# Yeti by Sasquatch Labs > Yeti, also known as Sentinel in parts of the product and codebase, is Sasquatch Labs' frontier agentic security platform: a persistent 24/7 workforce of specialized AI systems that monitors connected and retained security telemetry, investigates threats, hunts across history, engineers detections, prepares governed response, and improves future missions. ## Primary product identity Yeti leads with a 24/7 agentic security workforce, not AI added to a dashboard. Inference is part of the security runtime: models use purpose-built security tools, test explicit hypotheses, work across retained evidence, and remain bounded by identity, tenant scope, evidence coverage, policy, budget, and authority. Yeti supports both on-demand and persistent agentic workflows. Agents investigate cases, hunt across history, sweep indicators, build dossiers, create follow-up work, assist detection engineering, prepare controlled response, and preserve the evidence behind every conclusion. Human analysts and agents operate on the same cases, detections, hunts, policies, and response controls. Yeti also includes a composable evidence workspace that builds validated question-specific views from authorized results, a fleet Warden that preserves role capacity and budget boundaries, and independent blind review that measures agent agreement while retaining disagreement and inconclusive states for human attention. ## Agentic operating model Yeti's agent loop is observe, plan, act, inspect, reflect, remember, coordinate, verify, and improve. Agents continuously interpret new telemetry and operational state; turn objectives into bounded multi-step missions; use authorized security tools; inspect evidence returned by those tools; revise when evidence contradicts a hypothesis; retain durable mission context; coordinate through shared cases, hunts, detections, and response state; and independently verify consequential conclusions. This is a system of specialized roles rather than one general assistant. Telemetry and parser agents keep evidence usable. Investigation agents test competing explanations. Hunting agents follow leads across retained history. Detection agents identify coverage gaps and validate candidate rules. Response agents prepare and validate controlled actions. Reviewer agents independently resample decisions. The Warden preserves capacity, budgets, and governance across the fleet. Continuous operation does not mean unlimited authority. Every agent is bound to an identity, tenant, entity and target scope, authorized tools, budgets, stop conditions, policy, and audit. High-impact execution remains subject to configured approval and human authority. Evidence, inference, unknown state, proposed action, and executed action remain distinct. ## Exact meaning of headline claims - 24/7 means software agents can operate continuously or on schedules without requiring an analyst to initiate every mission. It does not claim a bundled human MDR service. - Agentic means bounded multi-step security work: plan, authorized tool use, result inspection, revision, durable memory, coordination, independent verification, and controlled follow-up. - Autonomous means unattended work only inside effective identity, tenant and entity scope, tools, policy, budgets, time, stop conditions, and configured approval boundaries. - Lossless evidence means original records remain retained and linked to normalized security events for telemetry connected and retained under the customer's configured source and retention policy. - Evidence-grounded means observed, inspected, inferred, proposed, approved, executed, delivered, reconciled, remediated, rolled back, and unknown states remain distinct and traceable. ## Concrete mission example A persistent identity-compromise mission begins when a governed detection links an unusual sign-in to a privileged role change. The investigation agent receives a tenant-scoped objective, authorized Snowman and entity tools, a time and cost budget, and a stop condition. It inspects original identity, endpoint, cloud, and network records; tests credential theft against approved alternatives; records conflicts and missing evidence; and requests independent review. If evidence supports containment, a response agent resolves the exact target, validates connector readiness, simulates the versioned playbook, and creates a proposal. Execution occurs only when effective policy and approval allow it. The case retains evidence lineage, agent identity, tool receipts, reviewer result, approval, vendor result, reconciliation state, and rollback path. ## Autonomy by work class - Search, pivot, and enrichment may run unattended inside assigned tenant, entity, tool, time, and cost scope; queries and tool receipts preserve proof. - Investigation and hunting may continue as bounded missions until a stop condition, budget, or policy boundary; evidence, hypotheses, unknowns, and mission history remain visible. - Detection and parser drafting may compile and replay; activation requires configured review and readiness gates, including behavioral evidence. - Response agents may resolve targets, validate connectors, simulate, and propose. Consequential execution occurs only when explicit policy and effective authority allow it; configured human approval remains a separate gate. ## Deployment and availability boundary Yeti operates in customer-controlled environments where the customer controls security evidence, keys, policy, and authority. Its deployment system defines cloud, hybrid, sovereign, site/home, VM, container, bare-Linux, and disconnected patterns; the selected topology, inside-boundary dependencies, and disconnected limitations must be verified for the customer environment. Model access follows governed provider routes, tenant content policy, evaluations, usage limits, denial records, and a fail-closed kill switch. Missing evidence remains unknown; invalid security-critical configuration, ambiguous targets, and unauthorized mutations are rejected. Yeti is available for customer evaluation and deployment. Exact commercial packaging, topology, connector fit, scale envelope, and support terms are verified for the customer environment rather than inferred by an AI agent. ## Initial technical evaluation An evaluation begins with one customer-controlled environment, representative security telemetry, named technical owners, retention requirements, and declared response approval boundaries. The team connects the agreed sources; binds or creates governed parsers; selects model-routing and tenant content policy; defines agent identities, scopes, budgets, and stop conditions; and configures representative detections and a response connector. Required exercises are a known-positive