Autonomous DevOps

Sentinel

See everything. Diagnose anything. Heal automatically.

Sentinel is an AI-driven DevOps control plane for your AWS cloud. A thin agent runs inside your own account and dials out to the control plane (no inbound access, no VPN, least-privilege IAM), and every metric, incident, and audit record persists in a PostgreSQL database in your own cloud. A continuous watch loop scans ECS, RDS, ALB, and ElastiCache around the clock; an AI root-cause engine correlates metrics, logs, and recent deploys into a plain-English diagnosis with a P0-P3 severity; and policy-gated, confidence-scored automations restart, redeploy, or scale the affected service. Cost rightsizing, WAF and security-group drift insights, and a scheduled-jobs health view round it out - so one engineer can operate the whole platform in minutes a day.

Capabilities

What Sentinel does

01

An agent in your own cloud

A thin agent runs inside your own AWS account and dials out to the control plane over an enrollment token. No inbound access, no VPN, least-privilege IAM. Telemetry, incidents, and the audit trail persist in a PostgreSQL database in your own cloud, never on Juniors AI servers.

02

One pane of glass

Unified monitoring across your services: ECS CPU and memory with scaling, ALB p99 latency and 5xx errors, RDS load and free storage, and ElastiCache health, all in one place. No more tab-hopping between half a dozen consoles.

03

Continuous watch loop

Sentinel scans your infrastructure every few minutes, around the clock. Live metrics are compared against your thresholds, and an incident opens the moment a signal breaches - while routine autoscaling noise is filtered out so only real, paging incidents surface.

04

AI root-cause analysis

When a signal breaches, the RCA engine pulls the relevant metrics, logs, and recent deploys and correlates them into a plain-English diagnosis: a P0-P3 severity, a confidence score, the likely root cause, a recommended action, and any attack indicators. With no LLM configured it falls back to an actionable rule-based assessment, so an incident is never blocked.

05

Policy-gated self-healing

Guarded fixes run automatically when you allow them: restart a crashed service, redeploy a bad release, scale a saturated one. Remediation only fires above a confidence threshold and inside a hard capacity clamp, every action is audit-logged, and anything outside policy waits for a human instead. Auto-remediation ships off by default.

06

Cost and rightsizing

Month-to-date spend, top services by cost, Savings Plan opportunities, and rightsizing recommendations - so capacity stays matched to demand without overpaying.

07

Deploys and CI/CD in one place

Connect your GitHub repos to see deployment history across all of them, drill into a live workflow run's jobs and logs, and trigger a manual deploy from the dashboard - so the same place you watch and heal your platform is where you ship to it.

08

Security and drift insights

Watch attacks being blocked at the edge by your firewall, catch security rules that have accidentally opened up to the entire internet, and review a threat snapshot of the countries, IPs, and paths under fire - alongside any security incidents Sentinel has opened.

09

Slack alerts and a full audit trail

Incidents page Slack with a rich, clearly formatted diagnosis, routed by severity so a P0 is loud and a P3 stays quiet - with a global mute and a fail-safe fleet pause when you need them. Every remediation, scaling action, and infrastructure change is written to a tamper-evident audit log.

Integrations & data sources

  • AWS ECS, RDS, ALB, ElastiCache
  • CloudWatch metrics & alarms
  • AWS WAF & security groups
  • Cost Explorer & Savings Plans
  • Scheduled jobs (EventBridge / cron)
  • GitHub Actions deploys
  • Slack alerts
  • Any LLM

On the stack

  • AI root-cause engine on your LLM key
  • Outbound-only agent in your own cloud
  • Telemetry, incidents & audit in your own database
  • Policy-gated, confidence-scored automations
  • Tamper-evident audit trail
  • Enrollment-token auth, no inbound access
MCP + API

Drive Sentinel from your AI agent

Sentinel is exposed through the Juniors AI MCP server, so Cursor, Claude, and any other MCP client can work with it directly. Grant a key the sentinel:read scope for the read tools, or sentinel:write to include the writes.

Read7 toolssentinel:read
  • sentinel_overview

    Fleet health at a glance: services, incidents, and what needs attention now.

  • sentinel_monitoring

    Live ECS, RDS, ALB, and ElastiCache metrics against your thresholds.

  • sentinel_alarms

    Open incidents with their AI root-cause diagnosis and severity.

  • sentinel_cost

    Month-to-date spend, top services, and rightsizing opportunities.

  • sentinel_security

    Firewall blocks, security-group drift, and the current threat snapshot.

  • sentinel_activity

    The audit trail of every remediation, scaling action, and change.

  • sentinel_cicd_deployments

    GitHub Actions deployment history across your connected repos.

Try asking your agent

Check fleet health, then summarise every open incident with its root cause and what you would do about it.

Set up MCP

33 tools across all six products, plus a public OpenAPI spec at /api/openapi.json if you would rather call the REST API directly.

Sentinel FAQ

Sentinel - common questions

Sentinel is the autonomous DevOps product inside the Juniors AI workspace. It watches your AWS infrastructure continuously, diagnoses incidents with AI root-cause analysis, and acts through policy-gated automations (restart, redeploy, scale) so a small team can operate a large platform in minutes a day.

Ready to run Sentinel on your infrastructure?

Get early access to the full Juniors AI workspace.

Get Access