Nobody watches a dashboard at three in the morning. What this district actually buys is three things stacked: an agent judging conduct on the machine, a layer above that pulls the estate into one picture, and a person whose shift it is when the alarm goes. Every post here carries all three.
Signature lists ran out of road years back. The SentinelOne agent works from conduct instead: which process spawned which, what got opened, what got reached for, and whether the whole shape of it resembles encryption, harvesting, or somebody moving carefully sideways. That judgment happens locally, so a laptop with no signal over Nebraska is still protected, and so is the shop machine nobody has rebooted since Easter.
Above the agents sits Fluency. It gathers login records, mail records, network flow, and the logs of tools you already license, then holds them together long enough to mean something. An alarm that arrives at our crew arrives with its surroundings, and surroundings are what turn a notification into a decision.
Grade one triages, then reports the finding and the recommended move. Grade two widens the aperture, so an unusual login out of Ohio and a peculiar process on a laptop in Georgia stop being two unrelated oddities. Grade three acts on its own: it isolates and reverts before anybody is awake, which matters most at two on a Sunday.
Cluster nodes get their own posts. The agent behaves differently on a node, a node is nothing like a desk, and rolling nodes into a desk count would put a small lie on your invoice. Nodes are what you count. Never pods.
Each rate below comes from billing the moment the page opens. Anything under this district drops into your roster while you read on.
Conduct judged on the machine, with a staffed crew standing behind the judgment. People work the findings, and what reaches you already carries a recommendation.
| Runs on | SentinelOne, with Fluency above it |
|---|---|
| Hardware | Windows, macOS and Linux desks and servers |
| You receive | A worked finding with a recommendation attached |
| No signal | The agent keeps deciding without a connection |
| Worked by | The Fortify 24x7 crew, at whatever hour |
| Billed per | Each protected endpoint, monthly |
Grade one with the aperture opened. Identity, mail and network signal join the machine record in one place, rather than sitting in four windows nobody keeps open.
| Runs on | SentinelOne, aperture opened by Fluency |
|---|---|
| Draws from | Machines, identity, mail and network together |
| You receive | A worked finding with a recommendation attached |
| Kept for | Longer, so a case can be reconstructed later |
| Fits | Offices whose work already lives in a cloud tenant |
| Billed per | Each protected endpoint, monthly |
Grade two with hands attached. Cross the line and the box drops off the network, then gets restored, before an analyst has finished reading the case.
| Runs on | SentinelOne, with automatic action enabled |
|---|---|
| Cut off | The box takes itself off the network |
| Put back | Whatever a convicted process altered is put back |
| Checked by | Each automatic action read by a person afterward |
| Fits | Bookkeeping desks, servers, anything near money |
| Billed per | Each protected endpoint, monthly |
Reading for containerized work, billed per node, so the figure matches the number your platform people already keep in their heads.
| Runs on | SentinelOne, built for Kubernetes |
|---|---|
| Draws from | How workloads on that node actually behave |
| You receive | A worked finding with a recommendation attached |
| Worked by | The Fortify 24x7 crew, at whatever hour |
| Billed per | Each cluster node, monthly |
Node reading with the aperture opened, so cluster activity gets read next to identity and machine activity instead of by itself.
| Runs on | SentinelOne for Kubernetes, aperture opened by Fluency |
|---|---|
| Draws from | Node runtime, identity, machines and network |
| You receive | A worked finding with a recommendation attached |
| Kept for | Longer, so a case can be reconstructed later |
| Billed per | Each cluster node, monthly |
The node post with automatic action switched on, for clusters running something that cannot sit misbehaving until Monday.
| Runs on | SentinelOne for Kubernetes, acting on its own |
|---|---|
| Cut off | A workload over the line is acted on without waiting |
| Checked by | Each automatic action read by a person afterward |
| Fits | Clusters carrying work your customers depend on |
| Billed per | Each cluster node, monthly |
Reading conduct is a strong control and a weak guarantee. Below is what these six posts do not reach, so the rest of the ground can be planned around it.
Heads up: card statements show FORTIFY 24X7 - Red White and Blue Networks is a Fortify 24x7 brand, and your subscription is billed by Fortify 24x7.