SentinelFlow Security Layer
Enterprise-Grade Credential Management for All Flow Products
Your automation is only as secure as your credentials.
SentinelFlow ensures every FoliosFlow, ServiceFlow and FlowBridge execution uses vault-secured authentication, with zero cloud exposure and complete audit trails.
- ✓ CyberArk, 1Password or Windows Credential Manager
- ✓ Local execution only (no SaaS, no cloud persistence)
- ✓ OAuth token lifecycle management
- ✓ Complete audit logs for compliance
Why Credential Security Matters for Automation
Enterprise automation needs privileged access to systems such as Planview and ServiceNow. Without a security layer, those automations create new risks.
❌ Hard-coded credentials
Problem: Passwords stored in scripts or configuration files.
Impact: Security audit failures and breach risk if files leak.
❌ Cloud-based vaults
Problem: Sensitive credentials sent to third-party SaaS platforms.
Impact: Data sovereignty concerns and compliance headaches.
❌ No audit trail
Problem: No reliable record of who accessed what, and when.
Impact: Difficult investigations and regulatory non-compliance.
❌ Token sprawl
Problem: OAuth tokens stored insecurely or never rotated.
Impact: Long-lived, “zombie” access with no clear owner.
SentinelFlow removes all four risks with a vault-native, local-execution architecture.
How SentinelFlow Secures Your Automation
Every Flow product run follows the same secure pattern: retrieve from your vault, authenticate locally, execute, log, and clean up tokens.
🔐 Step 1: Vault retrieval
Credentials stay in your vault.
SentinelFlow retrieves credentials from:
- CyberArk Application Access Manager (AAM)
- 1Password CLI
- Windows Credential Manager
- Azure Key Vault (coming soon)
Credentials are never stored in Flow configuration files or logs.
🏠 Step 2: Local authentication
OAuth tokens, API keys or username/password pairs are used to authenticate directly from your infrastructure to the target systems.
There is no cloud proxy, no third-party middleman, and no data exfiltration risk.
✅ Step 3: Execution and logging
Every credential retrieval and API call is logged with:
- Timestamp
- User or service account
- Target system and endpoint
- Success / failure status
- Optional email alerts
Ideal for SOC 2, ISO 27001 and internal audit evidence.
🗑️ Step 4: Token lifecycle
OAuth tokens are refreshed automatically and expired tokens are purged. No stale credentials lingering in memory or on disk.
Works with Your Existing Vault
SentinelFlow integrates with enterprise-grade credential management systems, so security teams can keep using the vaults they already trust.
CyberArk AAM
Application Access Manager integration with support for Central Credential Provider and credential rotation.
Best for enterprises with existing CyberArk deployments.
View CyberArk setup guide1Password Business
Uses the 1Password CLI for secret access by vault or item ID, with team-managed policies.
Ideal for teams already standardised on 1Password.
View 1Password setup guideWindows Credential Manager
Uses built-in Windows encryption with no additional licensing or external services.
Well suited to sandbox, test or single-server environments.
View WCM setup guideAzure Key Vault (coming soon)
Microsoft Azure–native credential store with managed identities and RBAC.
Available: Q2 2026.
SentinelFlow Security Architecture
Every Flow execution follows a repeatable, governed pattern: vault retrieval, SentinelFlow mediation, SmartSync execution and direct calls to target systems.
Suggested diagram layout:
• FoliosFlow / ServiceFlow / FlowBridge inside "Your Infrastructure"
• Flows → SentinelFlow → CyberArk / 1Password / WCM vault
• SentinelFlow issues OAuth tokens → calls Planview / ServiceNow / other target apps
• Side panel showing "Audit Log" capturing each step
- Credentials never leave your vault.
- No cloud proxy or third-party access to secrets.
- Direct authentication from your infrastructure to target systems.
- Complete audit trail at every step of the run.
Why Security Teams Choose SentinelFlow
SentinelFlow turns Flow products into security-approved automation, aligned with Zero Trust and modern governance requirements.
🔐 Vault-native architecture
Integrates with CyberArk, 1Password or Windows Credential Manager – no proprietary sentinel vault to manage.
