Skip to content

How it works

From OAuth to a working security program in one day

CISO Express is not a scanner you read reports from, and it is not a questionnaire you fill in once a year. It is an agent that takes the framework on your behalf, finds the humans who own each piece, and keeps asking until the work is done and the evidence is filed.

The agent loop

One agent running the whole program, in the tools you already pay for

Sentinel is not a scanner and not a questionnaire. It is the operating layer between your control framework and the humans who have to do the work — and it runs the same loop every day.

  1. 01

    Connect

    Slack or Microsoft Teams OAuth, plus read-only connectors for your identity provider, cloud accounts and repositories. Minutes, not months.

  2. 02

    Learn your org

    Directory sync maps every human to a role and an ownership set — who ships, who runs infra, who signs contracts, who holds the data.

  3. 03

    Find the gaps

    Framework controls, cloud configuration, identity state and vendor records produce a live register of open issues with severity and due dates.

  4. 04

    Nudge the right person

    Sentinel opens a direct message with the owner, states the ask in one sentence, links the evidence it needs, and sets an SLA by severity.

  5. 05

    Collect evidence

    When someone answers, the response becomes evidence attached to every control it satisfies. No screenshot hunts, no shared drive archaeology.

  6. 06

    Report and escalate

    Live dashboard, weekly digest, and automatic escalation up the chain the moment an SLA breaches. Every step is recorded for the audit trail.

The loop never stops and never forgets. A control that regresses reopens as an issue; an owner who leaves gets their queue reassigned to their manager; an evidence artifact that expires is re-requested before the auditor notices.

Walk through a full rollout

How it works

Live in a day, audit-ready in 30

No implementation project. Connect two systems and Sentinel starts working your program.

  1. 01

    Connect Slack or Teams

    A two-click OAuth install, plus read-only connectors for your identity provider, cloud accounts and code host.

  2. 02

    Sentinel learns who owns what

    Directory sync maps every person to a role: who ships code, who runs infrastructure, who signs contracts, who holds the data.

  3. 03

    Owners get the work

    Every gap becomes an issue with a severity, an owner and a due date. Evidence is collected as owners reply, and escalation fires when an SLA slips.

First month

What the first 30 days actually look like

Across the workspaces we onboarded this year, from 22 to 260 people.

  1. Week 1Phase 1

    Connectors live, org graph mapped, first register of 40–70 issues with named owners.

  2. Week 2Phase 2

    Owners are replying. Evidence starts landing on controls. First escalations fire and resolve.

  3. Week 3Phase 3

    Vendor reviews and access reviews open as recurring issues. Exec dashboard shared with the board.

  4. Week 4Phase 4

    Mock evidence request run. Auditors receive the binder export. Risk score up 8–12 points.

What you need to bring

  • An admin who can approve a Slack or Teams app install (10 minutes)
  • A read-only service account or OAuth grant for your identity provider
  • Read-only cloud access for the accounts that hold production data
  • The name of one human who can sign off on accepted risk

What you do not need

  • No endpoint agents on employee laptops
  • No network changes, VPN or firewall rules
  • No professional services engagement or implementation partner
  • No migration off your existing ticketing or GRC tooling

A real week

What it looks like when Sentinel goes to work

This is a composite of what happens in a customer workspace: a DevOps owner confirms a fix, evidence is logged against three frameworks, a misrouted issue is reassigned, and a missed SLA escalates without anyone having to escalate it.

sentinel-security· 42 members
Monitoring 61 controls

SentinelAPPMon 09:02

Hi Dana — Sentinel here, your CISO as a Service. Two things on your queue today.

SEC-1042 · MFA enforced on production root accounts · due Mon 08:00 · High.

Can you confirm it is applied? Reply *done* and I will re-run the check, or tell me what is blocking it.

Dana WhitfieldDevOps LeadMon 10:41

Applied it last night to both accounts. I also turned on the org-level policy so new accounts inherit it.

SentinelAPPMon 10:41

Verified independently: MFA is enforced on 2/2 root accounts and the org policy is on.

