Financial Systems
4 use casesPlatform capability
The end-of-day batch that died at 23:52
Nobody found out until 06:40. By then the branches were open.
No alert fires. The job did finish, it just finished badly. Six downstream jobs stall behind it. Detection, when it comes, is a branch manager on the phone.
- Process Ops
- Service Ops
- ProcBot
Illustrative scenario · not a measured deployment
Platform capability
The switch was fine. The cut-off wasn't.
Nothing alerted, because nothing broke. It just got slower every hour.
Authorisation latency drifts from 240ms toward 900ms across an afternoon. No threshold crossed. The risk is not an outage, it is missing settlement and carrying value into tomorrow.
- Service Ops
- Infra Ops
- Sherlock
What changes when Sentinel is on it
- Projects the breach before it lands
- Protects the cut-off, not just uptime
- Cause posted with the alert
Platform capability
Two hundred ATM tickets, one upstream cause
The service desk filled with one ticket per machine. Every one triaged separately.
ATMs across a region start declining. Nobody looks upstream because no alarm points there. The actual fault is a single switch path, and field crews are already rolling.
- Service Ops
- Infra Ops
- Copilot
What changes when Sentinel is on it
- 214 tickets become one incident
- Holds dispatch until cause is confirmed
- Designed to correlate on arrival
Platform capability
A privileged login at 02:14, from a jump host nobody recognises
It could be emergency change work. It could be the start of something much worse.
No change record is open. The session is live on a host inside the cardholder boundary. Isolating the wrong account mid-settlement is its own incident.
- Security Ops
- DevSec Ops
- Sentinel
What changes when Sentinel is on it
- Voice-verified before isolation
- No blind lockout mid-settlement
- Full audit trail by default
Fintech & Payments
3 use casesPlatform capability
Success rate slipped four points. Nobody filed a ticket.
The first real signal was a customer complaining on social media, three hours later.
Payment success falls from 98.6% to 94.1%. Every infrastructure dashboard stays green, because the infrastructure is fine. One acquirer route is quietly failing.
- Service Ops
- Data Ops
- Sherlock
What changes when Sentinel is on it
- Catches it before the complaint
- Isolates the failing route, not the whole stack
- Failover staged with expected recovery
Platform capability
Seventy-eight percent of the way to a timeout
Nothing has failed yet. When it does, customers will see declines, not slowness.
Authorisation round-trip climbs toward the issuer limit after a deploy adds synchronous enrichment. Retries rise. Decline rate is still flat, for now.
- Service Ops
- Infra Ops
- ProcBot
What changes when Sentinel is on it
- Acts on headroom, not on failure
- Prevents declines, not just slowness
- Reversible rollback path staged
Platform capability
Onboarding stopped completing. The dashboard said fine.
Nobody noticed until the growth team asked why activations were flat.
Applications enter the queue and never reach approved. A partner returns a soft failure the application layer treats as pending, so nothing errors and nothing alerts.
- Process Ops
- Data Ops
- Copilot
What changes when Sentinel is on it
- Catches the stall, not the silence
- Protects the activation funnel
- Backlog replayed under governance
Fiber & Access Networks
3 use casesPlatform capability
Four thousand subscribers dark, four thousand alarms
The NOC saw a wall of individual faults. The contact centre started filling.
Loss-of-signal from 4,120 ONTs inside three minutes. No alarm names the parent. Every minute spent triaging subscriber alarms is a minute not spent fixing the uplink.
- Telemetry Ops
- Service Ops
- Sentinel
What changes when Sentinel is on it
- 4,120 alarms become one incident
- Blast radius sized automatically
- Designed to collapse on arrival
Platform capability
The break is somewhere on forty kilometres of fibre
Restoration time is dominated not by the splice, but by finding the break.
A route goes dark and the SLA clock starts. A crew dispatched to the wrong span costs hours. Nobody knows which access point to open first.
- Telemetry Ops
- Infra Ops
- Sherlock
What changes when Sentinel is on it
- Narrows the break before dispatch
- Cuts the search, not just the splice
- Restoration ordered by SLA exposure
Platform capability
The port was dying for nine days before anyone looked
No alarm fired, because nothing had failed yet. Subscribers churned quietly.
Optical receive power drifts slowly out of tolerance on one PON port. Error counters rise on a subset of ONTs. No threshold is breached, so nothing is raised.
