No matching help topics found.
Try a shorter term, or browse the FAQs.
Portal Overview
The Illuminate AI Portal is Sentinel's unified platform for AI-assisted sales, security, and operations intelligence. All features live behind Microsoft Entra ID (Azure AD) single sign-on — no separate passwords required.
Signing In
- Navigate to the portal URL (e.g.
https://illuminate.sentinel.com). - Click Sign-In. You will be redirected to Microsoft's login page.
- Authenticate with your Sentinel corporate account (MFA if required).
- You are redirected back to the portal, which sets a server-side session cookie. This cookie is used for all subsequent API calls — you do not need to sign in again during the session.
Navigation
After sign-in you land on the Sentinel Hub page (Sentinel.html). Use the card grid to navigate to each tool. The sidebar (where present) lets you switch between tool sub-views. Most tools require your Sentinel role to be set in the system — contact your admin if a card is greyed out.
Environment Banners
You are on the development environment. Data may be reset at any time.
You are on the UAT (User Acceptance Testing) environment. Used for validation before production releases.
Sales Dashboard (Customer Intelligence)
The Sales Dashboard is the account manager's home for everything about a customer: revenue, pipeline, support tickets, quality cases, installed-base lifecycle, and account health — plus a portfolio-wide rollup for managers and executives.
Accounts Sidebar
- Accounts are grouped into Active and a collapsible Other section (Dormant + Prospects).
- Parent/child NetSuite account hierarchies are shown together, with child totals rolled up onto the parent row.
- Use the search box or the A–Z jump bar to find an account quickly.
Per-Customer Tabs
Macro-level snapshot only: status chips, Revenue (with YTD/30/60/90-day/12-month windows), Open Pipeline, Open Tickets, Quality Counts, Active Projects, Key Dates, Technology Stack, and Recent Calls.
Opportunities (open pipeline only — closed won/lost are excluded), with Estimated GP shown alongside Revenue and a direct View ↗ link out to the record in NetSuite. Products shows Business Unit saturation — which of the 23 NetSuite business units the customer has purchased vs. remaining whitespace. Recent Invoices lists line items with an Opp/SO reference and a NetSuite View ↗ link.
Tickets are split into three sections: Open Tickets (age-bucketed so stale ones stand out), Security Open Tickets, and Recent Closed Tickets. Click a ticket to expand its full description, notes, SLA status, and assignment group inline — no ServiceNow login required.
Open and total Quality Counts (QC) cases for the account, refreshed every 4 hours in addition to the nightly full sync.
Device inventory with End-of-Life / End-of-Support dates and a search box, so an AM can quickly find refresh candidates.
Health Score, Alerts & Last Contact, Opportunity Signals, Customer Notes, and Meeting Notes — everything that isn't part of the at-a-glance Overview.
Portfolio / Account-Health View
Toggle to the Portfolio view (button above the account list) for a sortable, all-accounts table: health score, revenue, pipeline $ and stage, upside opportunities, open tickets, security incidents, Quality Counts, device count, EOL risk, and next key date (earliest of contract renewal, opportunity close, or project end).
Technology & Services Coverage Heatmap
Click Heatmap to see, per customer, which technology categories and services are covered, gap, or competitor-held — auto-filled from device inventory, managed-services quotes, and NetSuite billing, with manual override where needed.
AM Dashboard
The team-level dashboard (Team View / Executive View, depending on your role) rolls up revenue, pipeline, tickets, and Quality Counts across every account you manage. The Open Tickets, Open Quality Counts, and Needs Attention tiles are clickable — they jump to the detail panel with the underlying list.
Health Score
Each account's 0–100 health score is the sum of four 25-point dimensions: Lifecycle (device EOL/EOS exposure), Support (ticket volume/severity), Engagement (service tier, install footprint, active projects), and Commercial (YoY revenue trend, pipeline, win/loss).
Market & Customer Research
Cross-account industry intelligence: pick an industry (and optionally a service) to see peer adoption data across services, equipment, and contracts, run whitespace campaigns against it, and review company-wide deal-loss analysis.
