Sentinel Signal Product Surfacing Implementation Report
Release context
- Baseline commit:
30d45a1 - Verify baseline:
1.0.759 - Released Verify version:
1.0.761 - Sentinel Policy baseline:
0.1.1 - Database migrations: none
- Deployment: IONOS production, 2026-08-29
- Marketplace publication: not performed
- Apify mutation: not performed
The implementation adds a connected, machine-readable product graph. It does not add product capabilities, persistence, authentication, billing, scoring, or enforcement behavior.
Architecture delivered
sentinelsignal.io
├── /healthcare ────────────────┐
├── /developers │
├── /tools │
└── /integrations │
│ │
├── verify.sentinelsignal.io
│ ├── /trustops
│ ├── /verify-intelligence-api
│ ├── /verify-data
│ ├── /agent-reliability
│ └── /integrations/vscode
│
└── policy.sentinelsignal.io/
Stable entity identifiers are:
https://sentinelsignal.io/#organizationhttps://verify.sentinelsignal.io/#producthttps://policy.sentinelsignal.io/#producthttps://sentinelsignal.io/tools#developer-utilities
Corporate surface
- Added real
/toolsand/integrationsstatic pages using the shared SSI shell, styles, footer, and analytics. /toolsowns exactly the three verified public Apify Actors and emitsItemList/SoftwareApplicationJSON-LD./integrationsmaps first-party developer, runtime, API/data, registry, Marketplace, Apify, and PyPI destinations without claiming an unavailable Marketplace identity.- Healthcare now distinguishes Claims Intelligence from Sentinel Policy.
- Developers now separates Verify, Healthcare, Policy, and Developer Utilities.
- The homepage and footer provide compact discovery links; primary navigation remains unchanged.
- The corporate sitemap includes
/toolsand/integrations. - Organization JSON-LD has a stable identifier and only the verified Apify publisher profile in
sameAs.
Corporate click telemetry now sends placement, destination, product, and source_page through the existing Verify analytics endpoint.
Sentinel Policy surface
Public GET and HEAD routes are registered before the root MCP mount for:
//robots.txt/sitemap.xml
The landing page is server-rendered and includes canonical, robots, Open Graph, and SoftwareApplication JSON-LD metadata. The sitemap contains only the canonical landing page. Robots rules exclude APIs, administrative paths, health endpoints, the MCP transport, and documentation/operational paths from crawler indexing. Existing MCP initialization, authentication, ingestion, rights, and persistence behavior is unchanged.
Verify VS Code integration
Added public GET/HEAD /integrations/vscode with:
- Canonical, Open Graph, and product JSON-LD metadata.
- The evidence → policy → snapshot → managed settings → customer deployment → Microsoft/GitHub enforcement boundary.
- TrustOps and API documentation links.
- Public-cache, sitemap, synthetic-health, and route-render coverage.
- A compact TrustOps backlink with analytics.
Configuration:
MCP_VERIFY_VSCODE_MARKETPLACE_URL=
Blank configuration renders an indexable neutral “Marketplace release pending” state and omits the listing URL, Marketplace click event, and Marketplace sameAs. A configured value must be an HTTPS marketplace.visualstudio.com/items?... URL; invalid scheme, host, path, credentials, port, or missing query fails application settings construction.
The IONOS production environment example and Verify web service pass-through include the optional variable. Production currently leaves it blank, so the pending state is live and no Marketplace identity is claimed.
Cross-surface and machine discovery
- Verify Intelligence links to the Trust Data Feed for full-corpus ingestion.
- The Trust Data Feed links to Intelligence for operational queries.
/ecosystemnow includes Intelligence, Data Feed, Agent Reliability, VS Code, and the first-party developer-utilities owner page./llms.txtis a concise factual product index grouped into public trust, commercial query, bulk data, governance, enforcement integrations, and developer utilities./llms-full.txtretains detailed MCP tools, routes, examples, and commercial context.- Marketplace discovery appears only when configured. Administrative, internal, authenticated-management, and nonexistent routes are excluded from the concise index.
Analytics contract
The following values are accepted by AnalyticsEvents and classified as click events:
corporate_policy_click
corporate_tools_actor_click
corporate_integration_click
verify_vscode_marketplace_click
verify_vscode_trustops_click
verify_intelligence_data_feed_click
verify_data_feed_intelligence_click
verify_apify_tool_click
No analytics migration or new analytics service was introduced.
Crawl validation
scripts/check_product_surfacing.py validates owned corporate, Verify, and Policy pages for:
- HTTP 200 and an expected page marker.
- Title and description.
- Canonical URL.
- Open Graph title, description, and URL.
- Parseable JSON-LD.
- Reachability of links between the owned pages in the product graph.
Use --check-external to test other HTTP/S links as warning-only checks. Defaults target the three production domains and can be replaced with --corporate-base, --verify-base, and --policy-base after an authorized deployment.
Verification results
Focused local results during implementation:
- Corporate product messaging and smoke-parser tests: 55 passed.
- Policy API, security-route, and MCP boundary tests: 40 passed.
- Verify product-surfacing tests: 7 passed.
- Verify route and analytics regression selection: 181 passed; three initial environment/coverage failures were isolated. Two were caused by running from the Verify subdirectory without the repository root on
PYTHONPATH; the product-related synthetic route omission was corrected and its focused rerun passed.
Final required gates:
pytest tests/unit/test_product_messaging.py: 52 passed.PYTHONPATH=policy/src pytest policy/tests: 206 passed.PYTHONPATH=verify/src:. pytest verify/tests: 1,001 passed. The explicit repository-root entry is needed by two pre-existing cross-package tests that importappandscripts.make test-suites: 356 passed; line coverage 75.75% and branch coverage 60.85%, both above their enforced 70% and 55% thresholds.
Production verification on 2026-08-29:
- The immutable release marker, public Verify build endpoint, and all Verify runtime roles reported the deployed Git SHA and release version.
- The deploy run passed route-version, analytics-partition, trust-surface-coherence, migration, and health gates.
- The product-surfacing smoke validated all 11 owned pages across the corporate, Verify, and Policy domains, including parseable JSON-LD and owned-link reachability.
- Corporate
/toolsand/integrations, Policy landing/robots/sitemap, and Verify/integrations/vscodereturned their distinct production content. - The Marketplace-pending state is live; no Marketplace CTA or identity is emitted while the configuration is blank.
Limitations and deferred work
- No VS Code extension or Marketplace listing exists in this repository. Configure the listing only after independent publication and verification of the exact public URL.
- Actor source repositories are not present here. Add their
/toolsownership footers through those repositories or the Apify console as an external follow-up. - Marketplace homepage/docs/support backlink changes are deferred until a listing exists.
- No dashboard, new API, deployment automation, database, migration, auth, billing, scoring, Policy ingestion, or runtime enforcement change was introduced.