DEVELOPER & SECOPS DOCUMENTATION

SentinelNHI Technical Documentation

Complete guides, integration walkthroughs, and REST API specifications for autonomous non-human identity governance.

1. Quickstart Guide

SentinelNHI connects to your SaaS estate agentlessly via official cloud provider APIs. Follow these steps to trigger your initial discovery scan:

1
Connect SaaS Providers:Navigate to Settings & Hub and click "Connect Integration" for Microsoft Entra ID, Google Workspace, GitHub, or Slack.
2
Trigger Initial Multi-SaaS Scan:Click "Scan Now" in the top console navigation or invoke POST /api/scans/trigger. Discovery completes in ~5 seconds.
3
Review Risk Ratings:Inspect discovered machine identities under NHI Inventory. Each identity is scored from 0–100 using pgvector embeddings.

2. SaaS Platform Connectors

SentinelNHI requires minimal read-only permissions to audit machine identities. You never grant full write or super-admin credentials during discovery:

Microsoft Entra ID (Graph API)
• Application.Read.All
• Directory.Read.All
Used to evaluate enterprise application consent grants and client secret expirations.
Google Workspace (Admin SDK)
• admin.directory.user.readonly
• iam.serviceAccounts.list
Uncovers service accounts with Domain-Wide Delegation (DWD) granted.
GitHub Enterprise
• members:read
• administration:read
Monitors organization deploy keys with write permissions, PATs, and GitHub Apps.
Slack Enterprise Grid
• apps:read
• users:read
Flags bot tokens authorized for private channel history and file reading.

3. Zero-Day Real-Time Ingestion Webhooks

Don't wait for scheduled daily scans to detect rogue credentials. Configure event webhooks in your SaaS platforms to ingest new deploy keys, PATs, and OAuth grants the instant they are created:

// Example: Ingesting GitHub deploy_key event
POST https://sentinel.tkoresearch.com/api/webhooks/github
Content-Type: application/json
X-Hub-Signature-256: sha256=...

{
  "action": "created",
  "key": {
    "id": 8941029,
    "key": "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5...",
    "title": "ci-runner-deploy-key",
    "read_only": false
  },
  "repository": { "full_name": "acme/prod-core" },
  "sender": { "login": "devops-admin" }
}

4. Autopilot Governance & CISO Whitelists

Autopilot enables autonomous containment without human intervention for high-risk threats, while providing flexible CISO waivers for critical legacy systems:

Departed Owner Rule:If the human employee who created an OAuth token is deactivated in Okta or Google Workspace, Autopilot quarantines the token immediately.
CISO Risk Exemptions (Whitelists):Grant temporary 30-day or 90-day waivers with business justifications for production systems undergoing migration, preventing accidental automation lockouts.

5. REST API Reference

All dashboard capabilities are accessible via standard REST endpoints with bearer token authentication:

MethodEndpointDescription
GET/api/identitiesFilter & list all discovered machine identities
POST/api/scans/triggerTrigger instant multi-SaaS discovery scan
POST/api/remediation/executeExecute quarantine, revoke, or scope trim
POST/api/compliance/generateGenerate DORA / NIS2 / Insurance passport (R2)
POST/api/billing/checkoutInitialize Stripe Checkout subscription session