Skip to content
How it works

Local agent. Encrypted relay. Your browser.

Sentinel is three things working together: a tiny agent on the customer's network, a small UK relay, and the engineer dashboard in your browser. Approved installers sign in with their work email (secured by Cloudflare Access), pair with a six-character code, and read the system live. Any change is written to a permanent audit log — tied to you and the system — before it reaches the inverter.

Setup

Four steps to a live system. Then you diagnose.

  1. Install

    The customer opens Sentinel

    Your customer downloads Sentinel and opens it on any computer on the same network as the inverter — no command line, no router changes, nothing to leave running. They open it for the session and close it when you're done.

    A few minutes

  2. Pair

    Pair with a six-character code

    The agent shows a six-character code; the customer reads it to you. Sentinel opens an encrypted outbound connection through a Cloudflare relay to your browser dashboard — nothing to port-forward.

    About 30 seconds

  3. Diagnose

    Read the system live

    Power flow, battery, solar, grid, EMS state, per-cell voltages and every exposed register — live in your browser, on mobile too. Read-only by default.

    From the moment it pairs

  4. Act safely

    Make a change only with consent

    Need to write a setting? Request it; the change applies only after the customer taps “Allow” on their own device during an armed window, and every write is recorded to a permanent, tamper-evident log the moment it's made — no engineer can alter or delete it.

    Only when needed · always logged

What you catch

The faults you spot without going to site.

A non-exhaustive list — the patterns engineers see go wrong most often on GivEnergy systems in the field, all readable live once you're paired.

Battery not charging

Solar is generating, the charge slot is active, but state of charge isn't rising. Common when a BMS contactor weakens or a charge schedule has drifted.

Battery not discharging

No solar, load is present, SoC well above reserve, no discharge slot blocking — but the inverter isn't drawing from the battery. Classic comms-loss symptom.

Fault codes thrown

Read the inverter's holding-register fault codes and map them to plain-English categories — "battery comms loss", "grid out-of-range", "BMS isolation fault" — so you know what you're walking into.

Temperature drift

Battery or inverter temperature climbing outside the safe envelope. Early warning for degradation and end-of-life cell failure.

Grid excursions

Voltage or frequency outside the G98/G99 envelope. Could be DNO side, could be the inverter — read the trend live and you know which.

Known-buggy firmware

Check the firmware version against known issues (charge-slot resets, EPS misbehaviour, and the like) the moment you pair, before you touch anything.

Read-only, consent-gated, fully audited

You read by default. The customer allows every change. Every write is logged.

Sentinel reads registers only. Any inverter write happens solely after the customer allows it on their own device during an engineer-armed access window — and every write is recorded to a permanent, tamper-evident audit log before it ever reaches the inverter.

Read-only by default

Once paired, the agent streams registers to your dashboard and nothing else. It cannot write to the inverter unless you explicitly request a change.

The customer allows it on their device

To make a change you arm an access window and request it. The write applies only after the customer taps "Allow" on their own device inside that window; the agent refuses writes outside it.

Logged before it reaches the inverter

Every write is recorded to an append-only, hash-chained audit log — keyed to the signed-in engineer and the system — before the command is relayed. No log, no write: if it can't be recorded, the change is refused.

Under the hood

What it reads, what it writes, and how pairing works

Live power flow (solar, battery, grid, load), state of charge, battery cell and module voltages and temperature, inverter temperature, error and fault codes, charge/discharge schedule, EMS state, firmware version, and aggregate energy counters. Read from the inverter's standard local Modbus port over the LAN — the same registers the GivEnergy kit exposes on-site.
Yes, by default. The agent only reads registers; nothing is written to the inverter unless you explicitly request a change and the customer approves it on their own device during an armed access window. If you never request a write, Sentinel can never write.
The agent shows a six-character code that the customer reads to you. Sentinel opens an encrypted outbound connection from the customer's LAN through a small UK Cloudflare relay to your browser dashboard — outbound TLS only, no inbound ports opened on the home router. Per-device mTLS certificates are issued at pairing and rotated annually.
You arm an access window from your dashboard and request the specific change. The change applies only after the customer taps "Allow" on their own device inside that window; the agent refuses any write outside it. Before the command ever reaches the inverter it is written to a permanent, tamper-evident audit log — hash-chained and append-only, keyed to you (the signed-in engineer) and the system. If it can't be logged, the write is refused.
Only approved installers. Engineers sign in with their work email, secured by Cloudflare Access — there is no open signup. Ron approves each installer and can disable access from an admin console, so the person on the other end of any session is always a known, currently-approved engineer. Every remote change is recorded against that engineer and the specific system.
The agent keeps reading over the LAN even if the connection to the relay drops, and resumes streaming to your dashboard automatically once it's back. No inverter data is lost while the link is down.
The local agent keeps reading the inverter over the LAN regardless. Your remote session and the browser dashboard need the customer's connection up, because the relay runs over the internet — but nothing depends on a GivEnergy cloud account.
No. Only the inverter register values and fault flags needed for diagnosis pass through the relay — no personal data, no audio, no video, no LAN topology, no tracking. Sentinel is not affiliated with GivEnergy and sets no tracking cookies.
Apply for access

Get access in minutes once you're approved.

Sentinel is free to approved installers. Access is by application — apply, and once you're approved you can run the desktop app and pair to a customer's system in minutes.

  • Six-character pairing, encrypted outbound only
  • Read-only by default, consent-gated writes
  • Works behind any home router
  • Free to approved installers