Canonical agent knowledge document · Yeti / Sentinel

Security inference.
Agentic security workflows.

Yeti is Sasquatch Labs’ security inference and agentic security operations platform. It combines security-native inference, governed agentic workflows, persistent security missions, complete evidence, detection engineering, hunting, and controlled response in one customer-controlled system.

What makes Yeti different

Yeti does not place a generic chatbot beside a SIEM. Models operate through a governed security harness, use purpose-built security tools, test explicit hypotheses, and remain bounded by evidence coverage, tenant scope, policy, budget, and authority. Model text is never silently converted into fact, confidence, permission, or execution.

Complete capability families

Security inference
Evidence-bounded reasoning across identities, endpoints, email, cloud, network, applications, cases, detections, hunts, and response state.
Dark Matter
On-demand investigations and persistent security missions with governed tools, memory, schedules, budgets, autonomy policy, promotion, and rollback.
Agentic workspace and trust
Composable evidence views, shared agent work and memory, fleet capacity governance, and independent blind review with explicit agreement, disagreement, and inconclusive states.
Snowman
Plain-language, native, and SPL-style investigation across events, logs, metrics, traces, live data, retained history, and original evidence.
Cases and incidents
Queues, timelines, entities, recurring context, evidence, hypotheses, verdicts, feedback, handoffs, reports, and response linkage.
Detection engineering
Sigma-style and stateful detections, AI-assisted authoring, compilation, historical replay, positive and negative behavioral proof, review, activation, health, coverage, revision, and rollback.
Yeti Hunter
Interactive and scheduled hunts, indicator sweeps, durable retrohunts, pivots, findings, dossiers, follow-ups, health, and immutable hunt-to-case provenance.
Threat context
Threat-intelligence feeds, indicator operations, UEBA, entity baselines, risk evidence, critical assets, and evidence-backed threat graph relationships.
Controlled response
Versioned playbooks, connector capabilities, protected targets, validation, dry runs, approval, execution, partial failure, reconciliation, receipts, readiness, and rollback.
Access and governance
Roles, resource scopes, workload identities, temporary access, delegation, effective permissions, policy simulation, mutation preview, access review, audit, and compliance evidence.
Collection and sources
Cloud, identity, endpoint, email, network, application, database, infrastructure, security-product, HTTP, HEC, Kafka, relay, syslog, flow, and cloud-native telemetry.
Parser Factory
Governed corpora, AI drafts, compile, replay, review, approval, shadow, canary, activation, convergence, revocation, and rollback.
Evidence and storage
OCSF-aligned normalization, original-record linkage, provenance, replay awareness, live events, historical search, raw archive, retention, recovery, and evidence health.
AI and models
Security-specific inference, governed model routing, tenant data policy, evaluations, usage accounting, budgets, denials, and a fail-closed kill switch.
Operations and deployment
Dashboards, executive risk, alerts, delivery, readiness, audit verification, customer-controlled deployment, air-gap operation, and interoperability.

Truth and authority

  • Absence of evidence is unknown, never proof of safety.
  • Capability does not imply permission.
  • Proposed, approved, executed, delivered, reconciled, remediated, and rolled back are distinct states.
  • Ambiguous targets and malformed security-critical configuration are rejected before mutation.
  • Confidence is constrained by evidence coverage and discrimination between alternatives.

Canonical resources

Use the JSON manifest for exact structured capabilities. Use this document for semantic context. Use llms.txt for discovery and routing. The human page is the visual product experience.