The protocol is frozen. The world is not.
Is the ground it was designed on still the ground — and is the model still trustworthy for it?
A Phase III trial can run for years. Over that span the standard of care moves, competitors read out, and the population that actually enrolls drifts away from the one that was powered for. None of this is visible from inside the protocol, because the protocol cannot change. Sentinel watches the ground underneath a running trial and reports when it has moved far enough to matter.
What Sentinel actually does for you.
A Phase III trial can take years, and the world does not hold still while it runs. The standard of care moves, the population that actually enrolls drifts, competitors read out. A prediction made when the protocol was drafted can quietly go stale — still confident, no longer earned — and nothing inside the frozen protocol will tell you.
Sentinel watches the live trial against the ground it was designed on. While that ground still holds, it tracks quietly. When the ground has moved too far, it does the unusual thing — it says so and withdraws its own calibration, rather than reporting a confident but stale number.
Sentinel monitors your running trial and tells you when the assumptions it was designed on no longer hold — before the readout, not after. What to do about it stays your decision; the job here is to make sure the drift is never a surprise.
Continuous drift and effective-coverage monitoring against the design-time reference distribution; fail-closed calibration withdrawal when population or standard-of-care drift exceeds tolerance; Mondrian-conditioned coverage tracking, each state change carrying a signed audit row.
It withdraws before it misleads. As the trial runs, the ground drifts off the distribution the model was calibrated on; past the tolerance threshold, Sentinel reports no number rather than a stale one. A hand-authored synthetic fixture, not a measurement.
Four things travel with every answer.
A drift severity, per stratum
Movement is rarely uniform. A trial can be stable overall while one enrolling subgroup has drifted past the point where the original powering assumption holds.
Effective coverage, not nominal coverage
What the intervals are actually delivering now, rather than what they were built to deliver under conditions that may no longer obtain.
An explicit trust state
Active, degraded, or withdrawn. The system is designed to fail closed: when it can no longer stand behind a calibration it says so, rather than continuing to emit a confident-looking number.
The specific mover
Which of the watched surfaces — standard of care, competitive field, enrolling population — accounts for the change, so the finding is actionable rather than merely alarming.
One substrate, addressed at a different moment.
Sentinel monitors the substrate a prediction was conditioned on and re-evaluates whether that conditioning still holds. The engineering commitment is the unusual part: the system's most important output is its own withdrawal. A monitor that never declines to answer is not a monitor, it is a number generator with a schedule.
What this surface does not claim.
Stated plainly, because a capability page that omits them is marketing rather than documentation.
It cannot change a frozen protocol
It tells you what you are now running, which is a different trial from the one you designed. What to do about that is a sponsor decision, not a model output.
Drift detection is not outcome prediction
A stable reading is not a favourable one, and a drifting reading is not a prediction of failure.
Thresholds are design choices
Where degraded becomes withdrawn is a governance decision, documented as such, not an emergent property of the data.
Not authorized
No FDA authorization exists. Pre-deployment; not for clinical use.
An interactive demo on a synthetic composite.
Every value in the demo is a hand-authored fixture. It is there to show the shape of the output and how it responds — not to report a measurement.