This is not a dashboard somebody expects you to keep glancing at. Three things arrive with every lever below. An agent that grasps the conduct of a process. A layer reading the agent alongside everything else moving on your estate. And a human being on duty who settles matters at four in the morning when a bell rings.
Recognising a known bad file stopped being sufficient years back. What SentinelOne does instead is model conduct on the machine: which children a process started, which files got opened, which addresses it reached toward, and whether the shape of all that resembles encryption, hoarding, or somebody moving softly across a network. None of this needs a connection, so a laptop on a train and a spare box under a bench are judged the same way.
Fluency then puts those reports beside everything else: sign-ins with the country they came from, what mail did, what the network saw, and logs from tools already on your books. A thing arriving at our desk therefore arrives with its surroundings attached, which is precisely the distance between being informed and being assisted.
The plain detection lever sorts and advises. The extended lever throws the net wider, so a peculiar sign-in raised in one country and an unusual process running on a machine elsewhere stop sitting in two windows as two separate oddities. The response grade goes further, containing and then reversing, and that grade is the one to hold when a bell rings at two on a Sunday.
Levers for cluster nodes stand on their own. A node behaves nothing like a laptop, the agent works differently on it, and quietly counting nodes as endpoints would put a false figure on your invoice. Count nodes. Never count pods.
Rates are lifted live from billing while this page loads. Whatever you send to the sheet sits waiting while you read on.
Conduct is modelled on the endpoint itself, and a staffed desk works whatever the agent raises. What you receive is a ruling with a recommendation on it, never a chart somebody hopes you will interpret before breakfast.
| Cleared for | Windows, macOS and Linux endpoints |
|---|---|
| Protects | The box itself, its running processes, and files those touch |
| Held until | An agent is on the machine and the machine has enrolled |
| Signalled by | SentinelOne, with Fluency correlating a layer up |
| Confirmed by | Case history held in the register, worked at our desk |
Everything the plain lever does, with the horizon pushed out, so that an unfamiliar sign-in raised in one place and an unfamiliar process running in another cease to be two curiosities filed in two windows.
| Cleared for | Endpoints, alongside identity, mail and network feeds |
|---|---|
| Protects | The box, plus whichever accounts can get at it |
| Held until | Feeds are plumbed in and the agent is reporting |
| Signalled by | SentinelOne, widened out by Fluency across sources |
| Confirmed by | Correlated cases naming each feed that agreed |
This is the grade that acts. Once something is convicted the agent shuts the machine off from the rest and puts back what the process altered, which beats a telephone call asking permission in the small hours of a Sunday.
| Cleared for | Windows, macOS and Linux endpoints, acting unattended |
|---|---|
| Protects | The box, contained and reversed wherever a platform allows it |
| Held until | You have settled which actions may run with nobody watching |
| Signalled by | SentinelOne Complete, correlated by Fluency |
| Confirmed by | A record naming what ran, at what hour, and on what evidence |
A node has nothing in common with a laptop. The agent behaves otherwise, workloads shift about, and rolling nodes in with endpoints would quietly print an untruth on your invoice. Count the nodes. Pods never come into it.
| Cleared for | Worker nodes and control plane nodes in a cluster |
|---|---|
| Protects | Conduct of processes and containers, judged at node level |
| Held until | The node agent has gone out across the cluster |
| Signalled by | SentinelOne, with Fluency correlating a layer up |
| Confirmed by | Node cases raised and worked at our own desk |
Node telemetry read against everything else you feed in. A container doing something odd means one thing alone, and quite another once you notice the account that deployed it signed in from an unfamiliar place an hour earlier.
| Cleared for | Cluster nodes, read beside whatever else you plumb in |
|---|---|
| Protects | Node conduct, tied to identity and network events around it |
| Held until | The cluster is enrolled and feeds reach Fluency |
| Signalled by | SentinelOne Complete, correlated by Fluency |
| Confirmed by | Cases naming the node together with events surrounding it |
The response grade applied to cluster nodes. Conviction brings containment at node level, under a policy you have signed off, because arming an automatic action against production is not a thing anybody should do casually.
| Cleared for | Cluster nodes, with unattended action allowed |
|---|---|
| Protects | Workloads at node level, shut off once something is convicted |
| Held until | A response policy for the cluster is agreed in writing |
| Signalled by | SentinelOne Complete, running on the node |
| Confirmed by | One action log per node, readable after the event |
As a control this is excellent. Mistake it for a guarantee and it is worth nothing at all. Below is what these six levers cannot reach, put plainly so you can judge what else the business needs.
Heads up: card statements show FORTIFY 24X7 - ServiceShield IT is a Fortify 24x7 brand, and your subscription is billed by Fortify 24x7.