Scope Hierarchy
SentinelOne uses a hierarchical structure to organize and manage your deployment.
Global → Account → Site → Group → Endpoint
Global
The Global scope represents the entire SentinelOne deployment.
Users with Global access can manage all Accounts, Sites, Groups, policies, and settings across the environment.
Account
An Account is a logical segment within a deployment.
Accounts are commonly used to separate business units, customers, departments, or managed environments.
Each Account:
- Can contain multiple Sites.
- Inherits settings from the Global level.
- Can have its own policies and configurations.
Multiple Accounts require the appropriate SentinelOne licensing.
Site
A Site is a physical or logical segment within an Account.
Examples include:
- Offices
- Departments
- Geographic regions
- Business units
Each Site:
- Belongs to a single Account.
- Has its own settings and policies.
- Contains one or more Groups.
- Receives licenses from its parent Account.
All SentinelOne Agents are assigned to a specific Site.
Group
Groups are logical collections of endpoints inside a Site.
Groups help organize devices and apply specific policies, exclusions, and configurations.
Groups do not control licensing or user permissions.
Types of Groups
Manual Groups
Endpoints are manually assigned to the Group.
Devices remain in the Group unless they are moved manually or match a Dynamic Group rule.
Dynamic Groups
Endpoints are automatically assigned based on filters and conditions.
For example:
- Operating System
- Device Name
- Domain
- Tags
- Agent Version
If an endpoint matches a Dynamic Group rule, it is automatically moved into that Group.
Pinned Groups
Pinned Groups override Dynamic Group assignments.
Endpoints assigned to a Pinned Group remain in that Group even if they match Dynamic Group criteria.
Accounts
Accounts are useful when different teams or administrators manage separate environments.
Each Account:
- Has its own license allocation.
- Has its own expiration date.
- Can contain multiple Sites.
- Can inherit settings from Global scope.
Account names must be unique within the deployment.
Sites
Sites represent individual environments within an Account.
Each Site:
- Belongs to only one Account.
- Has its own settings and policies.
- Receives licenses from the parent Account.
- Contains one or more Groups.
Site names must be unique within the same Account.
The same Site name can exist in different Accounts.
For example:
- Account A → IT
- Account B → IT
Licenses
Licenses are assigned at the Account level and distributed to Sites.
Each active Agent consumes a license.
An Agent is considered active if it has not been uninstalled or decommissioned.
Available license types depend on your SentinelOne subscription.
Examples include:
- Core
- Control
- Complete
- Mobile
- Add-on modules
If a Site is deleted, its licenses are automatically returned to the parent Account.
License deployment must match the purchased SKU. For example, workstation licenses should not be deployed to server environments.
View Sites in an Account
- Select an Account.
- Open Settings.
- Select Sites.
You can view:
- Site names
- License usage
- Total licenses
- Creation date
- Expiration date
View Site Details
- Select a Site.
- Open Sentinels.
- Select Site Info.
You can view:
- Site Token
- Site ID
- License allocation
- Creation date
- Expiration date
View Accounts
- 1. Select Global scope or a multi-account view.
- 2. Open Settings.
- 3. Select Accounts.
You can view:
- Account names
- License usage
- Creation date
- Expiration date
Site Expiration
When a Site expires:
- Endpoints remain assigned to the Site.
- Alerts are no longer shown in the console.
- Protection policies are reduced to detection mode.
- Agents continue communicating with the Management Console at reduced intervals.
If the Site is reactivated, it can take up to 60 minutes for Agents to resume normal communication.
To avoid unexpected license usage, regularly review inactive devices and configure automatic decommissioning where appropriate.