Cybersecurity tooling / 2026
Sentinel Local
An AI-assisted operations console for scoped investigations, evidence and human approvals.
- My role
- Application and policy-workflow development
- Stage
- Independent local tool
- Built with
- TypeScript · React · Express · SQLite · Ollama

01 / Context
The problem
Security investigation produces commands, observations and hypotheses. When AI is involved, those need an explicit target boundary and a clear record of what an operator actually approved.
02 / Ownership
My contribution
I built the local console, persistent project and agent workflows, target intake, approval queue, evidence-review surfaces and centralised policy boundaries.
03 / Reasoning
The decisions behind it
Make scope explicit
Projects define allowed hosts and network boundaries. The service and model connection remain on loopback; target tools check the project scope.
Separate suggestion from execution
Structured agent tools request actions through policy checks. Network and higher-risk actions pause for review. A model response does not grant permission to act.
Keep evidence traceable
SQLite stores project activity, handoffs, tool requests, approvals and audit events. The review workflow distinguishes observations, hypotheses and gaps.
04 / In practice
A closer look

05 / Evidence
Verification & boundaries
The repository contains type checks, policy and persistence tests, and a production build workflow. These screenshots were captured from a fresh local demonstration project. Opening the console is not an independent security assessment.
What this does and does not establish
An operator aid for authorised work. Scope checks and approvals do not replace written permission or careful review. The direct interactive terminal retains host access; AI summaries still require validation.
06 / Looking ahead
What comes next
Broaden regression coverage around scope and approval boundaries and make evidence provenance easier to inspect.