Peer Data Explorer
Select an industry in the sidebar, then Explore Peer Data to see what services, equipment, and contract types are common among peers in that vertical — useful for identifying what a given account might be missing relative to similar customers.
Campaign Builder
Runs a service-gap analysis by industry and (optionally) service, surfacing accounts that look like good campaign targets based on peer coverage patterns.
Deal Losses
Company-wide view of lost-opportunity reasons over a configurable window (default 12 months), bucketed by cause (pricing, competition, product fit, timing, relationship/execution) — loads independently of the industry filter.
Master Account Rollup
A cross-account rollup table for managers and CompassAI integration users, giving a single-page view across the full account book rather than one customer at a time.
Geographic Analytics
A map view of accounts and pipeline by geography — useful for territory planning and spotting regional concentration or gaps.
Sentinel ChatBot
The Sentinel ChatBot lets you ask questions about your customer data, Sentinel products, Cisco lifecycle information, and internal knowledge — all through natural language. No special query syntax required.
How to Use
- Open ChatBot from the Hub or sidebar.
- Type your question in the chat box and press Enter or click Send.
- The assistant streams the response in real time. Sources cited in the answer are clickable.
- Use the conversation history to ask follow-up questions — the bot retains context within a session.
- Click New Chat to start a fresh conversation (clears context).
Good Questions to Ask
- "Which customers have Cisco ASA devices reaching end of support in the next 90 days?"
- "Summarize open PSIRT advisories for Catalyst 9300 switches."
- "What are our renewal opportunities in the healthcare vertical this quarter?"
- "Draft a customer-facing summary of CVE-2024-XXXXX."
- "What Sentinel services cover network segmentation?"
- "Show me lessons learned from past firewall migration projects."
Scope and Limits
- Installed-base and account data (filtered to your permission level)
- Cisco EoX / PSIRT / lifecycle data
- Sentinel product and service catalog
- Lessons Learned repository
- Internal knowledge-base articles (where indexed)
- Access live internet or external websites
- Modify any records — it is read-only
- Access data outside your assigned accounts (respects RBAC)
- Provide legally binding security advice
How It Searches Data
The ChatBot uses a Retrieval-Augmented Generation (RAG) architecture. Your question is converted to an embedding vector, matched against a pre-built index of your data, and the top relevant chunks are passed to Azure OpenAI alongside your question. The model generates an answer grounded in those chunks — it does not hallucinate data that isn't in the index.
Reports
The Reports module provides pre-built and on-demand reports across accounts, renewals, security posture, and pipeline intelligence.
Available Reports
Per-account risk score, open alerts, upcoming renewals, and EoL device count. Useful for QBR preparation.
All contracts expiring within a configurable window (30 / 60 / 90 days), with contract value and account manager. Export to CSV for CRM import.
Customers affected by active Cisco security advisories, ranked by CVSS score. Includes remediation guidance.
All installed-base devices past or approaching EoX milestones across all customers.
Audit trail of all Azure OpenAI requests made by the platform — visible to admins only. Includes prompt, response, token count, latency, and model version.
Exporting Reports
- Most reports support CSV export for data manipulation in Excel.
- Account Health and PSIRT reports also offer PDF export for customer delivery.
- Use the Date Range filter before exporting to scope the data.
How to Read the Reports
All reports use traffic-light colouring: Red = critical / expired, Yellow = warning / approaching, Green = healthy. Column headers are sortable — click to sort ascending/descending.
SIEM Validator / Security
The SIEM Validator reviews a customer's SIEM configuration, log-source inventory, and detection rules against best-practice benchmarks and known-gap patterns, then generates a prioritised remediation report.
What It Validates
- Log-source coverage (are all critical asset categories sending logs?)
- Detection rule quality (duplicates, disabled rules, low-fidelity alerts)
- Retention policy compliance (minimum 12 months for most frameworks)
- Alert tuning — false-positive suppression lists that may be too broad
- Integration health (data connectors showing as disconnected or delayed)
How to Use
- Select the customer from the account picker.
