Bulk operations
Sentinel::model(Invoice::class) returns a ModelSeals handle that works on every row of a model. A query over another model class is refused (SealingMisconfiguredException::queryModelMismatch).
$seals = Sentinel::model(Invoice::class);
$seals->scan(); // ScanReport: counts per status + findings
$seals->scan(where: fn ($query) => $query->where('tenant_id', 7)); // only these rows, chunked
$seals->scan(progress: fn (int $rows) => $bar->setProgress($rows)); // after every chunk
$seals->sealMissing(reason: 'Initial baseline'); // adopt rows that were never sealed
$seals->reseal(); // re-seal intact rows with the current key
$seals->reseal(acknowledgeReason: 'INC-90'); // …and acknowledge the others
$seals->resealWhere(fn ($query) => $query->where('status', 'draft'), reason: 'INC-91', actor: $admin);
$seals->updateAndReseal(
fn ($query) => $query->where('status', 'draft'), ['currency' => 'EUR'], reason: 'FIN-12 currency migration', actor: $admin,
);
$seals->unsealedQuery()->count(); // rows without a seal row
$seals->seals(); // ['financial', 'identity']Flat forms
The flat forms take option objects, which also carry what the handle does not — checkSchema on a scan, upgradeFormat on a re-seal:
use RoundlyConsulting\Sentinel\DataTransferObjects\BaselineOptions;
use RoundlyConsulting\Sentinel\DataTransferObjects\ResealOptions;
use RoundlyConsulting\Sentinel\DataTransferObjects\ResealWhereRequest;
use RoundlyConsulting\Sentinel\DataTransferObjects\ScanOptions;
use RoundlyConsulting\Sentinel\DataTransferObjects\UpdateAndResealRequest;
Sentinel::scan(new ScanOptions([Invoice::class], seal: 'financial', limit: 10_000, checkSchema: true));
Sentinel::reseal(new ResealOptions(Invoice::class, onlyOutdated: true));
Sentinel::reseal(new ResealOptions(Invoice::class, upgradeFormat: true)); // rows of an older canonical format
Sentinel::resealWhere(new ResealWhereRequest(Invoice::class, fn ($query) => $query->where('tenant_id', 7), 'INC-91', $admin));
Sentinel::updateAndReseal(new UpdateAndResealRequest(Invoice::class, fn ($query) => $query->where('status', 'draft'), ['currency' => 'EUR'], 'FIN-12', $admin));
Sentinel::sealMissing(new BaselineOptions(Invoice::class, null, 'Initial baseline'));Re-sealing never launders
reseal() (and sentinel:reseal) re-verifies each row under its row lock and re-seals only Intact or Outdated rows (event rotated). Rows already sealed by the current key with the current definition are left alone. Every other status is skipped and reported — unless an acknowledgement reason is given, in which case each is acknowledged with the reason and actor recorded. A row that cannot be sealed counts as failed; a refusal by the acknowledgement policy stops the run. ResealReport has resealed, acknowledged, skipped, failed, skippedResults (up to 1 000) and dryRun.
Deliberate mass updates
updateAndReseal() first verifies every selected row in a read-only pass — any row that is not intact throws TamperedModelException::many() and nothing is written. Then, per chunk (500 by default) in one transaction, it locks the rows, verifies again under the lock (a row tampered in between still refuses the batch, a row deleted in between is skipped), runs the query-builder update($values) and re-seals each row with the reason.
Baselines
sealMissing() (and sentinel:seal-missing --reason=…) seals rows with no seal row and no ledger history (event baseline, reason required). Rows with history but no seal row are reported as seal_deleted, never baselined — a deleted seal is evidence.
A scan’s where is a closure receiving the model’s query (global scopes off, as for the whole table) or a builder of that model; it filters, never orders. reseal() and sealMissing() take a progress callback too, and the long commands show a progress bar on a terminal.
Show your open-source love
This package is free and MIT-licensed. If it saves you time, a one-off donation or a Patreon membership keeps it maintained, tested and documented.
More ways to support, including cryptoBy donating, you agree to our donation terms.
Want this built into your product?
We integrate our packages into custom Laravel and AI builds. Tell us what you're working on and we'll reply within 48 hours.