The custom sensor catalog
Every sensor planned for Guard Pro: what it catches, how it connects to your app, and where you set the limit. Below the tables: the probe endpoint, the ping address and the MCP tools, at the level of principles.
Coming to Guard ProFilter by category or by how it connects.
X A limit you set. Guard suggests it from your business's own history; you approve or change it.
Pull Guard checks your app Ping Your app pings Guard Probe Signed probe in your app Provider Read-only provider connection
Part of the Guard Pro watch Already among the checks Guard Pro runs on every watched app.
No sensor matches. Try another word or set a filter back to All.
Online store
22 sensorsThe checks a store owner wishes they had the week the checkout broke quietly.
| Sensor | What it catches | How it connects | Your limit |
|---|---|---|---|
| Last order older than X hours | The checkout broke quietly | Probe | X you set |
| Checkout page loads and shows the pay button | A broken checkout | Pull | No limit to set |
| Add to cart works (a flow of a few steps) | A cart that does not update | Pull | No limit to set |
| Failed payments above X% in an hour | A problem with card processing | Providere.g. Stripe | X you set |
| Payment webhook not delivered | Orders that are never marked as paid | Providere.g. Stripe | No limit to set |
| Payments and orders differ by more than X | Lost orders | Probe | X you set |
| Best seller out of stock or below X units | Sales that stop | Probe | X you set |
| A product price changed by more than X% | A mistake or a break-in | Probe | X you set |
| A coupon used abnormally (over X uses an hour) | A coupon code that leaked | Probe | X you set |
| Order confirmation email sent | Customers who get no confirmation | Ping | No limit to set |
| Shipping cost is calculated | A shipping calculator that went down | Pull | No limit to set |
| Store search returns results | Broken search | Pull | No limit to set |
| Product images load | Broken images after a storage change | Pull | No limit to set |
| Inventory sync ran in the last X hours | Stock levels out of date | Ping | X you set |
| Orders not shipped within X days | Fulfillment running late | Probe | X you set |
| Refunds or cancellations above X% | A product problem or fraud | Providere.g. Stripe | X you set |
| New payment disputes | Risk to your payment account | Providere.g. Stripe | No limit to set |
| Price on the page differs from the price at checkout | A pricing fault | Pull | No limit to set |
| Product page slower than X seconds | Shoppers who leave | Pull | X you set |
| Daily order value X% below normal | A drop in sales | Probe | X you set |
| Abandoned carts above X% | A checkout that drives buyers away | Probe | X you set |
| Contact form submits | Messages that never arrive | Pull | No limit to set |
Suspicious silence
21 sensorsThe strongest category for a founder. Most expensive failures do not look like an error; they look like nothing happening. Each sensor alerts when something that should happen did not happen within X hours or days.
| Sensor | What it catches | How it connects | Your limit |
|---|---|---|---|
| No new order within X | A broken checkout or payment | Probe | X you set |
| No new sign-up within X | A broken sign-up, or a verification email that never arrives | Probe | X you set |
| No successful sign-in within X | Broken sign-in | Probe | X you set |
| No successful payment within X | Card processing that got stuck | ProviderProbe | X you set |
| No subscription renewal within X | Recurring charges that fail | Providere.g. Stripe | X you set |
| No email sent by the system within X | The email provider blocked or suspended the account | Ping | X you set |
| No SMS or WhatsApp message within X | The messaging provider stopped | Ping | X you set |
| No contact form lead within X | A broken form | Probe | X you set |
| No user file upload within X | File storage full or blocked | Probe | X you set |
| No backup run within X | Backups that stopped | Ping | X you set |
| No sync from an outside system within X | An expired key or an API that changed | Ping | X you set |
| No hourly or daily scheduled job within X | A scheduler that was switched off | Ping | X you set |
| No content update (post, product, page) within X | A content system that is stuck | Probe | X you set |
| No call to the app's AI feature within X | The AI feature failing quietly | Probe | X you set |
| No analytics event from the site within X | Tracking code removed in a deploy | Ping | X you set |
| No home page visit within X | The site not reachable for real users | Ping | X you set |
| No job completed in the queue within X | A stuck queue | Probe | X you set |
| No invoice issued within X | An invoicing system that is stuck | Ping | X you set |
| No daily report sent to the admin within X | Reports that stopped | Ping | X you set |
| No new deploy within X (for projects that ship daily) | A deploy pipeline that is stuck | Pulldeploy fingerprint | X you set |
| Not even one active user within X | An app that is empty in practice | Probe | X you set |
Databases and data
20 sensorsChecked from inside your app, with the connection it already has. 7IT never receives a database password.
