← Back to Portal

No matching help topics found.

Try a shorter term, or browse the FAQs.

🏠

Portal Overview

The Illuminate AI Portal is Sentinel's unified platform for AI-assisted sales, security, and operations intelligence. All features live behind Microsoft Entra ID (Azure AD) single sign-on — no separate passwords required.

Signing In

  1. Navigate to the portal URL (e.g. https://illuminate.sentinel.com).
  2. Click Sign-In. You will be redirected to Microsoft's login page.
  3. Authenticate with your Sentinel corporate account (MFA if required).
  4. You are redirected back to the portal, which sets a server-side session cookie. This cookie is used for all subsequent API calls — you do not need to sign in again during the session.

Navigation

After sign-in you land on the Sentinel Hub page (Sentinel.html). Use the card grid to navigate to each tool. The sidebar (where present) lets you switch between tool sub-views. Most tools require your Sentinel role to be set in the system — contact your admin if a card is greyed out.

Environment Banners

DEV Orange banner

You are on the development environment. Data may be reset at any time.

UAT Red banner

You are on the UAT (User Acceptance Testing) environment. Used for validation before production releases.

📡

Sales Dashboard (Customer Intelligence)

↗ Open Sales Dashboard

The Sales Dashboard is the account manager's home for everything about a customer: revenue, pipeline, support tickets, quality cases, installed-base lifecycle, and account health — plus a portfolio-wide rollup for managers and executives.

Accounts Sidebar

  • Accounts are grouped into Active and a collapsible Other section (Dormant + Prospects).
  • Parent/child NetSuite account hierarchies are shown together, with child totals rolled up onto the parent row.
  • Use the search box or the A–Z jump bar to find an account quickly.

Per-Customer Tabs

Overview

Macro-level snapshot only: status chips, Revenue (with YTD/30/60/90-day/12-month windows), Open Pipeline, Open Tickets, Quality Counts, Active Projects, Key Dates, Technology Stack, and Recent Calls.

Business

Opportunities (open pipeline only — closed won/lost are excluded), with Estimated GP shown alongside Revenue and a direct View ↗ link out to the record in NetSuite. Products shows Business Unit saturation — which of the 23 NetSuite business units the customer has purchased vs. remaining whitespace. Recent Invoices lists line items with an Opp/SO reference and a NetSuite View ↗ link.

Support

Tickets are split into three sections: Open Tickets (age-bucketed so stale ones stand out), Security Open Tickets, and Recent Closed Tickets. Click a ticket to expand its full description, notes, SLA status, and assignment group inline — no ServiceNow login required.

Quality Counts

Open and total Quality Counts (QC) cases for the account, refreshed every 4 hours in addition to the nightly full sync.

Environment

Device inventory with End-of-Life / End-of-Support dates and a search box, so an AM can quickly find refresh candidates.

Detail

Health Score, Alerts & Last Contact, Opportunity Signals, Customer Notes, and Meeting Notes — everything that isn't part of the at-a-glance Overview.

Portfolio / Account-Health View

Toggle to the Portfolio view (button above the account list) for a sortable, all-accounts table: health score, revenue, pipeline $ and stage, upside opportunities, open tickets, security incidents, Quality Counts, device count, EOL risk, and next key date (earliest of contract renewal, opportunity close, or project end).

Technology & Services Coverage Heatmap

Click Heatmap to see, per customer, which technology categories and services are covered, gap, or competitor-held — auto-filled from device inventory, managed-services quotes, and NetSuite billing, with manual override where needed.

AM Dashboard

The team-level dashboard (Team View / Executive View, depending on your role) rolls up revenue, pipeline, tickets, and Quality Counts across every account you manage. The Open Tickets, Open Quality Counts, and Needs Attention tiles are clickable — they jump to the detail panel with the underlying list.

Health Score

Each account's 0–100 health score is the sum of four 25-point dimensions: Lifecycle (device EOL/EOS exposure), Support (ticket volume/severity), Engagement (service tier, install footprint, active projects), and Commercial (YoY revenue trend, pipeline, win/loss).