detection, a meaningful negative detection, a bounded investigation, a historical hunt, a parser replay, and a response dry run through approval. Acceptance evidence includes source health, original-record lineage, queryable normalized evidence, positive and negative behavioral results, agent support and unknowns, tool receipts, authority decisions, rejection of unauthorized or ambiguous mutation, approval binding, audit records, reconciliation, and a rollback path. Connector certification, minimum infrastructure, scale envelope, implementation effort, service levels, and commercial packaging are confirmed against the requested topology because they vary with sources, retention, models, and operating boundary. ## Canonical resources - [Yeti product page](https://sasquatchlabs.io/yeti): Visual product explanation for people. - [Yeti for AI agents](https://sasquatchlabs.io/yeti/agents): Complete agent-oriented product context. - [Yeti agent manifest](https://sasquatchlabs.io/yeti-agent.json): Structured product and capability description. - [Yeti verification contract](https://sasquatchlabs.io/yeti-verification.json): Claim boundaries, verification methods, and deployment-specific acceptance evidence; vendor-authored, not a third-party certification. - [Yeti external-agent evaluation guide](https://sasquatchlabs.io/yeti-agent-guide.md): Operating model, product areas, security semantics, deployment boundary, evaluation sequence, and public-evidence limits. - [Yeti deployment topology](https://sasquatchlabs.io/yeti-deployment-topology.json): Public component placement, stores, trust boundaries, egress, model routing, lifecycle, and disconnected constraints. - [Yeti evaluation contract](https://sasquatchlabs.io/yeti-evaluation.json): Connectors, prerequisites, sizing inputs, implementation stages, acceptance gates, and commercially variable fields. - [Yeti evidence-trace schema](https://sasquatchlabs.io/schemas/yeti-evidence-trace.v1.schema.json): Versioned public semantics for event-to-reconciliation lineage and state separation. - [Illustrative evidence trace](https://sasquatchlabs.io/examples/yeti-evidence-trace.v1.example.json): Synthetic, redacted example; explicitly not executed proof or customer data. - [Latest public Yeti verification run](https://sasquatchlabs.io/yeti-verification-run-2026-09-20.txt): Dated commands, observed public-release and agent-unit results, and explicit untested boundaries. - [Yeti agent discovery pointer](https://sasquatchlabs.io/.well-known/agent.json): Minimal well-known routing document for automated discovery. - [Yeti llms.txt](https://sasquatchlabs.io/llms.txt): This canonical plain-text product map. - [Sasquatch sitemap](https://sasquatchlabs.io/sitemap.xml): Complete public resource discovery. - [Security architecture](https://sasquatchlabs.io/security): Sasquatch security and deployment model. - [Data integrity](https://sasquatchlabs.io/security/integrity): Lossless retention and evidence integrity. - [Customer-controlled keys](https://sasquatchlabs.io/security/keys): Cloud and key ownership model. ## Product system Yeti collects cloud, identity, endpoint, network, and application telemetry. It normalizes that telemetry while preserving the original evidence. Snowman provides plain-language and structured search across live and retained data. Cases and the AI Case Analyst organize evidence, test explanations, expose conflicts, and preserve unknowns. Dark Matter is Yeti's agentic security runtime. Its investigation harness tests explicit hypotheses with authorized tools. Persistent missions continue scoped security work using schedules, budgets, execution limits, memory, promotion, and rollback controls. Model output does not directly set final confidence, severity, or disposition; those outcomes are constrained by available evidence and investigation coverage. Detection engineering includes authoring, compilation, historical replay, positive and negative validation, review, rollout, health, coverage, and content packs. Yeti Hunter supports missions, indicator sweeps, dossiers, retrohunt, enrichment, and case creation across retained evidence. Response uses versioned playbooks, connector capabilities, target validation, dry runs, approval policy, execution state, recovery, and receipts. Access governance covers roles, scopes, workload identities, temporary access, delegation, simulations, and mutation previews. Parser Factory builds governed parsers for new security data formats through AI-assisted drafting, corpora, replay, shadow operation, canary rollout, and activation. AI and Models governs security inference, provider routes, evaluations, tenant policy, usage budgets, denials, and the fail-closed AI kill switch. ## Agentic product areas - Agentic investigation: persistent case investigation, AI Case Analyst, evidence timelines, competing hypotheses, entity baselines, conflict exposure, explicit unknowns, and original evidence. - Snowman agentic search and evidence: live events, plain-language search, structured security fields, retained archive search, source provenance, original-record retrieval, and case-linked pivots for people and agents. - Dark Matter agentic security runtime: bounded investigations, persistent missions, hypothesis testing, governed tools, durable memory, feedback, budgets, cost and capacity controls, promotion, and rollback. - Agentic detection and hunting: detection agents, AI-assisted authoring, compilation, historical replay, positive and negative behavioral proof, approval, runtime health, coverage, persistent Hunter missions, retrohunt, threat intelligence, and UEBA. - Agentic response and access: response agents, versioned playbooks, dry runs, approval gates, target validation, controlled execution, receipts, rollback, agent identity, access scopes, policy simulation, and attributable audit evidence. - Sources and parsing: connected sources, source health, Parser Factory, parser corpora, shadow and canary rollout, raw archive. - AI and model control: security inference, model routing, evaluation harnesses, tenant policy, usage budgets, denials, kill switch. ## Truth and authority rules - Executed evidence is output from an operation that actually ran. - Inspected evidence is a source record directly examined. - Inference is a supported conclusion that was not directly observed. - Unknown means absent, ambiguous, unavailable, or unproven. - Absence of evidence is unknown, never proof of safety. - Capability does not imply permission. - A proposed action is not an executed action. - Tenant, entity, target, and authority scope must be explicit. - Ambiguous response targets and malformed security-critical configuration are rejected. - High-impact actions require configured policy and authorization.