| Sensor | What it catches | How it connects | Your limit |
|---|---|---|---|
| Database answers within X ms | An outage or slowness | Probe | X you set |
| Open connections above X% of the limit | "Too many connections" on the way | Probe | X you set |
| Database size above X% of the plan | A switch to read-only mode | ProbeProvider | X you set |
| A table growing abnormally fast | A bug that duplicates rows, or spam | Probe | No limit to set |
| A table suddenly emptied | Accidental deletion or a break-in | Probe | No limit to set |
| A known query slower than X | An index that is missing or was dropped | Probe | X you set |
| Last backup older than X hours | Backups that stopped | PingProvider | X you set |
| The last tested restore passed | A backup you cannot restore from | Ping | No limit to set |
| Orphan records (an order with no customer) above X | Data that broke | Probe | X you set |
| A public table without row level security | Data open to everyone | Providere.g. Supabase | No limit to set |
| The data provider flags a new security advisory | A risky setting | Providere.g. Supabase | No limit to set |
| The project is close to pausing for inactivity | A database that falls asleep | PullProvider | No limit to set |
| Query errors above X an hour | Code that broke against the database | Ping | X you set |
| Locks waiting more than X seconds | A lock that freezes the app | Probe | X you set |
| The cache (Redis) answers | Cache down | Probe | No limit to set |
| Cache memory above X% | Data pushed out of the cache | Probe | X you set |
| File storage above X% of the plan | Uploads that are about to fail | Provider | X you set |
| A storage bucket turned public | Users' files leaking | Pullon an app you own | No limit to set |
| A migration that did not complete | A deploy stuck halfway | Probe | No limit to set |
| Replica lag above X seconds | Users shown stale data | Probe | X you set |
Background jobs and integrations
20 sensorsThe work nobody sees until it stops: scheduled jobs, queues, webhooks and the outside services your app calls.
| Sensor | What it catches | How it connects | Your limit |
|---|---|---|---|
| A scheduled job ran on time | A cron job that was switched off | Ping | No limit to set |
| A job started and did not finish within X | A stuck job | Pingstart and success pings | X you set |
| A job failed (exit code) | An error during the run | Pingfail ping | No limit to set |
| A job took longer than X | Load that keeps growing | Ping | X you set |
| Queue above X jobs | Workers that cannot keep up | Probe | X you set |
| The oldest job has waited more than X | A stuck queue | Probe | X you set |
| Jobs that failed for good (dead letter) | Work that was lost | Probe | No limit to set |
| Incoming webhooks failed above X | A provider that stopped sending | Ping | X you set |
| An outside API key works | A key that expired or was revoked | Probe | No limit to set |
| A key or token expires within X days | A failure you can see coming | Probe | X you set |
| The email provider accepts requests | Emails that are not going out | Probe | No limit to set |
| Bounced emails above X% | Getting blocked on the way to inboxes | ProviderPing | X you set |
| The SMS provider answers | Messages that are not sent | Probe | No limit to set |
| An outside rate limit was exceeded | A temporary block that breaks a feature | Ping | No limit to set |
| The CRM or spreadsheet sync ran | Leads that never arrive | Ping | No limit to set |
| A customer export or report was produced | A process that failed | Ping | No limit to set |
| Image or video processing finished | A heavy process that is stuck | Ping | No limit to set |
| Jobs that ran twice (duplicates) | Double emails or double charges | Ping | No limit to set |
| The background worker is connected and alive | A worker that crashed | Ping | No limit to set |
| GitHub Actions run succeeded | A deploy or tests that failed | ProviderGitHub | No limit to set |
SaaS and users
20 sensorsSign-in, subscriptions and the one action your product exists for, watched the way a user meets them.
