Sentinel Signal

Sentinel Signal Product Surfacing Implementation Report

Source: docs/sentinel-signal-product-surfacing-implementation.md

Document Content

Sentinel Signal Product Surfacing Implementation Report

Release context

  • Baseline commit: 30d45a1
  • Verify baseline: 1.0.759
  • Released Verify version: 1.0.761
  • Sentinel Policy baseline: 0.1.1
  • Database migrations: none
  • Deployment: IONOS production, 2026-08-29
  • Marketplace publication: not performed
  • Apify mutation: not performed

The implementation adds a connected, machine-readable product graph. It does not add product capabilities, persistence, authentication, billing, scoring, or enforcement behavior.

Architecture delivered

sentinelsignal.io
├── /healthcare ────────────────┐
├── /developers                 │
├── /tools                      │
└── /integrations               │
        │                       │
        ├── verify.sentinelsignal.io
        │   ├── /trustops
        │   ├── /verify-intelligence-api
        │   ├── /verify-data
        │   ├── /agent-reliability
        │   └── /integrations/vscode
        │
        └── policy.sentinelsignal.io/

Stable entity identifiers are:

  • https://sentinelsignal.io/#organization
  • https://verify.sentinelsignal.io/#product
  • https://policy.sentinelsignal.io/#product
  • https://sentinelsignal.io/tools#developer-utilities

Corporate surface

  • Added real /tools and /integrations static pages using the shared SSI shell, styles, footer, and analytics.
  • /tools owns exactly the three verified public Apify Actors and emits ItemList/SoftwareApplication JSON-LD.
  • /integrations maps first-party developer, runtime, API/data, registry, Marketplace, Apify, and PyPI destinations without claiming an unavailable Marketplace identity.
  • Healthcare now distinguishes Claims Intelligence from Sentinel Policy.
  • Developers now separates Verify, Healthcare, Policy, and Developer Utilities.
  • The homepage and footer provide compact discovery links; primary navigation remains unchanged.
  • The corporate sitemap includes /tools and /integrations.
  • Organization JSON-LD has a stable identifier and only the verified Apify publisher profile in sameAs.

Corporate click telemetry now sends placement, destination, product, and source_page through the existing Verify analytics endpoint.

Sentinel Policy surface

Public GET and HEAD routes are registered before the root MCP mount for:

  • /
  • /robots.txt
  • /sitemap.xml

The landing page is server-rendered and includes canonical, robots, Open Graph, and SoftwareApplication JSON-LD metadata. The sitemap contains only the canonical landing page. Robots rules exclude APIs, administrative paths, health endpoints, the MCP transport, and documentation/operational paths from crawler indexing. Existing MCP initialization, authentication, ingestion, rights, and persistence behavior is unchanged.

Verify VS Code integration

Added public GET/HEAD /integrations/vscode with:

  • Canonical, Open Graph, and product JSON-LD metadata.
  • The evidence → policy → snapshot → managed settings → customer deployment → Microsoft/GitHub enforcement boundary.
  • TrustOps and API documentation links.
  • Public-cache, sitemap, synthetic-health, and route-render coverage.
  • A compact TrustOps backlink with analytics.

Configuration:

MCP_VERIFY_VSCODE_MARKETPLACE_URL=

Blank configuration renders an indexable neutral “Marketplace release pending” state and omits the listing URL, Marketplace click event, and Marketplace sameAs. A configured value must be an HTTPS marketplace.visualstudio.com/items?... URL; invalid scheme, host, path, credentials, port, or missing query fails application settings construction.

The IONOS production environment example and Verify web service pass-through include the optional variable. Production currently leaves it blank, so the pending state is live and no Marketplace identity is claimed.

Cross-surface and machine discovery

  • Verify Intelligence links to the Trust Data Feed for full-corpus ingestion.
  • The Trust Data Feed links to Intelligence for operational queries.
  • /ecosystem now includes Intelligence, Data Feed, Agent Reliability, VS Code, and the first-party developer-utilities owner page.
  • /llms.txt is a concise factual product index grouped into public trust, commercial query, bulk data, governance, enforcement integrations, and developer utilities.
  • /llms-full.txt retains detailed MCP tools, routes, examples, and commercial context.
  • Marketplace discovery appears only when configured. Administrative, internal, authenticated-management, and nonexistent routes are excluded from the concise index.

Analytics contract

The following values are accepted by AnalyticsEvents and classified as click events:

corporate_policy_click
corporate_tools_actor_click
corporate_integration_click
verify_vscode_marketplace_click
verify_vscode_trustops_click
verify_intelligence_data_feed_click
verify_data_feed_intelligence_click
verify_apify_tool_click

No analytics migration or new analytics service was introduced.

Crawl validation

scripts/check_product_surfacing.py validates owned corporate, Verify, and Policy pages for:

  • HTTP 200 and an expected page marker.
  • Title and description.
  • Canonical URL.
  • Open Graph title, description, and URL.
  • Parseable JSON-LD.
  • Reachability of links between the owned pages in the product graph.

Use --check-external to test other HTTP/S links as warning-only checks. Defaults target the three production domains and can be replaced with --corporate-base, --verify-base, and --policy-base after an authorized deployment.

Verification results

Focused local results during implementation:

  • Corporate product messaging and smoke-parser tests: 55 passed.
  • Policy API, security-route, and MCP boundary tests: 40 passed.
  • Verify product-surfacing tests: 7 passed.
  • Verify route and analytics regression selection: 181 passed; three initial environment/coverage failures were isolated. Two were caused by running from the Verify subdirectory without the repository root on PYTHONPATH; the product-related synthetic route omission was corrected and its focused rerun passed.

Final required gates:

  • pytest tests/unit/test_product_messaging.py: 52 passed.
  • PYTHONPATH=policy/src pytest policy/tests: 206 passed.
  • PYTHONPATH=verify/src:. pytest verify/tests: 1,001 passed. The explicit repository-root entry is needed by two pre-existing cross-package tests that import app and scripts.
  • make test-suites: 356 passed; line coverage 75.75% and branch coverage 60.85%, both above their enforced 70% and 55% thresholds.

Production verification on 2026-08-29:

  • The immutable release marker, public Verify build endpoint, and all Verify runtime roles reported the deployed Git SHA and release version.
  • The deploy run passed route-version, analytics-partition, trust-surface-coherence, migration, and health gates.
  • The product-surfacing smoke validated all 11 owned pages across the corporate, Verify, and Policy domains, including parseable JSON-LD and owned-link reachability.
  • Corporate /tools and /integrations, Policy landing/robots/sitemap, and Verify /integrations/vscode returned their distinct production content.
  • The Marketplace-pending state is live; no Marketplace CTA or identity is emitted while the configuration is blank.

Limitations and deferred work

  • No VS Code extension or Marketplace listing exists in this repository. Configure the listing only after independent publication and verification of the exact public URL.
  • Actor source repositories are not present here. Add their /tools ownership footers through those repositories or the Apify console as an external follow-up.
  • Marketplace homepage/docs/support backlink changes are deferred until a listing exists.
  • No dashboard, new API, deployment automation, database, migration, auth, billing, scoring, Policy ingestion, or runtime enforcement change was introduced.