.png&w=256&q=75)
1
1
Looking for experience!

Security incidents are not single-prompt problems. Investigation, engineering review, threat assessment, compliance judgment, approval, containment, and reporting are separate responsibilities that must share context without collapsing into one opaque answer. Sentinel Relay turns that process into a visible multi-agent workflow. A Band Leader opens a shared incident room and delegates work to Forensics, Code Review, Threat Intelligence, Risk & Compliance, and Remediation agents. Each specialist posts structured findings and evidence references into Band. Risk & Compliance can challenge unsupported claims, and high-impact containment remains blocked until a human Security Lead approves a precisely scoped action. Band is the coordination layer—not a notification wrapper. It carries agent identity, task handoffs, shared room context, challenges, approval state, remediation updates, and the collaboration record used to generate the final report. The War Room makes that coordination legible in seconds through a message stream, evidence board, collaboration map, decision state, and audit replay. The demo investigates a synthetic API-key exposure after a Friday deployment. Agents correlate API access, authentication events, code changes, incident policy, and customer-impact evidence. They distinguish proven unauthorized access from unsupported exfiltration claims, request approval for issuer-first containment, and preserve the decision boundary that customer notification remains held pending scope verification. Sentinel Relay includes a production-deployed Next.js interface, typed shared schemas, Python agent workers, a server-side Band adapter, AI/ML API reasoning for the policy gate and Band Leader synthesis, deterministic replay for demo reliability, two generalization fixtures, and verification gates covering build, schema integrity, evidence grounding, dissent, approval controls, routing, and report traceability.
19 Jun 2026