⚠ Not built. SG/Sentinel is a published design from May 2026 — “this is how I would build it” — not a product. No plans to build it unless somebody funds it. Read the note →
sg-sentinel.sgit.ai / documents / tabletop-2

SG/Sentinel Tabletop Simulation Part 2: Blocking Malicious Activity

TypeArch brief (tabletop simulation) Versionv0.27.58 Date18 May 2026 AuthorDinis Cruz (project lead) and collaborators LicenceCC BY 4.0 Sourceraw markdown · view on GitHub

Summary

The attack half: an obvious-bad probe, a WordPress scan, a brute-force on a valid login endpoint, a fast-tracked user turning malicious, a slow patient probe from rotating IPs, and an in-profile exploit — fourteen gaps, seven major. The consequential cluster: fast-track must never skip authorisation (9.1/9.2, the fundamental redesign); per-IP is insufficient against distributed attacks (8.2/10.3, multi-dimensional evidence keying); Sentinel is blind to auth outcomes without a reverse coupling from the app (8.3); and no-invalid-request is necessary but not sufficient — in-profile exploits need content rules and, ultimately, a secure application (11.1/11.2, the honest limit).

Key concepts

Key ideas

On this site

Second half of the tabletop section; GAP 6.1's HTTP-level actions ship in the MVP as the action enum.

Read the document

📄 Original document · v0.27.58 · 18 May 2026 · rendered from the raw markdown (the source of truth)