# OfficeCom Sentinel Architecture ## Goal OfficeCom Sentinel is a Windows endpoint client that: - runs on every monitored device - reads local attack telemetry and optional local vulnerability exports - writes NinjaOne device custom fields locally - uploads signed JSON reports to n8n - receives updates through NinjaOne tasks from Gitea-hosted releases ## Current Model The repository now keeps only the client-side architecture: - endpoint scan and correlation - local NinjaOne field publishing - optional n8n upload - packaged ZIP release flow for NinjaOne deployment The client must not depend on a PostgreSQL IP or hostname. PostgreSQL stays a server-side concern behind the ingest or n8n layer. ## PostgreSQL Handling - PostgreSQL is not contacted directly by endpoint clients. - The PostgreSQL host or IP should be tracked in the repository only as internal deployment metadata. - Review that internal target on every release before publishing. - Keep the actual production value in a private operational copy if it should not be visible in the public repository. ## Removed Model The following older pieces are intentionally no longer part of the repo: - share-based organization aggregation - dedicated server-side collector package - server-side NinjaOne organization field updater