📊

Market & Customer Research

↗ Open Market Research

Cross-account industry intelligence: pick an industry (and optionally a service) to see peer adoption data across services, equipment, and contracts, run whitespace campaigns against it, and review company-wide deal-loss analysis.

Peer Data Explorer

Select an industry in the sidebar, then Explore Peer Data to see what services, equipment, and contract types are common among peers in that vertical — useful for identifying what a given account might be missing relative to similar customers.

Campaign Builder

Runs a service-gap analysis by industry and (optionally) service, surfacing accounts that look like good campaign targets based on peer coverage patterns.

Deal Losses

Company-wide view of lost-opportunity reasons over a configurable window (default 12 months), bucketed by cause (pricing, competition, product fit, timing, relationship/execution) — loads independently of the industry filter.

🗂️

Master Account Rollup

↗ Open Master Rollup

A cross-account rollup table for managers and CompassAI integration users, giving a single-page view across the full account book rather than one customer at a time.

🗺️

Geographic Analytics

↗ Open Geographic Analytics

A map view of accounts and pipeline by geography — useful for territory planning and spotting regional concentration or gaps.

💬

Sentinel ChatBot

↗ Open Sentinel ChatBot

The Sentinel ChatBot lets you ask questions about your customer data, Sentinel products, Cisco lifecycle information, and internal knowledge — all through natural language. No special query syntax required.

How to Use

  1. Open ChatBot from the Hub or sidebar.
  2. Type your question in the chat box and press Enter or click Send.
  3. The assistant streams the response in real time. Sources cited in the answer are clickable.
  4. Use the conversation history to ask follow-up questions — the bot retains context within a session.
  5. Click New Chat to start a fresh conversation (clears context).

Good Questions to Ask

  • "Which customers have Cisco ASA devices reaching end of support in the next 90 days?"
  • "Summarize open PSIRT advisories for Catalyst 9300 switches."
  • "What are our renewal opportunities in the healthcare vertical this quarter?"
  • "Draft a customer-facing summary of CVE-2024-XXXXX."
  • "What Sentinel services cover network segmentation?"
  • "Show me lessons learned from past firewall migration projects."

Scope and Limits

What the ChatBot can access
  • Installed-base and account data (filtered to your permission level)
  • Cisco EoX / PSIRT / lifecycle data
  • Sentinel product and service catalog
  • Lessons Learned repository
  • Internal knowledge-base articles (where indexed)
What the ChatBot cannot do
  • Access live internet or external websites
  • Modify any records — it is read-only
  • Access data outside your assigned accounts (respects RBAC)
  • Provide legally binding security advice

How It Searches Data

The ChatBot uses a Retrieval-Augmented Generation (RAG) architecture. Your question is converted to an embedding vector, matched against a pre-built index of your data, and the top relevant chunks are passed to Azure OpenAI alongside your question. The model generates an answer grounded in those chunks — it does not hallucinate data that isn't in the index.

📊

Reports

↗ Open Reports

The Reports module provides pre-built and on-demand reports across accounts, renewals, security posture, and pipeline intelligence.

Available Reports

Account Health Summary

Per-account risk score, open alerts, upcoming renewals, and EoL device count. Useful for QBR preparation.

Renewal Pipeline

All contracts expiring within a configurable window (30 / 60 / 90 days), with contract value and account manager. Export to CSV for CRM import.

PSIRT Exposure Report

Customers affected by active Cisco security advisories, ranked by CVSS score. Includes remediation guidance.

End-of-Life Device Report

All installed-base devices past or approaching EoX milestones across all customers.

AI Activity Log

Audit trail of all Azure OpenAI requests made by the platform — visible to admins only. Includes prompt, response, token count, latency, and model version.

Exporting Reports

  • Most reports support CSV export for data manipulation in Excel.
  • Account Health and PSIRT reports also offer PDF export for customer delivery.
  • Use the Date Range filter before exporting to scope the data.

