Sentinel & Steward Loop — Ops Runbook (SCBE Edition)
Purpose
- Gate and verify every envelope with adaptive dwell + explainable risk signals.
- Steward lane handles review; Sentinel automates fast-path.
Daily Checklist
- Review
gcm_failures,nonce_reuse,replay_rejects,aad_mismatch. - p95/p99
envelope_create_msandenvelope_verify_mswithin targets (<10ms / <25ms). - Phase skew p99 < 2000ms across providers.
- Verify canary flags and circuit-breakers (no unintended trips).
- Audit 5 random ALLOW decisions (attest reasonability).
- Export yesterday’s metrics and lock/audit.
Escalations
- Sev2: review queue SLA breach or sustained
review> 10% for 10m. - Sev1: any nonce reuse or GCM auth failure rate > 0.5% for 5m.