Cabier Global Assurance · Architecture

    Sentinel

    Adversarial intelligence across eight domains, on one assumption: the adversary may be a person, a machine, a person directing a machine, or a coordinated set of both, and the institution rarely knows which at the moment it matters.

    The unit of detection is a pattern, not an event. The question is not whether one transaction, login or instruction looks suspicious. It is whether thousands of individually plausible events share timing, counterparties, routing, identity relationships and propagation characteristics that the established baseline does not produce.

    Published as reference architecture. Detection logic, baselines and correlation thresholds are set per engagement and are not published.

    Who the adversary might be

    The architecture does not require the answer in advance.

    HumanAIHuman-directed AICoordinated human and AIUnknown

    Eight detection domains

    Seven of them exist in most institutions in some form, owned by different teams and assessed separately. The eighth is the one that changes the outcome.

    Identity

    Synthetic identity, credential reuse, coordinated onboarding, relationship patterns that no legitimate population produces.

    Behavioural

    Timing, sequencing and velocity that are individually plausible and collectively inconsistent with the established baseline.

    Cyber

    Reconnaissance, access, persistence and exfiltration signals correlated across estates rather than assessed in one.

    AI

    Agent action outside its envelope, prompt injection paths, tool misuse, model behaviour drift, generated social engineering.

    Financial

    Routing, liquidity, settlement, collateral, foreign exchange and rejection patterns read as a set.

    Supply chain

    Provider, cloud, API and library dependency change, and concentration around a single intermediary.

    Physical and industrial

    Operational technology adjacency, access events and anomalous instruction sequences.

    Cross-domain

    The layer that matters most. Correlation across the seven above, because coordinated activity rarely stays in one of them.

    What Sentinel does not do

    It does not attribute activity to a named actor, it does not claim to prove that a particular model generated a particular behaviour, and it does not take action. It detects, correlates, explains and escalates to human authority.

    The clearest illustration of cross-domain correlation is the one where every individual signal sits below its own institution's threshold.

    See it applied to financial flows