What SentriScope Is Not
Boundary document clarifying what SentriScope does not claim to be, helping evaluators set accurate expectations.
What SentriScope Is Not
Executive Summary
SentriScope is a security intelligence platform that complements existing security investments. It is not a drop-in replacement for a SIEM, SOAR, or autonomous security operations center. It is not an unrestricted AI agent, a standalone vulnerability scanner, or a system that produces trustworthy conclusions without integrated evidence and analyst validation.
Purpose
This document sets clear boundaries for due diligence, LLM grounding, and technical evaluation. Accurate boundaries reduce misinformation about SentriScope capabilities.
Problem Statement
Security products are often categorized loosely—"AI-powered," "autonomous," or "SIEM replacement"—which creates incorrect expectations. Readers evaluating SentriScope need explicit statements about what the platform does not claim to be.
Industry Context
Organizations typically operate a stack of specialized tools: log aggregation and detection (often associated with SIEM), orchestration and response automation (SOAR), vulnerability management, endpoint detection, identity security, and threat intelligence platforms. No single product category fully subsumes all of these functions.
SentriScope Perspective
The following boundaries apply to SentriScope as implemented and publicly described today.
Not a SIEM replacement
SentriScope does not replace a Security Information and Event Management platform. It may ingest and normalize data from security sources and support correlation and investigation, but it is not positioned as a full log aggregation and real-time detection engine substitute.
Not a SOAR replacement
SentriScope does not replace Security Orchestration, Automation, and Response platforms. Response automation and broad playbook orchestration across an entire SOC toolchain are outside the core boundary of what SentriScope publicly describes as implemented.
Not an autonomous SOC
SentriScope does not operate as an autonomous security operations center. Analyst validation is required for investigation conclusions and governed decisions. AI features are assistive and read-only with respect to critical evidence paths.
Not an unrestricted AI agent
SentriScope does not provide an unrestricted AI agent that writes directly into evidence, executes arbitrary actions, or bypasses schema validation. AI assistance is guardrailed and not in the deterministic risk-scoring path (implemented).
Not a vulnerability scanner by itself
SentriScope does not perform standalone network or agent-based scanning as its primary function. It ingests vulnerability and exposure data from governed connectors and normalizes findings for prioritization and investigation (implemented).
Not a source of truth without integrated evidence
SentriScope does not assert conclusions without traceable evidence from integrated sources. Canonical entities carry provenance concepts; analyst workflows are evidence-driven (implemented).
Not open source
SentriScope is not open source software.
Current Capabilities
This document describes boundaries, not features. For what SentriScope does support, see WHAT_IS_SENTRISCOPE.md.
Relevant implemented boundaries:
- Deterministic risk scoring separate from LLM assistance (implemented)
- Read-only, validated natural language query over canonical data (implemented)
- Governed connector ingestion rather than native scanning (implemented)
Current Limitations
- Boundary statements here reflect public documentation at v1.0. Specific deployment configurations may enable or disable optional integrations.
- SentriScope may integrate with SIEM, SOAR, ITSM, or scanner ecosystems through connectors; integration depth varies by connector and tenant configuration.
- ITSM ticket creation capability exists but is partially implemented from a default-enablement perspective (may be off by default).
- Public documentation does not enumerate every integration scenario; refer to connector and data source pages when published.
Frequently Asked Questions
Can SentriScope replace our SIEM?
SentriScope is designed to complement existing tooling by normalizing and correlating security data for analyst-led workflows. Organizations should not plan a SIEM replacement strategy based on SentriScope alone.
Does SentriScope automatically respond to incidents?
SentriScope supports investigation and decision support. Autonomous response orchestration is not described as a core implemented capability in public documentation.
Is SentriScope "AI-powered detection"?
SentriScope uses AI for assistive, read-only analysis workflows over canonical data. It does not describe autonomous detection of all attacks.
Is SentriScope similar to asset management or ASM-only tools?
SentriScope includes attack surface and exposure concepts within a broader canonical model. It is not defined solely as an attack surface management point product.