| Sensor | What it catches | How it connects | Your limit |
|---|---|---|---|
| The sign-in flow works (test user) | Sign-in broken after a change | Pulla flow of a few steps | No limit to set |
| Failed sign-ins above X% an hour | A sign-in fault, or break-in attempts | Probe | X you set |
| A burst of sign-in attempts from one source | Password guessing | Probe | No limit to set |
| Suspicious sign-ups above X an hour | Bots and spam | Probe | X you set |
| The verification email arrives within X minutes | Users stuck at sign-up | Ping | X you set |
| The password reset link works | Users locked out | Pull | No limit to set |
| Sign-in with Google or GitHub works | A sign-in provider that broke | Pull | No limit to set |
| Active subscriptions dropped X% in a day | Cancellations or failed charges | Providere.g. Stripe | X you set |
| Failed recurring charges above X | Revenue being lost | Providere.g. Stripe | X you set |
| A paying user did not get access | Permissions that do not update | Probe | No limit to set |
| A cancelled user still has access | Service given away after cancelling | Probe | No limit to set |
| Daily active users X% below normal | A bug that drives users away | Probe | X you set |
| The product's core action succeeds (save, send, create) | The main feature broke | PullProbe | No limit to set |
| Inviting a user to a team works | Growth that is blocked | Pull | No limit to set |
| A user's data export completes | Privacy requests left unhandled | Ping | No limit to set |
| Account deletion requests waiting more than X days | Legal exposure | Probe | X you set |
| Users go past their plan's limits | Limits that are not enforced | Probe | No limit to set |
| User notifications (push, email) were sent | A notification system that is stuck | Ping | No limit to set |
| Main API response time above X | Slowness users can feel | Pull | X you set |
| A burst of errors on users' screens above X a minute | Crashes on the user's side | Pingfail ping | X you set |
AI features
20 sensorsMost apps built with AI also use AI. Here the risk is both money and quality.
| Sensor | What it catches | How it connects | Your limit |
|---|---|---|---|
| The AI feature answers a test question correctly | A broken feature | Probe | No limit to set |
| Daily AI spend above X | A bill that blows up | ProviderProbe | X you set |
| One user consumes more than X% of the spend | Abuse | Probe | X you set |
| AI provider rate-limit errors above X | Hitting the provider's rate limit | Ping | X you set |
| AI provider credit about to run out | A feature that stops tomorrow | Provider | No limit to set |
| Average AI response time above X seconds | Users kept waiting | Ping | X you set |
| Empty or cut-off answers above X% | Quality that dropped | Ping | X you set |
| A retired model still in use | A break you can see coming | Probe | No limit to set |
| AI endpoint open without sign-in Part of the Guard Pro watch | Usage billed to you | Pull | No limit to set |
| AI key in the code browsers receive Part of the Guard Pro watch | A key that leaked | Pull | No limit to set |
| AI provider outage Part of the Guard Pro watch | A feature failing through no fault of yours | Providerprovider status page | No limit to set |
| AI requests above X an hour | A usage spike or an attack | Ping | X you set |
| Content filter blocks above X | Misuse, or a filter set too strict | Ping | X you set |
| Document search (vector) returns results | An index that was deleted or is empty | Probe | No limit to set |
| Documents waiting for processing above X | Embedding work that is stuck | Probe | X you set |
| Average cost per AI chat up X% | A prompt that grew after an update | Ping | X you set |
| An agent looping beyond X steps | Cost with no ceiling | Ping | X you set |
| An MCP server the app uses answers | An outside tool that is down | Provider7Maps data | No limit to set |
| The system prompt changed in a deploy | An unintended change in behavior | Probefingerprint only | No limit to set |
| Negative user feedback (thumbs down) above X% | Quality that dropped | Ping | X you set |
How the library connects.
Sensors per category and connection method. A sensor that can use two methods counts in both.
| Category | Pull | Ping | Probe | Provider | Sensors |
|---|---|---|---|---|---|
| Online store | 8 | 2 | 8 | 4 | 22 |
| Suspicious silence | 1 | 9 | 10 | 2 | 21 |
| Databases and data | 2 | 3 | 12 | 6 | 20 |
| Background jobs and integrations | 0 | 12 | 7 | 2 | 20 |
| SaaS and users | 6 | 4 | 9 | 2 | 20 |
| AI features | 2 | 8 | 7 | 4 | 20 |
| All | 19 | 38 | 53 | 20 | 123 |
Pull Guard checks your app
Guard calls an address in your app on a schedule and checks the answer: a page, an API response, a word that must appear, a flow of a few steps.
