IT Sentinel

Your IT and security tools, in one conversation.

IT Sentinel is an AI assistant that runs on your own server, reads your SIEM, endpoint protection, firewall, Active Directory, Microsoft 365 and ticketing, and answers in plain language, with the evidence.

Tell us about your environment → Fully on-premises. Read-only. Every answer checked.
Your tools (SIEM, endpoint protection, firewall, Active Directory, Microsoft 365, ticketing, monitoring, backup, threat intelligence and your policies) feed IT Sentinel on your own server, which gives you answers, alerts, findings and one-click reviews.

The problem

Small teams, the same tools as large ones

Small IT teams run the same tools as large ones (a SIEM, EDR, firewall, directory, cloud, backup, ticketing) without the people to watch them. Each tool has its own console and its own language. The answer to "did anything bad happen last night?" is spread across six of them, and the question nobody asked is the one that matters.

What it does

Ask

"Which accounts failed to sign in from outside the country this week?" "What does this GPO actually do?" "Is anything exposed to the internet that shouldn't be?" One question, and it queries every relevant system.

Get told

Alerts arrive in Microsoft Teams already investigated: who, what, where, and what to check next. A daily briefing and a findings list, each with a one-click ticket and an Investigate button.

Findings include directory risks nobody checks by hand: accounts that can copy every password hash, Kerberoastable service accounts, unconstrained delegation, an old krbtgt password.

Review

One button produces a fresh report: unused Group Policy, risky firewall rules, audit-policy problems, stale devices, idle mailboxes, unused licenses, guests who never accepted, expired app secrets.

Prove the fix

After you change something, ask "did my fix work?" and it re-runs that check live, then tells you what's fixed, what's still there and what's new.

One click runs a fresh IT review covering Group Policy, the firewall, audit-policy health, and Microsoft 365, Entra and Active Directory clean-up.
Find it, fix it, prove it: a scheduled audit finds a risk, one click investigates it, a person applies the exact fix, and asking 'did my fix work?' re-runs the check live.

How it works

From a question to a checked answer

  1. You ask in plain language, in a web portal on your network.
  2. Questions it recognises (a review, a named policy) run the right check first.
  3. The model calls read-only tools that fetch live data from your systems.
  4. A local language model, running on your own GPU server, writes the answer.
  5. Code checks every concrete claim against what the tools returned, then corrects or marks it.
  6. You get the answer with its sources, plus Export and "+ Ticket".
Six steps: you ask; recognised questions run the right check first; read-only tools fetch live data; a local model writes the answer; code checks every claim against the data; you get the answer with sources, export and a ticket button.

Private and verifiable

Your data stays yours. Its answers can be checked.

Runs on your hardware

Fully on-premises: the model, the data, the logs and every answer stay in-house, on your network. No prompts or results are sent to an AI service, or to us.

Read-only by design

Its tools only read your systems. The one thing it writes is a help-desk ticket, when you ask for one.

A person approves every change

It recommends, drafts tickets and writes the exact commands; it doesn't run them.

Checks its own answers

Addresses, rule and policy numbers, CVEs, compliance control IDs, host names, identifiers and dates must come from the data, or the answer is corrected or marked "not confirmed".

Your directory decides who's in

Sign-in uses your own accounts, limited to a group you choose; roles can give managers and help desk staff different tools and data.

Watches itself

A watchdog checks the SIEM, the language model and its GPU, and posts to Teams when one of them stops, so a quiet assistant is never mistaken for a quiet network.

What it connects to

The tools you already run

SIEM / XDR
Wazuh, including Sysmon and Windows audit logs from its agents
Endpoint protection
SentinelOne, Palo Alto Cortex XDR
Firewall
FortiGate, one site or several, including application control
Email security
Perception Point
Directory
Active Directory (LDAP, Group Policy, SYSVOL)
Cloud and identity
Microsoft Entra ID, Microsoft 365, Exchange Online, Azure
IT service management
GLPI
Monitoring
Zabbix
Backup
Veeam, Rubrik
Virtualisation
VMware Cloud Director
Phone system
FreePBX / Asterisk
Threat intelligence
abuse.ch, Spamhaus, AlienVault OTX, VirusTotal
AI usage
Microsoft 365 Copilot activity, firewall AI-application traffic, AI tools started on PCs
Alerts and SOC
Microsoft Teams; real-time log forwarding to an outsourced SOC
Compliance
ISO 27001 controls, mapped to your own policies

Not on the list? Integrations are modular; tell us what you run.