- Telemetry Ops
- AI Ops
- ProcBot
What changes when Sentinel is on it
- Acts days ahead of impact
- Planned work instead of emergency
- Predictive, not threshold-based
Infrastructure
3 use casesPlatform capability
The CPU spiked at 3am and the pager did its job
An engineer woke up to read graphs a machine could have read faster.
A service saturates under an overnight traffic shift. The alert routes to a human who spends the first twenty minutes rebuilding context the system already had.
- Service Ops
- Data Ops
- Infra Ops
What changes when Sentinel is on it
- Designed to reach RCA in minutes
- ↓ MTTR
- Fully autonomous
Source: observability platform 2024 State of Observability - DB issues are #2 cause of all production incidents
Read the full storyPlatform capability
Something is slow. Nobody can say which something.
Four services blame each other while the customer waits.
Latency rises across a request path spanning several teams. Each dashboard shows only its own hop, so the investigation becomes a negotiation rather than a diagnosis.
- Service Ops
- Infra Ops
What changes when Sentinel is on it
- Topology mapped in minutes
- ↓ cross-service MTTR
- Topology-aware AI
Source: application performance monitoring 2024 - 67% of latency incidents span 3+ services, requiring cross-system correlation
Read the full storyPlatform capability
The disk filled at the worst possible hour
It had been filling for days. Nothing was watching the trend.
Storage crosses its threshold overnight and takes the service with it. The signal existed the whole time, as a slope nobody was plotting.
- Data Ops
- Service Ops
- ProcBot
What changes when Sentinel is on it
- Proactive, days ahead of impact
- ↓ disk-fill outages
- Predictive detection
Source: Gartner 2025 - Disk/storage issues represent 20-30% of all infrastructure alerts in enterprise environments
Read the full storyL1/L2 Automation
3 use casesPlatform capability
The certificate expired on a Saturday
Everyone assumed someone else had the renewal in their calendar.
Certificate expiry is knowable weeks ahead and still causes outages, because renewal lives in a spreadsheet and the reminder goes to someone who has left.
- Service Ops
- Security Ops
- ProcBot
What changes when Sentinel is on it
- Acts ~30 days ahead of expiry
- ↓ cert-expiry outages
- Fully automated
Source: Sectigo 2024 - 76% of enterprise organizations experienced at least one certificate-related outage in the past 12 months
Read the full storyPlatform capability
The connection pool ran out and took checkout with it
The database was healthy. The pool in front of it was not.
Traffic shifts and the pool saturates. Every symptom points at the database, so that is where the team looks first, and loses twenty minutes.
- Data Ops
- Service Ops
- Fin Ops
What changes when Sentinel is on it
- Designed for minutes-scale resolution
- ↓ cascade risk
- Blocks the downstream cascade
Source: observability platform 2024 - DB connection pool exhaustion is the #2 cause of production Java application failures
Read the full storyPlatform capability
The quarterly access review that eats a week
Every quarter, the same spreadsheets, the same chasing, the same result.
Entitlements are exported, mailed to managers, chased, collated and filed. The work is enormous, the findings are usually the same, and the evidence is stale by the time it is signed.
- Security Ops
- Process Ops
- ProcBot
What changes when Sentinel is on it
- Designed to compress weeks into days
- ↓ review effort
- Audit-ready 24/7
Source: Ponemon 2024 - 58% of breaches involve credentials from orphaned or excessive-privilege accounts
Read the full storySecurity
3 use casesPlatform capability
A service account with far more access than its job needs
It has been that way for months. The audit is in three weeks.
Permissions drift quietly as systems change. Nobody notices until review season, when someone reconstructs months of entitlement changes by hand.
- Security Ops
- Infra Ops
- Sherlock
What changes when Sentinel is on it
- Designed to detect in minutes
- ↓ audit prep time
- Zero privilege drift
Source: CrowdStrike 2025 Global Threat Report - misconfigurations are the leading initial access vector in cloud environments
Read the full storyPlatform capability
A login that looks wrong, at an hour that looks worse
Block it and you may lock out a colleague. Ignore it and you may not.
Unusual geography, unusual time, valid credentials. The analyst has minutes to decide, and the evidence lives across four consoles.
- Security Ops
What changes when Sentinel is on it
- Investigation in minutes, not shifts
- ↓ investigation time
- MITRE T1078 mapped
Source: Verizon 2025 DBIR - credential theft detected on average 277 days after initial compromise without automation
Read the full storyPlatform capability
Someone escalated their own privileges. Quietly.