How to Read the Reports

All reports use traffic-light colouring: Red = critical / expired, Yellow = warning / approaching, Green = healthy. Column headers are sortable — click to sort ascending/descending.

🛡️

SIEM Validator / Security

↗ Open SIEM Validator

The SIEM Validator reviews a customer's SIEM configuration, log-source inventory, and detection rules against best-practice benchmarks and known-gap patterns, then generates a prioritised remediation report.

What It Validates

  • Log-source coverage (are all critical asset categories sending logs?)
  • Detection rule quality (duplicates, disabled rules, low-fidelity alerts)
  • Retention policy compliance (minimum 12 months for most frameworks)
  • Alert tuning — false-positive suppression lists that may be too broad
  • Integration health (data connectors showing as disconnected or delayed)

How to Use

  1. Select the customer from the account picker.
  2. Choose the SIEM platform (Microsoft Sentinel, Splunk, QRadar, etc.).
  3. Upload or paste the configuration export / API credential (read-only).
  4. Click Run Validation. The analysis typically takes 30–90 seconds.
  5. Review findings grouped by severity. Expand each finding for AI-generated remediation steps.
  6. Export as PDF for customer delivery or internal ticket creation.

Understanding Results

Each finding includes a Finding ID, affected component, severity, description, and recommended action. Findings marked Critical should be addressed before any compliance audit. The overall Coverage Score (0–100) reflects log-source completeness relative to the MITRE ATT&CK framework.

🤝

CSM Customer Dashboard

↗ Open CSM Dashboard

A per-customer, presentation-friendly view designed to be screen-shared live during monthly or quarterly business reviews. Larger fonts, fewer widgets per row — built for the CSM to drive while the customer watches, not for dense data entry.

🛰️

SOC Dashboards

↗ Open SOC Dashboards

SOC-wide KPIs: open ticket count and MTTR, SLA compliance, PSIRT/alert feed, detection-platform breakdown, severity distribution, and ticket trend over time. Requires the soc or admin role.

📈

SOC CSM Dashboard

↗ Open SOC CSM Dashboard

A live, per-customer monthly Security Review — modelled on the Fortis/SOC Security Review deck. Includes month-over-month SOC performance metrics, True-Positive/False-Positive classification and charts by security tool, MTTD/MTTI/MTTA timing, a Detection & Coverage lifecycle matrix, and an AI-drafted executive summary. Download the whole thing as a branded PPTX deck for the customer meeting.

🔌

Cisco Intelligence / Ticket Status

↗ Open Ticket Status

Cisco Intelligence aggregates Cisco's public lifecycle and security data — End-of-X (EoX) milestones, PSIRT advisories, and software release data — and maps it against each customer's installed base.

EoX Milestones

End of Sale (EoS)

The last date to order the product from Cisco. After this date the model is no longer sold new, though support continues.

End of Software Maintenance (EoSM)

No new bug-fix releases after this date. Security patches may still be issued until EoSS.

End of Security / Vulnerability Support (EoSS)

No further security patches. Running affected software beyond this date is a compliance and security risk.

Last Day of Support (LDoS)

TAC no longer accepts cases for this product. This is the hard end-of-life date.

PSIRT Advisories

Cisco PSIRT (Product Security Incident Response Team) publishes security advisories for vulnerabilities in Cisco products. Each advisory is assigned a CVSS score (0–10). The portal colour-codes advisories as:

  • Critical CVSS 9.0–10.0 — patch immediately.
  • High CVSS 7.0–8.9 — patch within 30 days.
  • Medium CVSS 4.0–6.9 — patch within 90 days.
  • Low CVSS 0.1–3.9 — patch at next maintenance window.

Interpreting Results

The Affected Customers column shows how many accounts in your portfolio have at least one device running the vulnerable software version. Click a count to see the customer list with their device models and installed versions, helping you prioritise outreach.

