# Sentinel (/sentinel)



## What Sentinel does [#what-sentinel-does]

A project's shared foundation keeps moving after launch: package managers change, and code copied into each project becomes published Ciridae packages. Porting every change by hand turns into maintenance debt. Sentinel applies Ciridae-authored updates to your repository and opens them as draft PRs your team reviews and merges.

Current updates move projects from Yarn to pnpm, replace duplicated auth, telemetry, OpenAPI tooling, Temporal Sentry, and Ghost client code with their published Ciridae packages, and adopt direct object storage access.

Sentinel never marks a PR ready or merges it. Your team decides when each change ships.

## How an update reaches your project [#how-an-update-reaches-your-project]

```mermaid
flowchart TD
  E[Eligible project] --> Q{Update applies?}
  Q -->|pattern absent| X[Stop without a branch]
  Q -->|yes| P[Agent opens a draft PR]
  P --> C[Correction, up to three rounds]
  C --> R[Team review and merge]
```

1. **Eligibility**: Sentinel considers projects that enable it in `project.yaml` and have a live full deployment.
2. **Qualification**: Sentinel reads the trunk branch and decides whether the update applies. If the pattern it replaces is absent, the run stops without creating a branch.
3. **Change**: An agent in a temporary workspace makes the change, runs the project's checks, and opens a draft PR. Some updates open an ordered stack of draft PRs, and each PR body states the merge and deployment order.
4. **Correction**: The agent works through CI failures and high-priority review findings, for up to three rounds.
5. **Review**: Your team reviews the draft, marks it ready, and merges it.

<Accordions>
  <Accordion title="Under the hood: update runs">
    Each update is a versioned Markdown file with a qualification prompt and execution and verification instructions. A project admin starts a run through the Crucible API; it runs as one Temporal workflow per project and update revision. Qualification uses read-only tools to list, search, and read tracked files, and classifies the repository as `active`, `dead`, `absent`, or `unknown`. Every result except `absent` creates a stable update branch, an expiring workspace, and a one-shot Codex session. A retry runs a fresh qualification; nothing is cached.
  </Accordion>
</Accordions>

## Turn Sentinel off [#turn-sentinel-off]

Projects created from the Agents template have Sentinel on. To opt out, override the setting in the project's `project.yaml` on the trunk branch:

```yaml title="project.yaml"
updates:
  sentinel:
    enabled: false
```