The command succeeded. Nothing alerted. It was found weeks later.
A sudo pattern that does not match the account's history. On its own it is noise. Against the change calendar and the identity system, it is not.
- Security Ops
- Sherlock
What changes when Sentinel is on it
- Correlated at execution, not at review
- ↓ response time
- MITRE T1078.004
Source: IBM Cost of Data Breach 2025 - insider-related incidents cost 20% more than external breaches and take longer to detect
Read the full storyProactive Voice & Chat
3 use casesPlatform capability
Sentinel calls the user before it locks the account
The cheapest way to know if a login is legitimate is to ask the person.
An unusual login is detected. Instead of a silent block or a queued ticket, the account owner gets a phone call and answers in seconds.
- Security Ops
- Voice Agent
What changes when Sentinel is on it
- Answered in the moment, not queued
- ↓ breach risk
- Voice-verified
Source: Pindrop 2024 - voice verification reduces account takeover success by 94% vs SMS/email-only flows
Read the full storyPlatform capability
Brute force on a production host. Sentinel phones the owner.
Isolating a production server without asking is its own outage.
Repeated failed authentication against a live host. The owner is called before anything is isolated, so containment and business continuity are decided together.
- Security Ops
- Infra Ops
- Voice Agent
What changes when Sentinel is on it
- Owner reached before isolation
- ↓ lateral move risk
- MITRE T1021.004
Source: CrowdStrike 2025 - average attacker breakout time is 62 minutes; containment must happen within first 30 minutes
Read the full storyPlatform capability
The manager is asked before the access is granted
Privilege escalation requests are approved by people who lack the context to judge them.
An escalation is requested outside the normal pattern. The line manager is messaged with the request, the history and the blast radius attached.
- Security Ops
- Copilot
What changes when Sentinel is on it
- Decided with blast radius attached
- ↓ response time
- MITRE T1078.004
Source: IBM Cost of Data Breach 2025 - insider incidents are the costliest category and take longest to detect without automation
Read the full storyManaged Services & Governance
5 use casesPlatform capability
The CAB meeting where nobody can score the risk
Thirty changes, one hour, and no consistent way to judge any of them.
Change requests arrive with no impact assessment attached. The board approves on instinct and experience, then finds out afterwards which one was the risky one.
- Service Ops
- Sherlock
What changes when Sentinel is on it
- Pre-CAB risk scoring
- CAB meetings shorter
Platform capability
The SLA breached while the ticket sat in a queue
Nobody was watching the clock until it had already run out.
Tickets age quietly toward their commitment. Breach is discovered in the monthly report, when the credit is already owed and the customer already knows.
- Service Ops
- Sherlock
What changes when Sentinel is on it
- Predictive, not reactive
- SLA protected
Platform capability
The same incident, for the eleventh time this quarter
Each one was closed correctly. Nobody joined them up.
Recurring incidents are resolved individually and never aggregated into a problem record. The systemic cause survives because no single ticket is big enough to justify finding it.
- Sherlock
- Service Ops
What changes when Sentinel is on it
- Systemic patterns surfaced
- ITIL Problem Mgmt activated
Platform capability
The model was fine at deploy. It is not fine now.
Accuracy decayed slowly enough that nobody noticed until the business did.
Input distributions shift after release. Nothing errors, nothing alerts, and the predictions get quietly worse until someone downstream questions the numbers.
- AI Ops
- Sherlock
What changes when Sentinel is on it
- Drift caught before review
- Guarded, reversible rollback
Platform capability
A critical CVE lands the day before release
Ship it and you carry the risk. Hold it and you carry the delay.
A vulnerability is published against a dependency already in the release candidate. Whether it is actually reachable from a public path takes hours to determine by hand.
- DevSec Ops
- ProcBot
What changes when Sentinel is on it
- Vulnerable release blocked
- Gate decision audited
Consolidated ROI Summary
38 use cases. Measurable outcomes.