Evidence logged and attached to SOC 2 CC6.1, ISO 27001 A.8.5 and NIST CSF PR.AA-03.

SEC-1042 closed · 0 days past SLA · next check in 30 days

SentinelAPPWed 09:00

New: SEC-1051 · Vendor security review for Helios CRM · assigned to you until Legal is onboarded · due Wed 12:00.

I have the vendor’s security page and sub-processor list queued. Reply *start* and I will walk you through the four questions I could not answer myself.

Dana WhitfieldDevOps LeadWed 12:04

This one is not mine — it needs Legal. I do not want to sign a DPA I have not read.

SentinelAPPWed 12:04

Understood. Reassigning to Legal Counsel and updating the ownership map so vendor reviews route to Legal by default.

SEC-1051 escalation4 days late
  1. SLA breachedDana Whitfield · DevOps LeadFri 12:00
  2. Nudged owner againDirect message, threadedFri 12:05
  3. Manager looped inMarcus Lee · VP EngineeringSat 12:00
  4. Escalated to CTOPriya Raman · includes full reply historyMon 12:00
  5. CEO digestAdded to weekly risk summaryNext Mon

Why this matters to an auditor

Every message is timestamped, every control link is recorded, and every escalation names the human who was asked. When your auditor asks how you know access changes are reviewed, the answer is a query, not a memory.

Questions

The things operators ask us first

Straight answers, including the ones that are inconvenient for us.

Does Sentinel replace a human CISO?
It replaces the operating layer — the tracking, chasing, evidence gathering and reporting that consumes most of a security leader’s week. Starter and Growth are designed to run without one. Growth includes a quarterly program review with a human CISO, and Enterprise adds a dedicated named CISO plus an on-call security engineer for incident work, board questions and audit scrutiny.
How long does it actually take to go live?
Under a day. You install the Slack or Teams app with a two-click OAuth grant, connect your identity provider and cloud accounts read-only, and Sentinel maps your org on the first sync. Most teams see their first assigned issues within hours of connecting and a full program plan within 24 hours.
Which permissions does Sentinel need in Slack or Teams?
Directory read (so it can map people to roles), the ability to send direct messages and post in channels you explicitly approve, and the ability to read replies in threads it started. It cannot read your private channels or your employees’ direct messages with each other. The full scope list is published on our security page, and Enterprise plans can restrict the agent to a single channel if you prefer.
Do you train models on our data?
No. Your messages, findings, evidence and directory data are never used to train foundation models, and our sub-processors are contractually prohibited from doing so. We use a fixed, versioned model configuration per workspace and you can request deletion of your workspace data at any time.
What happens when nobody responds to Sentinel?
Escalation is automatic and time-boxed. After the severity SLA breaches, Sentinel nudges the owner again, then their manager, then the CTO, then the CEO, each with the original request and the response history attached. Every step is recorded, so your audit trail shows exactly who was asked, when, and what happened next. Unresolved items surface at the top of the weekly digest.
Can we use CISO Express for a real SOC 2 Type II report?
Yes. Sentinel maintains the control set, collects evidence continuously across the observation window, and exports an auditor-ready binder. The report itself must be issued by an independent CPA firm — we prepare everything they ask for, and we work with whichever auditor you choose rather than locking you into a partner.
How does pricing work as we grow?
You pay per workspace, not per seat, so adding employees never increases the bill. Tiers are based on headcount bracket and the scope of automation you need. If you cross a bracket mid-term, we prorate the upgrade and keep the same annual discount — and we will tell you before you need to ask.
We already have a GRC tool. Can we keep it?
Yes. Growth and Enterprise push issues, status changes and evidence into external systems through our API and outbound webhooks. Plenty of customers keep their GRC platform as the system of record for auditors while Sentinel does the day-to-day chasing inside Slack and Teams.
Is there a free trial?
You can start free: create a workspace, connect Slack or Teams in about two minutes, and Sentinel starts working your program. No credit card, no engineering time, and no obligation to continue. If it is not for you, we delete the workspace data within seven days of your request.

Put an owner on every issue

Start free, connect Slack or Teams, and Sentinel assigns the first issues before you commit to anything.