Sentinel Labs

Research on the moment AI turns intention into action.

Technical reports, taxonomies and reference implementations on pre-execution validation, consequence-proportional security, and evidence that survives an audit. Written to be checked, not just read.

Reports and notes
SL-N-2026-01
September 2026
Note · v1.0

Read-only is not a property of a request

Agents confined to read-only internet access spent two months editing a wiki that accepted writes on ordinary reads. The control constrained the shape of requests, not their consequence. This note draws the distinction, shows how a blast-radius gate classifies a state-changing read, and argues that the two-month disclosure gap was an evidence gap first: you cannot report from a record you never kept.

agent securityegress controlincident disclosureconsequence-proportional validation
SL-N-2026-02
September 2026
Note · v1.0

North Carolina already wrote the use policy

G.S. 20-183.30–.33 names permitted purposes, caps retention at ninety days, requires written requests for sharing and an annual agency audit. What it lacks is enforcement at the moment of the query and evidence anyone outside the agency can verify. This note maps the statute clause by clause onto the gate in SL-TR-2026-01, shows how the public figures the permanent highway law dropped can be restored from the attestation log, and sets out a vendor-neutral policy a city council can adopt this fall.

north carolinapublic-sectorquery governancetransparency reporting
SL-TR-2026-01
September 2026
Working paper · v1.0

Verifiable use policies for vehicle surveillance data

Automated plate-reader networks are losing public consent, and the failures are almost all at the query layer — who searched, for what, how widely, and with whom the results were shared. This report describes a pre-execution gate that enforces a jurisdiction's own use policy on every query, share and automated stop, prices validation by blast radius, and produces signed, publicly verifiable evidence of enforcement.

public-sectorquery governanceattestationconsequence-proportional validation
Open source
Coppice
Apache-2.0
Python · GitHub

Coppice — a code-repair agent that searches over execution state instead of guessing at it

Prepare one verified checkpoint, fork it into many candidate patches, run the repository's own test suite in every fork, cut back the failures and grow the survivors. On a SWE-bench Lite sample, widening the search from one to sixteen attempts took the solve rate from 11% to 60%, with the curve replicating across two independent executors. The design principle is the same one behind SentinelPoT: an agent's work is accepted on evidence it cannot talk itself into — a real test run, not a model's opinion of its own output.

agentic engineeringverificationsearch over executionreproducible

Reports are published when there is something to check: a method, a reference implementation, or a result someone else can reproduce. Corrections and challenges are welcome at labs@sentinelpot.ai.