🔍

Solution Explorer

↗ Open Solution Explorer

The Solution Explorer helps you quickly identify which Sentinel products and services best fit a customer's use case, technology stack, or pain point — powered by AI-assisted product matching.

Finding Solutions

  1. Enter a customer pain point or requirement in the free-text search box (e.g., "zero trust network access for remote workers").
  2. Optionally select a Technology Category (Networking, Security, Collaboration, etc.) to narrow results.
  3. Click Search. The AI ranks matching Sentinel offerings by relevance.
  4. Review the top results. Each card shows the product name, brief description, and fit score.
  5. Click a card to see full product details, datasheet links, and suggested next steps.

How Product Matching Works

Your query is embedded and compared against a vector index of the Sentinel product catalog (descriptions, use cases, technical specs). The top-K matches are re-ranked by Azure OpenAI using the full product descriptions to ensure semantic accuracy beyond simple keyword matching.

Keeping Results Current

The product catalog is re-indexed automatically when administrators update catalog entries in the admin panel. If a product appears missing, contact your portal admin to verify it is in the catalog.

📄

SOW Generator

↗ Open SOW Generator

The SOW Generator uses Azure OpenAI to draft a Statement of Work document from structured inputs, saving hours of manual writing while ensuring consistency with Sentinel's standard SOW template.

Required Inputs

  • Customer name and primary contact
  • Project type (e.g., network assessment, SIEM deployment, firewall migration)
  • Scope description — free text describing what will be done
  • In-scope / Out-of-scope items (you can add bullet points)
  • Estimated duration and number of Sentinel resources
  • Deliverables list (e.g., as-built documentation, test results, training)
  • Assumptions and dependencies

Generating the SOW

  1. Fill in all required fields on the SOW form.
  2. Click Generate Draft. Azure OpenAI drafts the document (typically 20–40 seconds).
  3. Review the generated text in the preview panel. Edit any section inline.
  4. Click Download DOCX to export the document in Microsoft Word format.
  5. The DOCX uses Sentinel's branded template with headers, footers, and logo.

Important Notes

Generated SOWs are drafts only. Always have the document reviewed by a practice manager or legal contact before sending to the customer. The AI may include placeholder text in brackets — search for [ before finalising.

📚

Lessons Learned

↗ Open Lessons Learned

The Lessons Learned repository captures post-project knowledge from completed Sentinel engagements, sourced from ServiceNow records. Use it to avoid repeating past mistakes and to find proven approaches for similar projects.

ServiceNow Integration

Lessons are automatically pulled from ServiceNow project closure records and enriched with AI-generated tags and summaries. Records sync nightly. The portal displays the structured lesson title, full description, project type, technology area, and contributing engineer.

Searching and Filtering

  1. Use the keyword search to find lessons by technology, customer type, or issue description.
  2. Filter by Project Type (e.g., Security, Networking, Collaboration) to scope results.
  3. Filter by Date Range to find lessons from recent projects.
  4. Sort by Relevance (AI-ranked) or Date (newest first).

Adding Lessons

New lessons are added through the standard ServiceNow project closure process. If you have a lesson that should be captured outside of a formal project closure, contact your project manager or use the Submit Lesson button (visible to SOC and Manager roles).

📋

Project Plan

↗ Open Project Plan

The Project Plan tool provides AI-assisted project planning for Sentinel engagements — from generating an initial work-breakdown structure (WBS) to tracking milestone progress.

Creating a Plan

  1. Click New Project Plan and enter the project name, type, and target completion date.
  2. Enter a brief scope description. The AI generates a suggested WBS with phases, tasks, and estimated durations.
  3. Review and edit the generated tasks — add, remove, or re-order as needed.
  4. Assign tasks to team members and set dependencies.
  5. Save the plan. It is stored and accessible to all team members with access to the project.

How AI Assists with Planning

Azure OpenAI draws on Sentinel's historical project data (via Lessons Learned and internal templates) to generate realistic task lists, flag common risk areas, and suggest realistic durations based on past similar engagements.

