Oten Access

OTEN ACCESS CONTROL PLANE

Compute access decisions without becoming the application path.

The Oten Access Control Plane combines identity, qualified device, resource, session, and versioned policy context. It computes access decisions, distributes desired state to enforcement points, and records permitted decision and outcome metadata. Application payload remains in the data plane.

System role: Policy Decision Point + desired-state manager

The Control Plane qualifies identity, device, resource, condition, and current-session context before issuing bounded authority to enforcement points.

Context, desired state, and evidence stay correlated.

Identity integration

OIDC or SAML federation, user and session context, authentication assurance, groups, roles, and entitlement mapping.

Device registry

Enrollment, identity, ownership, posture, freshness, trust state, quarantine, and revoke.

Resource registry

Applications, services, hosts, databases, clusters, routes, protocols, ports, and sensitivity metadata.

Policy

Versioned definition, separate assignment, validation, evaluation, impact preview, and decision cache behavior.

Configuration

Signed desired state, target groups, staged activation, rollout, last-known-good state, and rollback.

Connectivity coordination

Mesh address, DNS, route metadata, peer map, Signal, and Relay configuration without carrying application payloads.

Audit

Actor, subject, device, resource, action, reason, policy and configuration version, enforcement points, and outcome.

POLICY MENTAL MODEL

WHO × DEVICE × RESOURCE × CONDITIONS → ACTION

Resource-aware policy tuple

Definition remains versioned in the Policy Library. Assignment targets the relevant group or resource without mutating the shared definition.

Who

User, service identity, federated group, or Oten role with authentication assurance.

Device

Enrollment, device group, platform, posture, evidence freshness, and explicit trust state.

Resource

Application, service, host, database, cluster, network route, role, protocol, or method.

Conditions

Time, location, network, risk, step-up, approval, current session, and prior decision state.

Action

Allow, Deny, Restrict, Step-up, Require approval, Revoke, or Isolate within a defined scope and lifetime.

A decision record explains what was decided and where it was enforced.

Subject context

Timestamp, subject, optional actor and device, requested resource, and authentication assurance.

Decision context

Allow, Deny, Restrict, Step-up, or Revoke with policy-safe reason codes.

Policy context

Policy ID and immutable version, posture snapshot reference, resource scope, TTL, and re-evaluation triggers.

Enforcement context

Required Policy Enforcement Points, acknowledgements, failures, correlation ID, and final outcome.

Service-level and endpoint-local authority remain distinct.

Oten Access Control Plane

The service-level Policy Decision Point combines cross-system context, computes access decisions, and distributes versioned policy and desired state. It does not carry application payload.

Oten Endpoint Local Control Plane

ogc-core persists durable local intent, reconciles desired and last-known-good state, and coordinates endpoint-owned enforcement services. It does not make the complete service-level access decision.

Control availability and data-path availability are different states.

  • Healthy or operating with a degraded dependency.
  • Policy validation or compilation failed.
  • Configuration rollout partially applied or stopped.
  • Signal or Relay region degraded while existing direct paths may remain unaffected.
  • Audit sink delayed with bounded buffering and visible backpressure.
  • Signed last-known-good policy active within a bounded lease.
  • Break-glass authority active with stronger audit and post-event review.

FAQ

Questions security and platform teams ask first.

Is Oten IdP part of the Access Control Plane?

Oten IdP is an integrated identity platform that can provide user and session context. Its trust boundary remains distinct, and enterprise federation support must be published through a verified connector matrix.

Where is policy enforced?

The Policy Decision Point computes the decision in the Control Plane. Oten Endpoint, Oten Gateway, and integrated Policy Enforcement Points apply the action. Audit identifies where enforcement was requested and where it was confirmed.

Is it safe to edit a policy assigned to many groups?

Only with explicit shared-impact information, version change, affected targets and sessions, rollout behavior, and rollback. Definition and assignment are separate operations.

Connect policy intent to verifiable enforcement.

See the end-to-end flow from identity and device evidence to a bounded decision, enforcement acknowledgement, and audit correlation.