Sentinel
Enterprise AI Governance
Mission impact
AI adoption stalls when leadership cannot demonstrate control over what AI systems are permitted to do. By converting governance policy into an enforced control plane — least-privilege access for models and agents, human-in-the-loop gates for high-risk actions, and a complete audit trail of every decision — Sentinel allows organizations to expand AI use at the pace of the mission rather than the pace of risk review. Oversight bodies receive evidence instead of assurances, and the enterprise gains the confidence to deploy AI where the stakes are highest.
Sentinel is the Wilkes & Liberty enterprise AI governance and policy-enforcement platform. It gives organizations centralized control over how AI is used across the enterprise — defining, enforcing, and auditing policies for models, data access, tool use, and agent behavior.
Built for regulated and mission-critical environments, Sentinel turns AI governance from a document into an enforced control plane: least-privilege access for AI systems, human-in-the-loop gates for high-risk actions, and a complete audit trail of every decision — enforced at the system of record, never by trusting the client.
Sentinel for Drupal — available today
The first shipping instance of Sentinel governs AI access to Drupal, and it is open source and in production now. Two layers, one outcome: productivity at the edge, authority at the source.
- Drupal MCP Connector — an MIT-licensed bridge that connects any AI assistant, via the open Model Context Protocol, to one or more Drupal sites. "Find every article missing a meta description" becomes a single operation instead of an afternoon of clicking — 66 tools spanning content, taxonomy, users, media, entities, and audit reporting, over both JSON:API and GraphQL, with an optional hardened Drush bridge for admin operations.
- MCP Sentinel — a GPL-licensed Drupal module that governs that access from inside Drupal: it decides what each agent may read, write, or never touch, redacts sensitive fields before content leaves the system, and records every action in a tamper-evident, HMAC-chained audit log. It never trusts a client's word about who it is. The module and the platform share the name by design — MCP Sentinel is Sentinel's enforcement engine inside Drupal.
The governance properties Sentinel enforces: server-authoritative authorization decided from authenticated roles and OAuth scopes; attribution of every AI action to a real, governed account — never anonymous "system" activity; publish authority reserved for accountable humans by role design; data-loss prevention through field-level redaction; and containment — content locks that protect in-progress human edits, rate and quota limits that bound blast radius, and read-only profiles that remove write capability entirely. The connector adds edge guardrails of its own (read-only and PII-redacting presets in one line of config), aligned with the server through a published integration contract rather than tight coupling: the connector proposes, the system of record disposes.
Open by design
Trust tooling should be inspectable. Both components are open source — you can read exactly how authorization is decided, how the audit chain is computed, and where your data can and cannot go: drupal-mcp-connector · drupal.org/project/mcp_sentinel. Built by Jeremy Michael Cerda and Wilkes & Liberty, LLC.
Beyond one CMS
The pattern — server-authoritative policy, scoped agent credentials, tamper-evident audit, human gates on one-way-door actions — is not Drupal-specific. Sentinel is the productization of that pattern for the systems of record regulated organizations actually run. The consulting practice behind it is AI Governance & MCP Integration; the delivery discipline is Agentic AI Development.
Key capabilities
Centralized identity and access management
Centralized identity and access management
Zero-trust security principles
Zero-trust security principles
Role-based access controls and auditing
Role-based access controls and auditing
Secure integration with VPN and mesh networking
Secure integration with VPN and mesh networking