aegis-sentinel-suite=1.2.2-1
Provides the complete public AEGIS application cohort and coordinated local workflows.
AEGIS is a local-first assistance and integrity suite layered on SentinelOS. The base v1.0.18-2 conversion remains fully functional without it. This manual covers the complete public suite, not private AEGIS Prime or private R.E.P.O tooling.

The final public conversion defaults to no AEGIS runtime. This avoids making the assistant a dependency of the operating system. Install both the suite and its conditional theme from the signed repository:
sudo apt update
sudo apt install aegis-sentinel-suite=1.2.2-1 sentinelos-aegis-theme=1.0.1-1
sudo aegis-public-suite-verify --system
sudo aegis-public-suite-initialize-user USERNAME
sudo sentinelos-aegis-theme --verify
sudo sentinelos-aegis-theme-apply-user USERNAMEReplace USERNAME with the normal desktop account. Log out and back in after the theme is applied.
aegis-sentinel-suite=1.2.2-1Provides the complete public AEGIS application cohort and coordinated local workflows.
sentinelos-aegis-theme=1.0.1-1Provides the conditional navy, grey and gold visual identity. It should not be present on a base non-AEGIS machine.
Run the system verifier and resolve missing packages or ownership errors before creating data.
Create or select the local vault root, verify permissions and record where backups will be stored.
Initialise intake, quarantine, sanitised import, index, reports and backup locations for the signed-in user.
Use B.A.S.T.I.O.N before importing important material or changing A.R.C runtime settings.
Review suite health, component availability and any warning before beginning normal workflows.
Provides the public dashboard, state summary, package and repair-plan coordination, and the user-facing command layer. It is the first place to assess overall suite health.
sentinel-commandCreates, verifies, repairs or deliberately wipes the user vault structure. Destructive actions require explicit user confirmation.
aegis-vault-setupMoves material through intake, quarantine, sanitation, approval and import. It prevents unreviewed material from being treated as trusted vault content.
avicCalculates checksums, audits records, certifies known-good state and generates repair plans. It should report uncertainty rather than silently rewriting evidence.
scan-nodeSearches and retrieves authorised local records and handles deliberate archive or deletion workflows.
vault-terminalCreates snapshots, backup archives, integrity records and restore evidence for the public vault.
bastionControls approved AEGIS runtime settings and local model or service state. Change one setting at a time and keep a rollback point.
arc-controlPackage builds may expose additional aliases. Use command -v and the installed desktop entries to confirm the executable on the machine.
Applications and assistants should not receive vault, credential, document or automation access merely because they are installed.
Authorise the specific tool, data category and action. Separate read, write, execute, export and delete authority.
Stored secrets remain encrypted and outside public build outputs. AEGIS may use a selected secret only after the user grants that specific permission.
High-impact operations should show the target, scope and expected result before execution.
A model should receive the minimum necessary context, not a raw dump of the complete vault or credential store.
Permissions should be removable without breaking the underlying application or operating system.
Place new material in the intake area without treating it as trusted.
Keep it isolated while provenance, file type and security checks are reviewed.
Create a safe working copy where the workflow supports sanitation. Preserve evidence of the original separately when required.
The user approves the item, destination and metadata before it enters trusted storage.
S.C.A.N records a digest and V.A.U.L.T makes the item discoverable under approved permissions.
B.A.S.T.I.O.N creates a verified recovery copy after meaningful changes.
Use A.V.I.C for intake and quarantine, review the result, approve import, run S.C.A.N to record the checksum, confirm lookup in V.A.U.L.T and create a B.A.S.T.I.O.N backup.
Search from Sentinel Command or V.A.U.L.T, confirm source and trust state, then open only the authorised result. Missing provenance should remain visible.
Read the summary in Sentinel Command, open S.C.A.N for evidence, review the repair plan, back up, then apply only the targeted correction.
Create a snapshot, record the current state, change one A.R.C setting, test suite health and roll back immediately if behaviour becomes unclear.
Use V.A.U.L.T, verify the selected item and dependencies, create a backup, then authorise archive or deletion explicitly.
Select the exact credential in Password Vault, grant the approved application a bounded use permission, complete the local action and revoke unnecessary access afterward.
Create a snapshot before bulk import, cleanup, repair, archive, delete or A.R.C changes.
Verify the archive and checksum record. Keep at least one copy away from the main vault location.
Confirm target, date and digest. Restore into a safe location first when practical, then compare before replacing working data.
Confirm the exact AEGIS suite and theme packages are installed.
Use the system verifier to identify missing components or ownership errors.
Read component status and the proposed repair plan.
Protect the last known working state before repair.
Correct the specific package, permission, index or runtime fault.
Run package, suite, theme and vault checks again and preserve the result.
aegis-public-suite-verify --systemVerify the complete public suite at system scope.sudo aegis-public-suite-initialize-user USERNAMEInitialise package-owned user integration for the target account.sentinelos-aegis-theme --verifyVerify the conditional AEGIS theme package.sudo sentinelos-aegis-theme-apply-user USERNAMEApply the AEGIS visual baseline to the selected user.dpkg-query -W aegis-sentinel-suite sentinelos-aegis-themeShow installed package versions.command -v sentinel-repoShould return nothing on the public system because private R.E.P.O is forbidden.Verify the backup before package removal.
Remove application permissions and lock credential access.
Apply the base GTK, Marco, icon and cursor themes before removing the AEGIS theme package.
Review the apt transaction and do not allow unrelated user data or SentinelOS base packages to be removed.
Run the SentinelOS release and drift audits after removal.
Verify aegis-sentinel-suite. A base system should not retain the conditional theme without the complete suite.
Check the package version and desktop file. Reinstall the owning signed package rather than creating unmanaged aliases.
Confirm the signed-in account, vault ownership and package initialisation. Do not solve a user-vault problem by running the desktop application as root.
Preserve both copies, stop import or restore, confirm the expected digest and investigate storage or modification history before trusting either file.
Confirm the import completed, the item is in an authorised location and S.C.A.N recorded the expected metadata before rebuilding only the affected index.
Restore the previous setting or snapshot, verify suite health and document the failed change before attempting another configuration.