Identity integration
OIDC or SAML federation, user and session context, authentication assurance, groups, roles, and entitlement mapping.
OTEN ACCESS CONTROL PLANE
The Oten Access Control Plane combines identity, qualified device, resource, session, and versioned policy context. It computes access decisions, distributes desired state to enforcement points, and records permitted decision and outcome metadata. Application payload remains in the data plane.
System role: Policy Decision Point + desired-state manager
OIDC or SAML federation, user and session context, authentication assurance, groups, roles, and entitlement mapping.
Enrollment, identity, ownership, posture, freshness, trust state, quarantine, and revoke.
Applications, services, hosts, databases, clusters, routes, protocols, ports, and sensitivity metadata.
Versioned definition, separate assignment, validation, evaluation, impact preview, and decision cache behavior.
Signed desired state, target groups, staged activation, rollout, last-known-good state, and rollback.
Mesh address, DNS, route metadata, peer map, Signal, and Relay configuration without carrying application payloads.
Actor, subject, device, resource, action, reason, policy and configuration version, enforcement points, and outcome.
POLICY MENTAL MODEL
Resource-aware policy tuple
User, service identity, federated group, or Oten role with authentication assurance.
Enrollment, device group, platform, posture, evidence freshness, and explicit trust state.
Application, service, host, database, cluster, network route, role, protocol, or method.
Time, location, network, risk, step-up, approval, current session, and prior decision state.
Allow, Deny, Restrict, Step-up, Require approval, Revoke, or Isolate within a defined scope and lifetime.
Timestamp, subject, optional actor and device, requested resource, and authentication assurance.
Allow, Deny, Restrict, Step-up, or Revoke with policy-safe reason codes.
Policy ID and immutable version, posture snapshot reference, resource scope, TTL, and re-evaluation triggers.
Required Policy Enforcement Points, acknowledgements, failures, correlation ID, and final outcome.
FAQ
Oten IdP is an integrated identity platform that can provide user and session context. Its trust boundary remains distinct, and enterprise federation support must be published through a verified connector matrix.
The Policy Decision Point computes the decision in the Control Plane. Oten Endpoint, Oten Gateway, and integrated Policy Enforcement Points apply the action. Audit identifies where enforcement was requested and where it was confirmed.
Next in Oten Access
See the end-to-end flow from identity and device evidence to a bounded decision, enforcement acknowledgement, and audit correlation.