Loading metrics...
Dependency Vulnerabilities
Click to scan dependencies for known vulnerabilities
View details →
Dependency Vulnerabilities
Click "Scan Dependencies" to check for known vulnerabilities
Governance Profile
Human Review Gates
Auto-Patch & Gate
Findings
| Severity ▲ | Rule ▲ | File ▲ | Message |
|---|
Reports
Standards Packs
Active Rules
| ID ▲ | Name ▲ | Type ▲ | Severity ▲ |
|---|
Work Items
| ID | Title | State | Rule | Findings | |
|---|---|---|---|---|---|
| Select the Work Items tab to load data. | |||||
Integration
Connection Status
Loading connection status...
Configure Provider
Test connection to load available types
Auth: use OAuth above, or set
AZURE_DEVOPS_PAT env var.Auth: use OAuth above, or set
GITHUB_TOKEN env var.
Story
Bug
Task
Epic
Sub-task
Requirement
Change Request
Auth: use OAuth above, or set
JIRA_USER + JIRA_TOKEN env vars.Agent Action Audit Log
Loading audit log...
Approval Requests
Human-in-the-loop approvals are a first-class governance primitive. Any agent action that exceeds your governance thresholds — gate failures, auto-patches, config changes, new dependencies — creates an approval request here. A security lead can approve (allow the action and record justification in the audit trail) or reject (block it). Agents can also call
sentrik request-approval directly.
Loading approvals...
Agent Identity & Tool Grants
Named agents authenticate with
sk_agent_ credentials scoped to specific operations. JIT (just-in-time) grants give agents temporary elevated access — requested via sentrik request-grant or the request_tool_grant MCP tool — and auto-expire after their TTL. Use sentrik agent-register to provision a new agent credential.
Registered Agents
Loading agents...
Active Tool Grants
Loading grants...
Quality Score
—
Overall Quality
No data yet
Score History
Project Profile
Design Decisions
Developer Expertise
Threat Model
Compliance Attestation
🔒
No attestation generated yet.
Run
sentrik attest to generate a signed compliance attestation.Configuration
🛡
Scanner: Built-in Rules Engine
Your code is analyzed using deterministic pattern matching and AST checks from your enabled standards packs. External scanner integration (SARIF import, AI-powered analysis) is available via the config file.
AI Integration
Configure an LLM to enable "Fix with AI" chat in findings and vulnerability pages. Your API key is stored as an environment variable — it is never written to config files.
Show raw JSON
Scan History
Total Scans
--
Avg Findings
--
Pass Rate
--
Avg Duration
--
| Date | Command | Findings | Critical | High | Compliance | Gate | Duration |
|---|---|---|---|---|---|---|---|
Loading history... | |||||||
Compliance Evidence Map
Shows where your code satisfies compliance requirements — not just violations, but proof of compliance.
| Rule | Clause | Requirement | Status | Evidence |
|---|---|---|---|---|
Loading evidence map... | ||||
License Compliance
All
High 0
Medium 0
Low 0
None 0
| Package | Version | License | Risk | Copyleft |
|---|---|---|---|---|
Click "Scan Licenses" to analyze dependency licenses | ||||