Skip to content
Help Center

Sentinel overview

View MarkdownContact support2 min read
On this page

What is Sentinel?

Sentinel collects passive device and network intelligence at important moments in a user’s journey, outside of a Persona verification flow. It gives you additional context for detecting suspicious activity and deciding when a user should complete a higher-assurance verification.

You can deploy Sentinel in:

Sentinel captures risk signals in the background when a user reaches an event you choose, such as signing in, changing payout details, adding a bank account, completing a delivery, or updating account information.

Common Sentinel use cases

  • Account takeover prevention: evaluate a device or network change before allowing a password, email, payout, or account-recovery update.
  • Account-sharing and account-farming detection: identify accounts connected through shared devices, device fingerprints, or network attributes.
  • Re-verification for high-risk actions: introduce an additional check before sensitive actions such as withdrawals, payment-detail changes, marketplace listings, or access to protected content.

Examples of signals captured by Sentinel

  • Network attributes: IP address, connection type (for example, residential), approximate location
  • Device attributes: device token/fingerprint, device model, OS
  • Derived signals: proxy detected, network threat level, velocity (count) of devices seen over a specified time frame

If Sentinel is enabled for your account, you’ll be able to view a full list of supported signals underneath the Transaction signals tab on the Signals glossary page of the Dashboard.

How Sentinel fits into a Persona Workflow

  1. A user initiates a sensitive action in your application, such as changing their email address, password, payout details, or bank account.
  2. Your application triggers Sentinel to collect device and network signals in the background.
  3. Those signals are captured as Transactions in your Dashboard. You can associate the Transaction with the authenticated user by passing your account reference ID.
  4. A Workflow starts when the new Transaction is created. The Workflow evaluates the current signals and can compare them with historical activity, such as whether the account has recently appeared across multiple devices.
  5. Based on your risk rules, the Workflow can automate these actions:
    1. Allow the action to proceed
    2. Create a Case for review
    3. Block or hold the action
    4. Trigger step-up verification, such as a selfie check or a government ID plus selfie verification
Was this page helpful?If something is missing, let us know and we will take a look.
Thanks for the feedback. It helps us improve these docs.