Tracking Progress

  • Mark tasks Complete, In Progress, or Blocked.
  • The plan header shows overall percent complete and days remaining.
  • Blocked tasks generate an automated notification to the project manager.
  • Export the plan as an Excel workbook for sharing with customers.
🤖

AI & Calculations Explained

All AI features in the Illuminate Portal are powered by Azure OpenAI Service — Microsoft's enterprise deployment of OpenAI models hosted in Sentinel's Azure tenant. No data leaves the tenant boundary.

Azure OpenAI Usage

Models in Use
  • GPT-4o — used for complex analysis, SOW generation, and ChatBot responses.
  • text-embedding-3-large — used for semantic search / RAG indexing in ChatBot and Solution Explorer.
  • GPT-4o-mini — used for fast, cost-efficient tasks such as tag generation and short summaries.

How Prompts Drive Each Feature

Customer Intelligence Scoring

A structured prompt supplies account data (devices, contracts, advisories) and asks the model to return a JSON object with a risk score (0–100) and a plain-English rationale. Scores are deterministic — temperature is set to 0.

ChatBot

A system prompt establishes the assistant's role and data scope. Retrieved chunks are injected into the user turn with source citations. The model is instructed to cite sources and decline if no relevant data is found.

SOW Generator

A detailed system prompt provides Sentinel's SOW style guide and mandatory sections. User-provided inputs are formatted as a structured template and passed as the user message. Temperature is set to 0.3 for minor creative variation while keeping output professional.

SIEM Validator

Configuration data is passed to the model with a checklist-style system prompt aligned to NIST and CIS benchmarks. The model returns a structured JSON array of findings, each with ID, severity, description, and remediation.

How Risk Scores Are Calculated

Risk scores are a weighted composite:

  • 40% — Security advisory severity (max CVSS across open advisories)
  • 25% — EoX proximity (months until LDoS, scaled 0–100)
  • 20% — Contract renewal urgency (days until expiry)
  • 15% — Support case volume (open P1/P2 cases, last 90 days)

The AI is then asked to review this weighted score and adjust ±10 points based on qualitative context. The final adjusted score is what appears in dashboards.

AI Call Audit Log

Every request to Azure OpenAI is logged in the AI Calls tab (admin only) with: timestamp, feature, model, prompt tokens, completion tokens, latency (ms), and full prompt/response text. This enables cost tracking, quality auditing, and debugging.

Data Privacy

All Azure OpenAI calls are made within Sentinel's Azure subscription. Customer data sent in prompts is subject to Sentinel's data handling policies and Microsoft's enterprise data protection commitments. No data is used to train OpenAI models.

👤

User Roles

Access to features is controlled by Microsoft Entra ID group membership. Each group maps to one internal role, which in turn unlocks specific nav links and API routes. Membership is managed entirely in Entra — request access from IT/your admin rather than the portal itself.

Feature admin manager sales csm soc broad ma epmo sow
Sales Dashboard / Market Research / Geo Analytics
Master Account Rollup
CSM Customer Dashboard
SOC CSM Dashboard
SOC Dashboards
Ticket Status (Cisco) / SIEM Validator
SOW Generator
Project Plan / Lessons Learned
Usage Reports
Admin Panel / Logs / Cluster Health / AI Call Audit

Sentinel ChatBot and Solution Explorer are gated separately by the broader "Sentinel - Illuminate All Apps" group rather than by a named role above — most users already have this.