🏠 Local execution only
Runs inside your infrastructure, with no cloud SaaS and no persistence of customer data outside your network.
✅ Complete audit trail
Every credential access and API call is logged – timestamp, identity, system and status – ready for compliance reviews.
🔄 OAuth lifecycle management
Automated token refresh, expiry handling and cleanup – no stale credentials or manual rotation scripts.
🌍 Export-compliant design
EAR99 classification – suitable for international deployments without complex export licensing in most cases.
🔒 Zero Trust compatible
Designed to work with Zero Trust network architectures, enforcing least-privilege access on every flow.
Built for Regulated Organisations
SentinelFlow provides the evidence and control needed for security-sensitive, regulated environments.
SOC 2 Type II ready
- Detailed event logging of access and execution.
- Documented controls for credential access.
- Change tracking for flows and policies.
ISO 27001 alignment
- A.9.4.1 – Information access restriction.
- A.9.4.2 – Secure log-on procedures.
- A.12.4.1 – Event logging and monitoring.
GDPR & NIST support
- Article 32 encryption and logging support.
- NIST CSF: PR.AC-1, PR.AC-4, DE.AE-3 alignment.
- Evidence trail for breach detection processes.
SentinelFlow does not replace your certification process, but gives your security and compliance teams the logging and control they need for audits.
Common SentinelFlow Deployment Scenarios
SentinelFlow underpins secure automation across financial services, healthcare, energy and government contractors.
Financial services
Scenario: Bank automates Planview user provisioning from HR.
Challenge: PCI-DSS requires vault-secured credentials and no cloud storage.
Solution: SentinelFlow + CyberArk AAM + FoliosFlow.
Result: Zero audit findings and 100% credential security.
Healthcare
Scenario: Hospital automates ServiceNow ITSM workflows.
Challenge: HIPAA requires encryption and full audit trail for access.
Solution: SentinelFlow + 1Password + ServiceFlow.
Result: Detailed logs and credentials never exposed in plaintext.
Energy and utilities
Scenario: Utility automates governance across multiple systems.
Challenge: NERC CIP standards require strict privileged access management.
Solution: SentinelFlow + CyberArk + FlowBridge.
Result: Centralised credential management across three systems.
Government contractor
Scenario: Defence contractor automates Planview reporting.
Challenge: ITAR/EAR export controls and FedRAMP alignment.
Solution: SentinelFlow (EAR99) with on-prem execution.
Result: Approved for use in controlled environments.
See SentinelFlow in Action
Demonstrate how SentinelFlow protects a FoliosFlow or ServiceFlow execution with CyberArk, 1Password or Windows Credential Manager.
Suggested walkthrough:
1) Credential stored in CyberArk / 1Password / WCM
2) Flow configuration references vault path, not plaintext password
3) SentinelFlow retrieves credential at runtime
4) OAuth token obtained and used
5) API call to Planview / ServiceNow
6) Audit log entry generated
7) Token cleaned up
SentinelFlow Pricing
SentinelFlow is available across Dynamic Data Flows product tiers, with options for advanced vault integrations and SIEM support.
Foundation – from £10,000/year
Core SentinelFlow capabilities for a single environment.
- Windows Credential Manager support.
- Basic audit logging and email alerts.
- Ideal for initial deployments or non-production estates.
Professional – from £17,500/year
Multi-environment coverage with richer logging and integrations.
- Multiple environments (for example sandbox, test and production).
- 1Password CLI integration.
- Enhanced logging with report-ready exports.
- Priority support for security teams.
Enterprise – from £35,000/year
Designed for complex estates and high-assurance environments.
- CyberArk AAM / CCP integration and support.
- Custom vault integrations where required.
- Architectural advisory for security and governance.
“We could not automate Planview without SentinelFlow. Our security team required CyberArk integration and complete audit trails – SentinelFlow delivered both from day one.”
— CISO, Direct Line Group
Ready to Secure Your Automation?
SentinelFlow is the security foundation for every Dynamic Data Flows product. Start with a focused pilot or roll it out alongside FoliosFlow and ServiceFlow.
Security questions? Email security@dynamicdataflows.com