Good for: Pages, APIs, sign-in and checkout flows, subdomains
Ping Your app pings Guard
Your job or app calls its own private ping address when something happens. A ping that does not arrive on time is the alert.
Good for: Cron jobs, backups, syncs, queues, emails the system sends
Probe Signed probe in your app
A small endpoint your AI adds to your app. Guard asks it with a signed request; it runs read-only checks inside your app and answers with a signed OK or not OK plus numbers.
Good for: Databases, internal services, keys to outside providers, business numbers
Provider Read-only provider connection
A one-click, read-only connection to a provider you already use, such as your payments, database or code host. Guard reads health and numbers; it cannot change anything.
Good for: Payments, database platforms, code hosting, AI providers
A signed check that runs inside your app.
One address in your app, such as /api/guard-probe, added by your AI from the probe kit for your stack: Next.js, Supabase Edge Functions, Express or Python.
- Signed requests only. It answers only a request signed (HMAC) with your app's own key, refuses anything unsigned, altered or stale, and signs its answer the same way. You can replace the key in one click.
- Read-only checks you approved. It uses the connection your app already has and runs only read-only checks you confirmed. The queries live in your code, not with 7IT.
- Status and numbers, never rows. The answer holds a status and numbers. Never rows, never user data, never secrets. Its size and shape are limited.
- Rate-limited. It limits how often it can be asked.
- An open format. The answer follows the shape of the IETF draft "Health Check Response Format for HTTP APIs": an overall status of
pass,warnorfail, and checks namedcomponent:measurementwith an observed value and unit.
An answer, with sample values
HTTP/1.1 200 OK
Content-Type: application/health+json
{
"status": "pass",
"checks": {
"database:responseTime": [
{ "observedValue": 41, "observedUnit": "ms", "status": "pass" }
],
"orders:lastCreatedAge": [
{ "observedValue": 37, "observedUnit": "min", "status": "pass" }
],
"jobs:queueDepth": [
{ "observedValue": 3, "observedUnit": "jobs", "status": "pass" }
]
}
}For jobs that should report in.
Each ping sensor has its own private address that cannot be guessed. A ping that does not arrive on time is the alert.
- <ping-url>
- Success: the job ran.
- <ping-url>/start
- The job started. Guard measures how long it runs and notices a job that started and never finished within your limit.
- <ping-url>/fail
- The job failed.
- <ping-url>/<exit code>
- The job's exit code: 0 is success, anything else is a failure.
- Grace
- How long after the expected time Guard waits before it alerts. You set it; Guard suggests it from the job's own history.
In a scheduled job
# the job started
curl -fsS -m 10 <ping-url>/start
# the job ran: report its exit code (0 is success)
./nightly-email.sh
curl -fsS -m 10 <ping-url>/<exit code>The address can be replaced in one click. Incoming pings are rate-limited.
The tools your AI uses.
New tools on the 7IT Guard MCP server, also available as a regular API with your 7IT key.
- propose_sensors
- Takes what you want watched, in words, and the app. Returns a proposed list of sensors in a fixed shape. Saves nothing.
- get_probe_snippet
- Returns a short probe endpoint for your stack (Next.js, Supabase Edge Functions, Express, Python) and the app's own signing key, for your AI to add to the code.
- add_sensor
- Registers one sensor, only after you confirm it in the chat. Marked as a tool that changes state.
- test_sensor
- Runs the sensor once and shows what it will report when it watches.
- list_sensors, sensor_status
- What is watched, and how each sensor stands right now.
- pause_sensor, remove_sensor
- Pause or remove a sensor.
Rules that always hold
- Your yes, every time. Your AI never registers or changes a sensor without your explicit confirmation in the chat.
- Paused until proven. A new sensor starts paused and turns on when its first check passes.
- Only your app. A sensor aimed outside an app whose ownership was proven, and its subdomains, is refused. Outside APIs, such as your payment provider, are checked through your own probe, not directly.
- No secrets in settings. A sensor setting that looks like a key or a password is refused when it is registered.
- Edit without AI. Pausing, renaming and removing a sensor also work from a simple screen in the control room. Adding one always goes through your AI, because it adds the code to your app.
This page describes what sensors do and how they connect. How Guard decides when to alert stays internal.
Custom sensors open with Guard Pro.
Part of Guard Pro and Pro + personal guidance. Prices are published when it opens.