- Choose the SIEM platform (Microsoft Sentinel, Splunk, QRadar, etc.).
- Upload or paste the configuration export / API credential (read-only).
- Click Run Validation. The analysis typically takes 30–90 seconds.
- Review findings grouped by severity. Expand each finding for AI-generated remediation steps.
- Export as PDF for customer delivery or internal ticket creation.
Understanding Results
Each finding includes a Finding ID, affected component, severity, description, and recommended action. Findings marked Critical should be addressed before any compliance audit. The overall Coverage Score (0–100) reflects log-source completeness relative to the MITRE ATT&CK framework.
CSM Customer Dashboard
A per-customer, presentation-friendly view designed to be screen-shared live during monthly or quarterly business reviews. Larger fonts, fewer widgets per row — built for the CSM to drive while the customer watches, not for dense data entry.
SOC Dashboards
SOC-wide KPIs: open ticket count and MTTR, SLA compliance, PSIRT/alert feed, detection-platform breakdown, severity distribution, and ticket trend over time. Requires the soc or admin role.
SOC CSM Dashboard
A live, per-customer monthly Security Review — modelled on the Fortis/SOC Security Review deck. Includes month-over-month SOC performance metrics, True-Positive/False-Positive classification and charts by security tool, MTTD/MTTI/MTTA timing, a Detection & Coverage lifecycle matrix, and an AI-drafted executive summary. Download the whole thing as a branded PPTX deck for the customer meeting.
Cisco Intelligence / Ticket Status
Cisco Intelligence aggregates Cisco's public lifecycle and security data — End-of-X (EoX) milestones, PSIRT advisories, and software release data — and maps it against each customer's installed base.
EoX Milestones
The last date to order the product from Cisco. After this date the model is no longer sold new, though support continues.
No new bug-fix releases after this date. Security patches may still be issued until EoSS.
No further security patches. Running affected software beyond this date is a compliance and security risk.
TAC no longer accepts cases for this product. This is the hard end-of-life date.
PSIRT Advisories
Cisco PSIRT (Product Security Incident Response Team) publishes security advisories for vulnerabilities in Cisco products. Each advisory is assigned a CVSS score (0–10). The portal colour-codes advisories as:
- Critical CVSS 9.0–10.0 — patch immediately.
- High CVSS 7.0–8.9 — patch within 30 days.
- Medium CVSS 4.0–6.9 — patch within 90 days.
- Low CVSS 0.1–3.9 — patch at next maintenance window.
Interpreting Results
The Affected Customers column shows how many accounts in your portfolio have at least one device running the vulnerable software version. Click a count to see the customer list with their device models and installed versions, helping you prioritise outreach.
Solution Explorer
The Solution Explorer helps you quickly identify which Sentinel products and services best fit a customer's use case, technology stack, or pain point — powered by AI-assisted product matching.
Finding Solutions
- Enter a customer pain point or requirement in the free-text search box (e.g., "zero trust network access for remote workers").
- Optionally select a Technology Category (Networking, Security, Collaboration, etc.) to narrow results.
- Click Search. The AI ranks matching Sentinel offerings by relevance.
- Review the top results. Each card shows the product name, brief description, and fit score.
- Click a card to see full product details, datasheet links, and suggested next steps.
How Product Matching Works
Your query is embedded and compared against a vector index of the Sentinel product catalog (descriptions, use cases, technical specs). The top-K matches are re-ranked by Azure OpenAI using the full product descriptions to ensure semantic accuracy beyond simple keyword matching.
Keeping Results Current
The product catalog is re-indexed automatically when administrators update catalog entries in the admin panel. If a product appears missing, contact your portal admin to verify it is in the catalog.
SOW Generator
The SOW Generator uses Azure OpenAI to draft a Statement of Work document from structured inputs, saving hours of manual writing while ensuring consistency with Sentinel's standard SOW template.
