Skip to content

Settings and license

Owners and admins manage organisation-wide settings under Settings. Changes to endpoint and privacy settings publish a new policy version, so devices pick them up at their next check-in.

Settings

PageContents
OrganizationOrganisation name; console session idle and absolute timeouts; require two-factor authentication for all admins
RetentionHow long findings, alerts, audit entries, evidence requests and integration deliveries are kept
Alerting & devicesAlert grouping window; when a device counts as offline; maximum devices per person
PrivacyPseudonymise people for analysts; notify employees about evidence requests; allow employees to pause capture
Endpoint defaultsDevice check-in interval, policy refresh, findings batching, maximum scanned size, maximum reported matches, and the notice shown on managed devices
KeysPolicy signing keys and the evidence key (below)
AdminsInvite, change role, disable, reset password or two-factor authentication
LicenseCurrent license, seats used, license upload
SystemVersion, nodes, job queue, database and migrations

Retention defaults

DataDefault
Findings365 days
Alerts730 days
Audit log7 years
Evidence requests and uploaded sealed evidence30 days
Integration deliveries30 days

A daily job removes expired data. Purging old audit entries keeps the remaining chain verifiable.

Keys

Keys

Policy signing keys sign the policies devices download. Rotate creates a new key that devices learn about in advance; it becomes active after 30 days, so no device loses trust. Rotating again before then replaces the announced key and restarts the 30 days.

The evidence key seals evidence on devices:

ActionWhenEffect
RotatePeriodically, or when people who know the passphrase changeNew key and passphrase for future evidence. Needs the current passphrase, so existing evidence stays openable.
Replace lost keyThe passphrase is lostNew key and passphrase. Evidence sealed to the old key can never be opened again. You must confirm this explicitly.

NOTE

The server's key-encryption key (sentinel.key) is not managed in the console. See Keys and secrets for backups and rotation.

License

Settings → License shows the edition, seats used (active people) and expiry. To install a license, upload the file you received from Lygon Software and confirm with your password (owners only).

StateWhat happens
EvaluationNo license installed: 30 days from the first start, up to 25 people
ActiveLicensed; seat overage shows a banner
GraceThe license has expired; everything keeps working for the grace period (normally 30 days)
ExpiredNew devices can no longer enroll. Existing devices keep syncing and reporting.

Sentinel never switches off protection because of licensing. To renew or add seats, contact enterprise@klipsu.com.

Klipsu Sentinel is a product of Lygon Software · enterprise@klipsu.com