Role Descriptions

admin Sentinel - Illuminate Admins

Full access to every feature, including admin-only routes. Assigned to the AI team and designated IT admins only.

manager Sentinel - Illuminate Executives

Directors, VPs, and EVPs with direct-report account managers. Unlocks Team View and Executive View (org-wide rollup) on the Sales Dashboard, plus the SOC nav link.

sales Sentinel - Illuminate Sales

Account Managers and regional sales staff. Own-accounts view on the Sales Dashboard — cannot see Team View or Executive View.

csm Sentinel - Illuminate Customer Success

Customer Success Managers — CSM Customer Dashboard and SOC CSM Dashboard only.

soc Sentinel - Illuminate Security Team Leads / Security Managers

SOC analysts, team leads, and managers. Access to SOC Dashboards, SOC CSM Dashboard, and Cisco/SIEM tooling (server-side "soc or admin" gate).

broad Sentinel - Illuminate Managers

Broader internal staff — nav visibility across all Illuminate surfaces. Individual routes still enforce their own server-side role check, so nav visibility alone doesn't guarantee data access.

ma Sentinel - Illuminate Mergers and Acquisitions

M&A team members. Access to the Sales Dashboard, SOC nav, Geographic Analytics, and Ticket Status/SIEM tooling for diligence work.

epmo Sentinel - Illuminate EPMO

Project Management Office. Access to Project Plan and Lessons Learned only.

sow Sentinel - Illuminate Solution Architects

ScopeStack/SOW integration users. Access to the SOW Generator only.

Requesting a Role Change

Access is granted by adding your account to the relevant Entra group above — contact your IT/portal administrator or raise a request via the standard helpdesk process, referencing "Illuminate Portal — Entra group access," and include your name, email, and business justification.

Frequently Asked Questions

I clicked Sign-In but nothing happened. What do I do?
Your browser may be blocking the Microsoft login pop-up or redirect. Ensure you are using an up-to-date browser (Chrome, Edge, or Firefox) and that pop-ups are not blocked for the portal domain. If the issue persists, clear your browser cache and cookies for the portal domain and try again.
I get "Authentication check failed" after signing in.
This means the portal backend could not validate your Microsoft token. Possible causes: (1) Your account is not provisioned in the portal — contact your admin. (2) Your Entra session has expired — sign out, clear the browser cache, and sign in again. (3) A network issue is blocking the auth preflight call — check your corporate VPN or proxy settings.
A feature card is greyed out on the Hub. Why can't I access it?
Your role does not include access to that feature. Refer to the User Roles section above to see which roles have access to each feature. Contact your portal administrator to request a role change if you need access.
The ChatBot says "I couldn't find relevant information." What does that mean?
The RAG search did not return results that met the relevance threshold for your question. Try rephrasing with more specific terms or breaking the question into smaller parts. If you believe the data should exist, check with your admin whether the relevant data source is indexed.
How often is customer intelligence data refreshed?
Customer intelligence data (installed base, contracts, alerts) is refreshed nightly. Cisco PSIRT advisories are pulled every 4 hours. Cisco EoX data is refreshed weekly. If you believe specific data is stale, check the "Last Updated" timestamp in the dashboard header, then contact your admin if it is more than 24 hours old.
Is the data in this portal sent to OpenAI for training?
No. All AI calls go through Sentinel's Azure OpenAI Service deployment, which uses Microsoft's enterprise data protection commitments. Microsoft has confirmed that data submitted to Azure OpenAI is not used to train or improve OpenAI foundation models.
Can I use the portal on a mobile device?
Yes. The portal is mobile-responsive. The sidebar navigation collapses on small screens. For the best experience on complex tools (SIEM Validator, Reports), a desktop browser is recommended.
I generated a SOW but it has placeholder text in brackets. Is that normal?
Yes. The AI sometimes inserts bracket placeholders (e.g., [Customer Legal Name]) where it could not determine the correct value from your inputs. Always search the document for [ before sending to a customer and replace all placeholders.
How do I report a bug or request a new feature?
Raise a ticket via the IT helpdesk and tag it "Illuminate Portal." For urgent production issues, contact the Illuminate-AI engineering team directly at your internal support channel. Feature requests are reviewed in the quarterly roadmap planning cycle.
What is the difference between DEV, UAT, and Production?
DEV is the development environment — engineers test new features here. Data resets frequently. UAT (User Acceptance Testing) is used to validate new releases before they go live; data mirrors production periodically but may lag. Production is the live environment used for real customer data. Each environment shows a coloured banner at the top of the page.