Required Inputs
- Customer name and primary contact
- Project type (e.g., network assessment, SIEM deployment, firewall migration)
- Scope description — free text describing what will be done
- In-scope / Out-of-scope items (you can add bullet points)
- Estimated duration and number of Sentinel resources
- Deliverables list (e.g., as-built documentation, test results, training)
- Assumptions and dependencies
Generating the SOW
- Fill in all required fields on the SOW form.
- Click Generate Draft. Azure OpenAI drafts the document (typically 20–40 seconds).
- Review the generated text in the preview panel. Edit any section inline.
- Click Download DOCX to export the document in Microsoft Word format.
- The DOCX uses Sentinel's branded template with headers, footers, and logo.
Important Notes
Generated SOWs are drafts only. Always have the document reviewed by a practice manager or legal contact before sending to the customer. The AI may include placeholder text in brackets — search for [ before finalising.
Lessons Learned
The Lessons Learned repository captures post-project knowledge from completed Sentinel engagements, sourced from ServiceNow records. Use it to avoid repeating past mistakes and to find proven approaches for similar projects.
ServiceNow Integration
Lessons are automatically pulled from ServiceNow project closure records and enriched with AI-generated tags and summaries. Records sync nightly. The portal displays the structured lesson title, full description, project type, technology area, and contributing engineer.
Searching and Filtering
- Use the keyword search to find lessons by technology, customer type, or issue description.
- Filter by Project Type (e.g., Security, Networking, Collaboration) to scope results.
- Filter by Date Range to find lessons from recent projects.
- Sort by Relevance (AI-ranked) or Date (newest first).
Adding Lessons
New lessons are added through the standard ServiceNow project closure process. If you have a lesson that should be captured outside of a formal project closure, contact your project manager or use the Submit Lesson button (visible to SOC and Manager roles).
Project Plan
The Project Plan tool provides AI-assisted project planning for Sentinel engagements — from generating an initial work-breakdown structure (WBS) to tracking milestone progress.
Creating a Plan
- Click New Project Plan and enter the project name, type, and target completion date.
- Enter a brief scope description. The AI generates a suggested WBS with phases, tasks, and estimated durations.
- Review and edit the generated tasks — add, remove, or re-order as needed.
- Assign tasks to team members and set dependencies.
- Save the plan. It is stored and accessible to all team members with access to the project.
How AI Assists with Planning
Azure OpenAI draws on Sentinel's historical project data (via Lessons Learned and internal templates) to generate realistic task lists, flag common risk areas, and suggest realistic durations based on past similar engagements.
Tracking Progress
- Mark tasks Complete, In Progress, or Blocked.
- The plan header shows overall percent complete and days remaining.
- Blocked tasks generate an automated notification to the project manager.
- Export the plan as an Excel workbook for sharing with customers.
AI & Calculations Explained
All AI features in the Illuminate Portal are powered by Azure OpenAI Service — Microsoft's enterprise deployment of OpenAI models hosted in Sentinel's Azure tenant. No data leaves the tenant boundary.
Azure OpenAI Usage
- GPT-4o — used for complex analysis, SOW generation, and ChatBot responses.
- text-embedding-3-large — used for semantic search / RAG indexing in ChatBot and Solution Explorer.
- GPT-4o-mini — used for fast, cost-efficient tasks such as tag generation and short summaries.
How Prompts Drive Each Feature
A structured prompt supplies account data (devices, contracts, advisories) and asks the model to return a JSON object with a risk score (0–100) and a plain-English rationale. Scores are deterministic — temperature is set to 0.
A system prompt establishes the assistant's role and data scope. Retrieved chunks are injected into the user turn with source citations. The model is instructed to cite sources and decline if no relevant data is found.
A detailed system prompt provides Sentinel's SOW style guide and mandatory sections. User-provided inputs are formatted as a structured template and passed as the user message. Temperature is set to 0.3 for minor creative variation while keeping output professional.
Configuration data is passed to the model with a checklist-style system prompt aligned to NIST and CIS benchmarks. The model returns a structured JSON array of findings, each with ID, severity, description, and remediation.
