Skip to content

Global Master Policies ​

Sentinel V2 applies one policy per account to every API key under that tenant on POST /v2/evaluate.

Configure it in the dashboard: Sentinel V2 Global Master Policies → GET / POST /api/policy/global.

There is no dashboard DSL editor today. Custom rules strings, ASN allow/block lists, and country lists are not shipped. The engine may retain a parser for future use; it is not a live product surface.


Controls (what ships) ​

ControlFieldEffect
Engine modemodeScore thresholds: PASSIVE, BALANCED, STRICT, DRACONIAN, HUMAN_ONLY
VPN / Proxyvpn_actionallow (score only), challenge, or block when VPN is detected
Datacenter IPsdatacenter_actionSame for hosting/cloud ranges
Force BWTforce_bwtChallenge browsers without a trust token before mode math
Exempt server clientsexempt_server_requestsSkips Force BWT only (not VPN/DC or mode)
PoW difficultydifficulty_level1–5 for /v1/challenge/issue when a valid tenant key is present

Evaluation order ​

  1. Private IP → mode math only
  2. Collect signals (token, VPN cache, ASN matrix, velocity, verified bot / scanner)
  3. Verified bot → skip VPN/DC hard blocks and Force BWT; mode still applies
  4. Valid trust token → skip infrastructure hard blocks; mode still applies
  5. VPN / datacenter hard actions
  6. Force BWT (if enabled)
  7. Score + mode thresholds

Modes (thresholds) ​

Signal weights (sum, clamped ±100):

SignalWeight
TOKEN_VALID+30
VERIFIED_BOT+50
RESIDENTIAL_IP+10
VPN_DETECTED−10
DATACENTER_IP−20
HIGH_VELOCITY−30
SCANNER_PATTERN−60
ModeALLOWCHALLENGEelse
PASSIVEscore ≥ −20score ≥ −40BLOCK
BALANCEDscore ≥ 10score ≥ −20BLOCK
STRICTscore ≥ 38score ≥ −10BLOCK
DRACONIANscore ≥ 38score ≥ 25BLOCK
HUMAN_ONLYresidential + token, or VERIFIED_BOTtoken onlyBLOCK (scanner/velocity → BLOCK)

Example policy payload ​

What the dashboard saves today:

json
{
  "mode": "BALANCED",
  "difficulty": 3,
  "vpn_action": "challenge",
  "datacenter_action": "block",
  "force_bwt": true,
  "exempt_server_requests": false
}

Verified bots ​

V2 recognizes known-good crawler User-Agents (Googlebot, Bingbot, Applebot, and similar) and emits VERIFIED_BOT (+50). Those requests are not tagged as SCANNER_PATTERN, and they skip Force BWT / VPN / DC hard blocks. Mode thresholds still apply (HUMAN_ONLY explicitly allows VERIFIED_BOT).


Roadmap (not available yet) ​

  • Custom DSL rule strings in the dashboard
  • Per-tenant ASN / country allow and block lists

Until those ship, do not document them as live features.

Enterprise Zero-Trust Shield.