Four of these are measured in live Tier-1 deployments, three telecom and one enterprise, and each links to the case study that records it. The rest are platform capabilities: the same governed patterns applied to a domain we have not yet published a deployment for. This table says which is which for every row, and it does not put a resolution time against a use case we have not measured.
| Use case | Domain | Evidence | What changes |
|---|---|---|---|
| UC-T1 Twenty-seven thousand devices, no single place to look | Telco | Measured in productionTier-1 telecom, India | 27,000+ devices under one pane |
| UC-T2 The server estate nobody could see inside | Telco | Measured in productionTier-1 telecom, North America | 100% iLO endpoints centralised |
| UC-T3 Patching two thousand nodes without a war room | Telco | Measured in productionTier-1 enterprise, North America | 2,000+ nodes live under ProcBot |
| UC-T4 The same fault, every week, forever | Telco | Measured in productionTier-1 telecom, North America | ~60% recurring faults resolved end to end |
| UC-07 The reconciliation job failed and told nobody | Business | Platform capability | Designed for minutes, not hours |
| UC-16 The quote is stuck and sales does not know why | Business | Platform capability | CRM + ERP correlation |
| UC-19 Day one, and the new starter cannot log in | Business | Platform capability | HR ↔ Identity ↔ Apps |
| UC-24 The batch failed and took eleven jobs with it | Business | Platform capability | Ranked by business impact |
| UC-08 Payroll ran short and nobody found out until Friday | Business | Platform capability | Population checked, not just the run |
| UC-15 The customer exists twice and both records are wrong | Business | Platform capability | Matched on likeness, not on key |
| UC-18 The stock said available. The warehouse disagreed. | Business | Platform capability | Promise reconciled to the ledger |
| UC-B1 The end-of-day batch that died at 23:52 | Banking | Platform capability | ~8 hrs to ~15 min, illustrative |
| UC-B2 The switch was fine. The cut-off wasn't. | Banking | Platform capability | Projects the breach before it lands |
| UC-B3 Two hundred ATM tickets, one upstream cause | Banking | Platform capability | 214 tickets become one incident |
| UC-B4 A privileged login at 02:14, from a jump host nobody recognises | Banking | Platform capability | Voice-verified before isolation |
| UC-P1 Success rate slipped four points. Nobody filed a ticket. | Fintech | Platform capability | Catches it before the complaint |
| UC-P2 Seventy-eight percent of the way to a timeout | Fintech | Platform capability | Acts on headroom, not on failure |
| UC-P3 Onboarding stopped completing. The dashboard said fine. | Fintech | Platform capability | Catches the stall, not the silence |
| UC-N1 Four thousand subscribers dark, four thousand alarms | Fiber | Platform capability | 4,120 alarms become one incident |
| UC-N2 The break is somewhere on forty kilometres of fibre | Fiber | Platform capability | Narrows the break before dispatch |
| UC-N3 The port was dying for nine days before anyone looked | Fiber | Platform capability | Acts days ahead of impact |
| UC-01 The CPU spiked at 3am and the pager did its job | Infrastructure | Platform capability | Designed to reach RCA in minutes |
| UC-02 Something is slow. Nobody can say which something. | Infrastructure | Platform capability | Topology mapped in minutes |
| UC-03 The disk filled at the worst possible hour | Infrastructure | Platform capability | Proactive, days ahead of impact |
| UC-12 The certificate expired on a Saturday | Infrastructure | Platform capability | Acts ~30 days ahead of expiry |
| UC-13 The connection pool ran out and took checkout with it | Infrastructure | Platform capability | Designed for minutes-scale resolution |
| UC-14 The quarterly access review that eats a week | Infrastructure | Platform capability | Designed to compress weeks into days |
| UC-04 A service account with far more access than its job needs | Security | Platform capability | Designed to detect in minutes |
| UC-05 A login that looks wrong, at an hour that looks worse | Security | Platform capability | Investigation in minutes, not shifts |
| UC-06 Someone escalated their own privileges. Quietly. | Security | Platform capability | Correlated at execution, not at review |
| UC-09 Sentinel calls the user before it locks the account | Proactive Voice | Platform capability | Answered in the moment, not queued |
| UC-10 Brute force on a production host. Sentinel phones the owner. | Proactive Voice | Platform capability | Owner reached before isolation |
| UC-11 The manager is asked before the access is granted | Proactive Voice | Platform capability | Decided with blast radius attached |
| UC-17 The CAB meeting where nobody can score the risk | Managed Services | Platform capability | Pre-CAB risk scoring |
| UC-20 The SLA breached while the ticket sat in a queue | Managed Services | Platform capability | Predictive, not reactive |
| UC-21 The same incident, for the eleventh time this quarter | Managed Services | Platform capability | Systemic patterns surfaced |
| UC-22 The model was fine at deploy. It is not fine now. | Managed Services | Platform capability | Drift caught before review |
| UC-23 A critical CVE lands the day before release | Managed Services | Platform capability | Vulnerable release blocked |