How Risk Scores Are Calculated
Risk scores are a weighted composite:
- 40% — Security advisory severity (max CVSS across open advisories)
- 25% — EoX proximity (months until LDoS, scaled 0–100)
- 20% — Contract renewal urgency (days until expiry)
- 15% — Support case volume (open P1/P2 cases, last 90 days)
The AI is then asked to review this weighted score and adjust ±10 points based on qualitative context. The final adjusted score is what appears in dashboards.
AI Call Audit Log
Every request to Azure OpenAI is logged in the AI Calls tab (admin only) with: timestamp, feature, model, prompt tokens, completion tokens, latency (ms), and full prompt/response text. This enables cost tracking, quality auditing, and debugging.
Data Privacy
All Azure OpenAI calls are made within Sentinel's Azure subscription. Customer data sent in prompts is subject to Sentinel's data handling policies and Microsoft's enterprise data protection commitments. No data is used to train OpenAI models.
User Roles
Access to features is controlled by Microsoft Entra ID group membership. Each group maps to one internal role, which in turn unlocks specific nav links and API routes. Membership is managed entirely in Entra — request access from IT/your admin rather than the portal itself.
| Feature | admin | manager | sales | csm | soc | broad | ma | epmo | sow |
|---|---|---|---|---|---|---|---|---|---|
| Sales Dashboard / Market Research / Geo Analytics | ✓ | ✓ | ✓ | – | – | ✓ | ✓ | – | – |
| Master Account Rollup | ✓ | ✓ | – | – | – | ✓ | – | – | – |
| CSM Customer Dashboard | ✓ | ✓ | – | ✓ | – | ✓ | – | – | – |
| SOC CSM Dashboard | ✓ | ✓ | – | ✓ | ✓ | ✓ | ✓ | – | – |
| SOC Dashboards | ✓ | ✓ | – | – | ✓ | ✓ | ✓ | – | – |
| Ticket Status (Cisco) / SIEM Validator | ✓ | – | – | – | – | – | ✓ | – | – |
| SOW Generator | ✓ | ✓ | ✓ | – | – | ✓ | – | – | ✓ |
| Project Plan / Lessons Learned | ✓ | ✓ | – | – | – | ✓ | – | ✓ | – |
| Usage Reports | ✓ | ✓ | – | – | – | ✓ | – | – | – |
| Admin Panel / Logs / Cluster Health / AI Call Audit | ✓ | – | – | – | – | – | – | – | – |
Sentinel ChatBot and Solution Explorer are gated separately by the broader "Sentinel - Illuminate All Apps" group rather than by a named role above — most users already have this.
Role Descriptions
Full access to every feature, including admin-only routes. Assigned to the AI team and designated IT admins only.
Directors, VPs, and EVPs with direct-report account managers. Unlocks Team View and Executive View (org-wide rollup) on the Sales Dashboard, plus the SOC nav link.
Account Managers and regional sales staff. Own-accounts view on the Sales Dashboard — cannot see Team View or Executive View.
Customer Success Managers — CSM Customer Dashboard and SOC CSM Dashboard only.
SOC analysts, team leads, and managers. Access to SOC Dashboards, SOC CSM Dashboard, and Cisco/SIEM tooling (server-side "soc or admin" gate).
Broader internal staff — nav visibility across all Illuminate surfaces. Individual routes still enforce their own server-side role check, so nav visibility alone doesn't guarantee data access.
M&A team members. Access to the Sales Dashboard, SOC nav, Geographic Analytics, and Ticket Status/SIEM tooling for diligence work.
Project Management Office. Access to Project Plan and Lessons Learned only.
ScopeStack/SOW integration users. Access to the SOW Generator only.
Requesting a Role Change
Access is granted by adding your account to the relevant Entra group above — contact your IT/portal administrator or raise a request via the standard helpdesk process, referencing "Illuminate Portal — Entra group access," and include your name, email, and business justification.