Observation is not a screen somebody promises to glance at between patients. Every line at this station brings three things at once: software reading behaviour where the work gets done, a layer that holds an entire clinic within a single view, and an engineer, three in the morning and wide awake, who decides what happens next.
Signature matching stopped carrying the load years ago, and no clinic can afford to wait while a definition file catches up with something written last Tuesday. SentinelOne works from behaviour instead. What did this thing start. Which files did it open, in what order. Where did it reach out to. Does the shape of all that resemble encryption, or collection, or somebody walking slowly across a network. All of it is worked out locally, which is why it holds up on a laptop sitting in a car park and on the machine nobody has signed into since Friday.
Fluency is the layer above. Agent output goes in beside sign-in records, mail activity, network data and logs from whatever else your practice already pays for, and comes back out as one picture. That is why what lands with our engineers can be decided instead of merely noticed, and most of what you are buying sits in the distance between those two words.
Line one sorts and advises. Line two broadens what gets read together, which is how the slow ones surface: an unusual sign-in on Monday, an odd process elsewhere on Wednesday, one story where there used to be a pair of shrugs. Line three acts without waiting, and earns its difference on hardware touching charting, imaging, claims, or the practice bank account. Almost no clinic needs it on everything.
Cluster nodes get billed apart. A node is not a reception PC, the software behaves quite differently on one, and folding them into a desktop count would leave a quiet untruth on your invoice. No Kubernetes anywhere in the clinic means three of the six below have nothing to offer you, and nobody here will argue otherwise.
Rates come live from billing. Anything tagged waits on the chart while you carry on reading.
Judgement about a running process happens on the machine itself, and a staffed desk settles what comes next. You hear what surfaced, and what got done. Nobody hands a clinic a graph to decipher between patients.
| Fitted to | Windows, macOS and Linux endpoints that will accept an agent |
|---|---|
| Watches | How processes behave, what files move, and where the machine reaches out to |
| Kept for | Whatever retention this line carries, settled during scoping |
| Escalates to | Our desk, whatever the hour, carrying a recommendation with it |
| Reviewed by | An engineer, ahead of anything landing with your practice |
Same work as the line above, except sign-ins, mail and network records sit alongside what the machine reports rather than in three separate windows. Monday's odd login and Tuesday's odd process stop being unrelated shrugs.
| Fitted to | Endpoints in a practice already running a Microsoft or Google tenant |
|---|---|
| Watches | Machines, identities, mail and network traffic, all read as one |
| Kept for | A longer window, so a week gone by can still be opened up |
| Escalates to | Our desk, arriving with the joined-up account attached |
| Reviewed by | An engineer, who works out what genuinely warrants your time |
The joined-up line, with hands. Cross the threshold and that machine leaves the network, then returns to how it stood beforehand, all while an analyst is partway through reading. Sunday, two in the morning, is where the difference shows.
| Fitted to | Machines that reach charting, imaging, claims or the practice bank account |
|---|---|
| Watches | The same joined-up signals, measured against a line worth crossing |
| Kept for | The longer window, plus a log of each automatic action taken |
| Escalates to | The machine is contained, then the desk, then your practice |
| Reviewed by | An engineer, afterwards, on everything the software did alone |
Watching over containerised workloads, billed per node so the number matches something your platform engineer already counts. Nodes, never pods.
| Fitted to | Kubernetes nodes, wherever the cluster happens to run |
|---|---|
| Watches | The way workloads on that node behave once running |
| Kept for | Whatever retention this line carries |
| Escalates to | Our desk, naming the node and naming the workload |
| Reviewed by | An engineer, ahead of anything landing with your platform team |
The node line with correlation switched on. Cluster activity ends up beside identities and machines instead of sitting in a vacuum. Worth the difference wherever a cluster rather than a server is what serves your patient portal.
| Fitted to | Kubernetes nodes in a practice with a wider correlated estate |
|---|---|
| Watches | Running nodes, identities, machines and network traffic as one |
| Kept for | A longer window, so a week of cluster history stays openable |
| Escalates to | The Fortify 24x7 desk, carrying the correlated story with it |
| Reviewed by | An engineer, who works out what warrants a phone call |
The node line with a hand attached, for a cluster carrying something nobody can leave misbehaving until the clinic unlocks its doors. Action first; paperwork catches up afterwards.
| Fitted to | Production clusters carrying patient-facing or billing workloads |
|---|---|
| Watches | Joined-up cluster activity, measured against a line worth crossing |
| Kept for | Extended retention, plus the record of each automated action |
| Escalates to | The workload is shut in, then the desk, then your platform team |
| Reviewed by | An engineer, afterwards, on everything the software did alone |
Each station has an edge to it, and clinics get caught out by suppliers who pretend otherwise. Below is where this one stops, set down so a practice can work out what else it needs and who else has to supply it.
Heads up: card statements show FORTIFY 24X7 - MediDefense IT is a Fortify 24x7 brand, and your subscription is billed by Fortify 24x7.