Questions it answers

Ask it the way you'd ask a colleague

Any critical alerts in the last 24 hours?
Lists them by severity, with the host, the rule and what to check next.
Investigate this impossible-travel alert.
Pulls the sign-ins, locations, device and MFA details, and lays out what points each way.
Which servers have no endpoint protection?
Compares the directory with the endpoint console and lists the machines missing from it.
What's published to the internet on the firewall, and to whom?
Every published service, the rule that allows it and who may reach it.
Are any of our Group Policies unused? What does the 'Drive Maps' one do?
A verdict per policy with the reason, and each setting explained in plain words.
Which shared mailboxes haven't been used in 90 days, and can I delete them?
The list, and what deleting each one would destroy, so a person decides.
Who used AI tools on their PC today, and what did they do?
Per person and PC, plus the machines it can't see, so silence isn't read as "none".
Did any Copilot session trigger a prompt-injection or jailbreak warning this week?
The flagged sessions, with the app and the user.
Who is using PC-042?
The employee's name, the PC's IP address and the last sign-in. Nothing more.
I removed those permissions. Can you check that the fix worked?
Re-runs the check live: fixed, still there, or new since the last run.
Which security groups are empty, and is anything still pointing at them?
The empty groups, keeping apart the ones a sign-in policy or a GPO filter still uses.
Did any malicious email stay in someone's mailbox today?
Only the messages that stayed after detection, and who received them.
Which ISO 27001 controls cover this finding?
The controls from your own policy documents, not a generic list.
Who uses AI, and how: AI tools started on the PCs, AI traffic seen by the firewall, and Microsoft 365 Copilot activity feed one answer, which always states which machines it can and can't see.

Things it found that nobody was looking for

A log that went quiet

A server group had stopped sending a whole category of Windows logs for weeks; every dashboard looked fine because no alert fires on silence. The daily "questions worth asking" now flags data that should arrive but doesn't.

An audit setting that switched itself off

Two kinds of audit policy were overriding each other, turning sign-in auditing off and on every few minutes. It surfaced as a flood of one event, which the review now checks for.

Reports that hid their own names

The cloud usage reports were anonymised by a tenant setting, which would have turned one departed user's files into dozens. The review refuses to guess and names the setting to change.

A permission nobody remembered granting

The scheduled directory audit found an account with the right to copy every password hash in the domain. Investigate explained the risk and the fix; after the admin removed it, "did it work?" re-ran the check live and confirmed it.

One phone, three addresses

The threat-intelligence feed flagged firewall sessions to a known command-and-control server from the guest Wi-Fi, whose shared address moved between access points as if it were three machines. Lining the hit times up with the connected clients pointed to one phone; it was blocked, and the feed has shown no attempts since.

What you get

A deployment, not a subscription to someone else's cloud

  • Installed on your hardware: a server with a GPU on your network, or a VM you provide (sizing advice included).
  • Connected to your stack: a dedicated account per system, alert routing to Teams, rules tuned to your noise.
  • The portal: chat (quick answers or advisor mode), findings with tickets, dashboards, one-click reviews, a wallboard view.
  • Grounded in your policies: advisor mode cites your own ISO 27001 controls and documents.
  • Hand-over and support: documentation, a walkthrough, and help as your environment changes.

FAQ

Questions we get asked

Does any data leave my network?

No. IT Sentinel is fully on-premises: everything it collects, stores and writes stays on your server. Nothing goes to an AI service, and nothing comes to us. Integrations that are themselves cloud services (Microsoft 365, a cloud EDR) are read through their APIs into your server, as your admins already do.

Which AI model does it use?

An open-weight model that runs locally; the exact model depends on your hardware.

What hardware do I need?

A server or workstation with a recent NVIDIA GPU (16 GB of VRAM is a good start). Exact sizing depends on your environment.

Can it make changes?

No. It's read-only. It drafts tickets and exact steps for a person.

How long does a deployment take?

It depends on how many systems you connect. First answers usually come within days, tuning over the first weeks.

We already have an outsourced SOC. Does this replace it?

No, it works next to it. It can forward the logs your SOC needs in real time, and it answers the questions a SOC doesn't: what's in your directory, your Microsoft 365 tenant and your Group Policy.

Is it a product or a service?

Both: the software plus the work of connecting and tuning it.

Contact

Tell us about your environment

Which tools you run, how big the team is, what you'd ask it first. We read every message and reply within two working days. No newsletter, no sales sequence.

Thanks, your message is on its way.

We'll reply within two working days.