01LOGIC DRIFT
The control loop's decision logic changes over time while outputs remain plausible. The rule is no longer the rule.
SENTINEL is a monitoring intelligence concept for detecting logic drift, abnormal behavior, unauthorized state transitions and emerging risk patterns in critical system control loops.
A future concept for watching behavior, not just signals — so a control loop that quietly changes its logic does not pass unnoticed.
System failure is not only a crash. It is also a control loop that keeps running — with its logic quietly changed.
Monitoring usually watches for the loud failures: a process that dies, an error rate that spikes, a resource that saturates. Those are signal-level failures. But in a critical system, the dangerous deviation is behavioral: a threshold that was silently relaxed, a transition taken outside policy, a rule that no longer matches its own documentation.
The system still returns results. The dashboards still update. The logic, however, has drifted. SENTINEL conceptualizes detection at this level — comparing observed behavior against an established baseline, and treating a quiet deviation as an event, not a coincidence.
SENTINEL is a future concept. It proposes detection surfaces — it does not ship a detector, an agent or an alerting product.
Two illustrative traces of the same control loop. One follows its established pattern. The other is still running — but its behavior no longer matches the baseline.
Five deviation classes a monitoring intelligence concept would need to distinguish. Each is a different failure of behavior, not of process.
The control loop's decision logic changes over time while outputs remain plausible. The rule is no longer the rule.
Observable behavior departs from the established pattern — cadence, amplitude or sequence — without a declared cause.
The system moves between states through a path that policy does not permit, even if the end state is valid.
Behavior that violates a declared boundary — a threshold bypassed, an approval skipped, an envelope exceeded.
The loop's responsiveness or stability decays gradually — slower correction, wider oscillation, growing lag.
Six conceptual stages from observation to escalation. This is a reference model for discussion — not an implemented stack.
Collect state transitions, execution traces and control-loop outputs into an ordered record.
Establish what "normal" means for this specific loop — its pattern, cadence and valid transitions.
Evaluate observed behavior against the baseline, in sequence, not in aggregate.
Link individual deviations into patterns: does this drift recur, spread, or align with policy changes?
Surface a deviation as a reviewable event with confidence, provenance and affected transitions.
Route to a human operator with the evidence required to decide. Detection ends where decision begins.
The unit of control is the transition between system states. SENTINEL conceptualizes three ways to act on it — always visible, never silent.
Every transition is checked against the set of permitted paths for the current policy. A valid transition in an invalid order is still flagged.
A detected deviation becomes a reviewable event with confidence and provenance — a record a human can inspect, not a buried log line.
An unauthorized state transition is refused at the boundary and held for review. The system does not repair itself; it stops, and reports.
A detector that cannot state its own uncertainty is just a louder alarm.
SENTINEL's value depends on honest degradation: confidence must decay as baselines age, as coverage shrinks, or as the system under observation changes faster than the baseline can be re-established.
A monitoring intelligence concept that reports its own confidence is a decision support surface. One that does not is a liability — it trains operators to ignore it.
PROPOSED: CONFIDENCE IS PART OF EVERY EVENT — never a separate "health score".
A weak or aging baseline weakens every comparison. Detection confidence must track baseline confidence.
If "normal" shifts slowly, deviations stop looking like deviations. SENTINEL must detect drift in its own baseline.
When observation stops seeing part of the loop, the gap is reported as reduced confidence — not as continued normalcy.
Directions SENTINEL could explore next — each stated as a question, not a roadmap.
How to detect that "normal" itself has moved — without mistaking a legitimate change for a deviation.
Linking separate deviations into a single emerging pattern, rather than treating each signal in isolation.
Calibrated confidence that operators can rely on — including explicit statements of when detection is unsure.
Characteristic patterns of a loop losing responsiveness, before any single threshold is violated.
How much transition history a reviewable record requires — and how it survives restarts and disputes.
Which flags reach humans, in what form, and how review outcomes re-tune the detector.
An illustrative replay of a deviation sequence inside a critical control loop. Play it, step through it, or click an event to inspect it. Everything here is simulated — no live telemetry is involved.
Illustrative replay of a deviation sequence. All timestamps, event identifiers and confidence values are simulated for demonstration — this is not a live monitoring system and reflects no real system.
SENTINEL is a future concept. It is a concept for monitoring intelligence — not a released product, not a deployed system, not a benchmarked implementation. This page documents the concept and its proposed shape.
Critical systems require deterministic boundaries before intelligence scales. SENTINEL is a research surface for detecting when a system crosses its own boundaries — quietly, while still appearing to work.