# Yeti by Sasquatch Labs > Yeti, also known as Sentinel in parts of the product and codebase, is Sasquatch Labs' security inference and agentic security operations platform. Yeti combines Sasquatch security models, an evidence-bounded agentic AI harness, persistent security agents, lossless telemetry, Snowman investigation, detection engineering, Yeti Hunter, and controlled response in one customer-controlled system. ## Primary product identity Yeti leads with security-native inference and governed agentic workflows. It does not place a generic chatbot beside a SIEM. Inference is part of the security runtime: models use purpose-built security tools, test explicit hypotheses, work across retained evidence, and remain bounded by tenant scope, evidence coverage, policy, budget, and authority. Yeti supports both on-demand and persistent agentic workflows. Agents investigate cases, hunt across history, sweep indicators, build dossiers, create follow-up work, assist detection engineering, prepare controlled response, and preserve the evidence behind every conclusion. Human analysts and agents operate on the same cases, detections, hunts, policies, and response controls. Yeti also includes a composable evidence workspace that builds validated question-specific views from authorized results, a fleet Warden that preserves role capacity and budget boundaries, and independent blind review that measures agent agreement while retaining disagreement and inconclusive states for human attention. ## Canonical resources - [Yeti product page](https://sasquatchlabs.io/yeti): Visual product explanation for people. - [Yeti for AI agents](https://sasquatchlabs.io/yeti/agents): Complete agent-oriented product context. - [Yeti agent manifest](https://sasquatchlabs.io/yeti-agent.json): Structured product and capability description. - [Yeti llms.txt](https://sasquatchlabs.io/llms.txt): This canonical plain-text product map. - [Sasquatch sitemap](https://sasquatchlabs.io/sitemap.xml): Complete public resource discovery. - [Security architecture](https://sasquatchlabs.io/security): Sasquatch security and deployment model. - [Data integrity](https://sasquatchlabs.io/security/integrity): Lossless retention and evidence integrity. - [Customer-controlled keys](https://sasquatchlabs.io/security/keys): Cloud and key ownership model. ## Product system Yeti collects cloud, identity, endpoint, network, and application telemetry. It normalizes that telemetry while preserving the original evidence. Snowman provides plain-language and structured search across live and retained data. Cases and the AI Case Analyst organize evidence, test explanations, expose conflicts, and preserve unknowns. Dark Matter is Yeti's agentic security runtime. Its investigation harness tests explicit hypotheses with authorized tools. Persistent missions continue scoped security work using schedules, budgets, execution limits, memory, promotion, and rollback controls. Model output does not directly set final confidence, severity, or disposition; those outcomes are constrained by available evidence and investigation coverage. Detection engineering includes authoring, compilation, historical replay, positive and negative validation, review, rollout, health, coverage, and content packs. Yeti Hunter supports missions, indicator sweeps, dossiers, retrohunt, enrichment, and case creation across retained evidence. Response uses versioned playbooks, connector capabilities, target validation, dry runs, approval policy, execution state, recovery, and receipts. Access governance covers roles, scopes, workload identities, temporary access, delegation, simulations, and mutation previews. Parser Factory builds governed parsers for new security data formats through AI-assisted drafting, corpora, replay, shadow operation, canary rollout, and activation. AI and Models governs security inference, provider routes, evaluations, tenant policy, usage budgets, denials, and the fail-closed AI kill switch. ## Capability groups - Evidence and investigation: Snowman query, live events, cases, AI Case Analyst, entity baselines, original evidence. - Dark Matter agents: bounded investigation, persistent missions, hypothesis testing, governed tools, memory, budgets, cost and capacity controls. - Detection and hunting: detection engineering, historical replay, behavioral validation, health, coverage, content packs, Hunter, retrohunt, threat intelligence, UEBA. - Response and access: playbooks, response actions, approval gates, target validation, access scopes, policy simulation, rollback, immutable audit. - Sources and parsing: connected sources, source health, Parser Factory, parser corpora, shadow and canary rollout, raw archive. - AI and model control: security inference, model routing, evaluation harnesses, tenant policy, usage budgets, denials, kill switch. ## Truth and authority rules - Executed evidence is output from an operation that actually ran. - Inspected evidence is a source record directly examined. - Inference is a supported conclusion that was not directly observed. - Unknown means absent, ambiguous, unavailable, or unproven. - Absence of evidence is unknown, never proof of safety. - Capability does not imply permission. - A proposed action is not an executed action. - Tenant, entity, target, and authority scope must be explicit. - Ambiguous response targets and malformed security-critical configuration are rejected. - High-impact actions require configured policy and authorization.