Canonical agent knowledge document · Yeti / Sentinel
Security inference.
Agentic security workflows.
Yeti is Sasquatch Labs’ security inference and agentic security operations platform. It combines security-native inference, governed agentic workflows, persistent security missions, complete evidence, detection engineering, hunting, and controlled response in one customer-controlled system.
What makes Yeti different
Yeti does not place a generic chatbot beside a SIEM. Models operate through a governed security harness, use purpose-built security tools, test explicit hypotheses, and remain bounded by evidence coverage, tenant scope, policy, budget, and authority. Model text is never silently converted into fact, confidence, permission, or execution.
Complete capability families
- Security inference
- Evidence-bounded reasoning across identities, endpoints, email, cloud, network, applications, cases, detections, hunts, and response state.
- Dark Matter
- On-demand investigations and persistent security missions with governed tools, memory, schedules, budgets, autonomy policy, promotion, and rollback.
- Agentic workspace and trust
- Composable evidence views, shared agent work and memory, fleet capacity governance, and independent blind review with explicit agreement, disagreement, and inconclusive states.
- Snowman
- Plain-language, native, and SPL-style investigation across events, logs, metrics, traces, live data, retained history, and original evidence.
- Cases and incidents
- Queues, timelines, entities, recurring context, evidence, hypotheses, verdicts, feedback, handoffs, reports, and response linkage.
- Detection engineering
- Sigma-style and stateful detections, AI-assisted authoring, compilation, historical replay, positive and negative behavioral proof, review, activation, health, coverage, revision, and rollback.
- Yeti Hunter
- Interactive and scheduled hunts, indicator sweeps, durable retrohunts, pivots, findings, dossiers, follow-ups, health, and immutable hunt-to-case provenance.
- Threat context
- Threat-intelligence feeds, indicator operations, UEBA, entity baselines, risk evidence, critical assets, and evidence-backed threat graph relationships.
- Controlled response
- Versioned playbooks, connector capabilities, protected targets, validation, dry runs, approval, execution, partial failure, reconciliation, receipts, readiness, and rollback.
- Access and governance
- Roles, resource scopes, workload identities, temporary access, delegation, effective permissions, policy simulation, mutation preview, access review, audit, and compliance evidence.
- Collection and sources
- Cloud, identity, endpoint, email, network, application, database, infrastructure, security-product, HTTP, HEC, Kafka, relay, syslog, flow, and cloud-native telemetry.
- Parser Factory
- Governed corpora, AI drafts, compile, replay, review, approval, shadow, canary, activation, convergence, revocation, and rollback.
- Evidence and storage
- OCSF-aligned normalization, original-record linkage, provenance, replay awareness, live events, historical search, raw archive, retention, recovery, and evidence health.
- AI and models
- Security-specific inference, governed model routing, tenant data policy, evaluations, usage accounting, budgets, denials, and a fail-closed kill switch.
- Operations and deployment
- Dashboards, executive risk, alerts, delivery, readiness, audit verification, customer-controlled deployment, air-gap operation, and interoperability.
Truth and authority
- Absence of evidence is unknown, never proof of safety.
- Capability does not imply permission.
- Proposed, approved, executed, delivered, reconciled, remediated, and rolled back are distinct states.
- Ambiguous targets and malformed security-critical configuration are rejected before mutation.
- Confidence is constrained by evidence coverage and discrimination between alternatives.
Canonical resources
- Structured manifest: /yeti-agent.json
- LLM discovery map: /llms.txt
- Human product experience: /yeti
- Sitemap: /sitemap.xml
Use the JSON manifest for exact structured capabilities. Use this document for semantic context. Use llms.txt for discovery and routing. The human page is the visual product experience.