UbID Sentinel AI
UbID Sentinel AI is the product domain for evidence-grounded operational assistance. It helps authorized teams interpret complex service, security, trust, and recovery evidence while deterministic systems remain authoritative for state changes and cryptographic outcomes.
The objective is not to place a language model in control of identity infrastructure. It is to reduce the time required to understand evidence, prioritize investigation, and prepare governed actions.
Appropriate uses
Under approved access and policy, Sentinel AI may assist with:
- summarizing service posture and recent changes;
- correlating alerts with relevant evidence;
- explaining which trust domain or user journey may be affected;
- identifying missing information before an operation can proceed;
- preparing a proposed investigation or remediation plan;
- validating whether a request contains the required fields;
- comparing an observed state with a documented policy or runbook;
- producing an evidence-referenced briefing for an authorized decision-maker.
Deterministic authority
Language-model output is advisory. Authoritative services continue to determine:
- credential issuance and status;
- identity-proofing outcomes;
- authentication and authorization;
- key and cryptographic operations;
- recovery preparation and release;
- policy enforcement;
- whether an external action was actually executed.
Sentinel AI must not claim that an operation occurred unless authoritative evidence confirms it.
Evidence grounding
A trustworthy operational assistant should link conclusions to specific evidence rather than relying on an unsupported narrative.
Evidence grounding includes:
- named data sources;
- timestamps and freshness;
- checksums or immutable references where appropriate;
- policy version;
- distinction between observation, inference, and recommendation;
- clear acknowledgement of missing or conflicting evidence.
When evidence is incomplete, the correct result may be to stop, request clarification, or escalate to a human reviewer.
Guardrails
Public guardrail principles include:
- least-privilege access to tools and resources;
- read-only operation by default;
- allow-listed tools and schemas;
- explicit authorization for state-changing actions;
- separation of preparation, validation, approval, and execution;
- idempotent and traceable runs where practical;
- protection against prompt-based attempts to expand authority;
- no silent external browsing or use of unapproved data sources;
- no exposure of secrets, personal data, or internal operational details in summaries.
MCP and trusted tools
Sentinel AI can use controlled tool interfaces, including Model Context Protocol resources and tools, to discover approved capabilities and retrieve evidence.
MCP is an integration mechanism, not an identity or credential standard. Its use must remain subject to authentication, authorization, schema validation, evidence, and institutional accountability.
High-impact identity actions should follow the pattern prepare → validate → approve → execute. An AI assistant may prepare and validate, but execution requires explicit policy or human authorization.
Human accountability
AI assistance does not transfer accountability away from the institution. Authorized people remain responsible for:
- reviewing material conclusions;
- confirming the scope of requested actions;
- resolving ambiguous or conflicting evidence;
- approving high-impact changes;
- ensuring that legal, privacy, and security obligations are met.
Relationship with other products
- UbID Pulse provides operational and trust evidence.
- UbID Trust API provides governed tool and data contracts.
- UbID KeyVault remains authoritative for cryptographic operations.
- UbID Recover retains guarded approval and release stages.
- UbID Credential Cloud, Proof, and Access remain authoritative for their domain decisions.
Public documentation boundary
Public documentation explains roles, evidence grounding, and guardrails. Internal prompts, tool credentials, private resources, incident data, action paths, model security controls, and customer-specific automation remain restricted.
See also MCP and Trusted Agents, Auditability and Observability, and UbID Pulse.