From OAuth to a working security program in one day
CISO Express is not a scanner you read reports from, and it is not a questionnaire you fill in once a year. It is an agent that takes the framework on your behalf, finds the humans who own each piece, and keeps asking until the work is done and the evidence is filed.
One agent running the whole program, in the tools you already pay for
Sentinel is not a scanner and not a questionnaire. It is the operating layer between your control framework and the humans who have to do the work — and it runs the same loop every day.
01
Connect
Slack or Microsoft Teams OAuth, plus read-only connectors for your identity provider, cloud accounts and repositories. Minutes, not months.
02
Learn your org
Directory sync maps every human to a role and an ownership set — who ships, who runs infra, who signs contracts, who holds the data.
03
Find the gaps
Framework controls, cloud configuration, identity state and vendor records produce a live register of open issues with severity and due dates.
04
Nudge the right person
Sentinel opens a direct message with the owner, states the ask in one sentence, links the evidence it needs, and sets an SLA by severity.
05
Collect evidence
When someone answers, the response becomes evidence attached to every control it satisfies. No screenshot hunts, no shared drive archaeology.
06
Report and escalate
Live dashboard, weekly digest, and automatic escalation up the chain the moment an SLA breaches. Every step is recorded for the audit trail.
The loop never stops and never forgets. A control that regresses reopens as an issue; an owner who leaves gets their queue reassigned to their manager; an evidence artifact that expires is re-requested before the auditor notices.
Across the workspaces we onboarded this year, from 22 to 260 people.
Week 1Phase 1
Connectors live, org graph mapped, first register of 40–70 issues with named owners.
Week 2Phase 2
Owners are replying. Evidence starts landing on controls. First escalations fire and resolve.
Week 3Phase 3
Vendor reviews and access reviews open as recurring issues. Exec dashboard shared with the board.
Week 4Phase 4
Mock evidence request run. Auditors receive the binder export. Risk score up 8–12 points.
What you need to bring
An admin who can approve a Slack or Teams app install (10 minutes)
A read-only service account or OAuth grant for your identity provider
Read-only cloud access for the accounts that hold production data
The name of one human who can sign off on accepted risk
What you do not need
No endpoint agents on employee laptops
No network changes, VPN or firewall rules
No professional services engagement or implementation partner
No migration off your existing ticketing or GRC tooling
A real week
What it looks like when Sentinel goes to work
This is a composite of what happens in a customer workspace: a DevOps owner confirms a fix, evidence is logged against three frameworks, a misrouted issue is reassigned, and a missed SLA escalates without anyone having to escalate it.
#sentinel-security· 42 members
Monitoring 61 controls
SentinelAPPMon 09:02
Hi Dana — Sentinel here, your CISO as a Service. Two things on your queue today.
SEC-1042 · MFA enforced on production root accounts · due Mon 08:00 · High.
Can you confirm it is applied? Reply *done* and I will re-run the check, or tell me what is blocking it.
DW
Dana WhitfieldDevOps LeadMon 10:41
Applied it last night to both accounts. I also turned on the org-level policy so new accounts inherit it.
SentinelAPPMon 10:41
Verified independently: MFA is enforced on 2/2 root accounts and the org policy is on.
Evidence logged and attached to SOC 2 CC6.1, ISO 27001 A.8.5 and NIST CSF PR.AA-03.
SEC-1042 closed · 0 days past SLA · next check in 30 days
SentinelAPPWed 09:00
New: SEC-1051 · Vendor security review for Helios CRM · assigned to you until Legal is onboarded · due Wed 12:00.
I have the vendor’s security page and sub-processor list queued. Reply *start* and I will walk you through the four questions I could not answer myself.
DW
Dana WhitfieldDevOps LeadWed 12:04
This one is not mine — it needs Legal. I do not want to sign a DPA I have not read.
SentinelAPPWed 12:04
Understood. Reassigning to Legal Counsel and updating the ownership map so vendor reviews route to Legal by default.
Manager looped inMarcus Lee · VP EngineeringSat 12:00
4Escalated to CTOPriya Raman · includes full reply historyMon 12:00
5CEO digestAdded to weekly risk summaryNext Mon
Why this matters to an auditor
Every message is timestamped, every control link is recorded, and every escalation names the human who was asked. When your auditor asks how you know access changes are reviewed, the answer is a query, not a memory.
Questions
The things operators ask us first
Straight answers, including the ones that are inconvenient for us.
Does Sentinel replace a human CISO?
It replaces the operating layer — the tracking, chasing, evidence gathering and reporting that consumes most of a security leader’s week. Starter and Growth are designed to run without one. Growth includes a quarterly program review with a human CISO, and Enterprise adds a dedicated named CISO plus an on-call security engineer for incident work, board questions and audit scrutiny.
How long does it actually take to go live?
Under a day. You install the Slack or Teams app with a two-click OAuth grant, connect your identity provider and cloud accounts read-only, and Sentinel maps your org on the first sync. Most teams see their first assigned issues within hours of connecting and a full program plan within 24 hours.
Which permissions does Sentinel need in Slack or Teams?
Directory read (so it can map people to roles), the ability to send direct messages and post in channels you explicitly approve, and the ability to read replies in threads it started. It cannot read your private channels or your employees’ direct messages with each other. The full scope list is published on our security page, and Enterprise plans can restrict the agent to a single channel if you prefer.
Do you train models on our data?
No. Your messages, findings, evidence and directory data are never used to train foundation models, and our sub-processors are contractually prohibited from doing so. We use a fixed, versioned model configuration per workspace and you can request deletion of your workspace data at any time.
What happens when nobody responds to Sentinel?
Escalation is automatic and time-boxed. After the severity SLA breaches, Sentinel nudges the owner again, then their manager, then the CTO, then the CEO, each with the original request and the response history attached. Every step is recorded, so your audit trail shows exactly who was asked, when, and what happened next. Unresolved items surface at the top of the weekly digest.
Can we use CISO Express for a real SOC 2 Type II report?
Yes. Sentinel maintains the control set, collects evidence continuously across the observation window, and exports an auditor-ready binder. The report itself must be issued by an independent CPA firm — we prepare everything they ask for, and we work with whichever auditor you choose rather than locking you into a partner.
How does pricing work as we grow?
You pay per workspace, not per seat, so adding employees never increases the bill. Tiers are based on headcount bracket and the scope of automation you need. If you cross a bracket mid-term, we prorate the upgrade and keep the same annual discount — and we will tell you before you need to ask.
We already have a GRC tool. Can we keep it?
Yes. Growth and Enterprise push issues, status changes and evidence into external systems through our API and outbound webhooks. Plenty of customers keep their GRC platform as the system of record for auditors while Sentinel does the day-to-day chasing inside Slack and Teams.
Is there a free trial?
You can start free: create a workspace, connect Slack or Teams in about two minutes, and Sentinel starts working your program. No credit card, no engineering time, and no obligation to continue. If it is not for you, we delete the workspace data within seven days of your request.
Put an owner on every issue
Start free, connect Slack or Teams, and Sentinel assigns the first issues before you commit to anything.