Experience and status
Presents current trust state, available resources, remediation, policy version, local enforcement status, and degraded or recovery conditions.
OTEN ENDPOINT
Oten Endpoint observes relevant device signals, qualifies posture for policy use, maintains durable local state through ogc-core, and coordinates source-side enforcement services for access and endpoint protection.
System role: Endpoint-side Policy Enforcement Point
ENDPOINT LOCAL AUTHORITY
Oten Endpoint separates the product experience, the durable Oten Endpoint Local Control Plane, and endpoint-owned enforcement services. Shared context does not flatten their authority boundaries.
Presents current trust state, available resources, remediation, policy version, local enforcement status, and degraded or recovery conditions.
ogc-core owns durable local intent, desired-state reconciliation, last-known-good state, and coordination of endpoint enforcement services.
Separately supervised processes apply network, posture, and security actions using native operating-system controls for their defined scope.
DEVICE EVIDENCE PIPELINE
Oten distinguishes observation from qualified posture. Source, freshness, relevance, device binding, policy version, and missing or conflicting state determine whether evidence can enter an access decision.
A named endpoint source reports a value with an observation time and device binding. Observation alone does not produce a permitted state.
Evidence is evaluated for source, freshness, relevance, conflicts, and current system state before policy can use it.
Use derived or qualified context where possible so policy receives the minimum information required for the named decision.
Enrollment, device identity, posture, group policy, resource-aware trust, and explainable Health Score inputs.
Explore Device Trust →Encrypted overlay, internal DNS, resource routes, direct and relayed paths, and an explicit VPN mode where needed.
Explore connectivity →Platform-native telemetry, common event schema, detection, and guarded access response.
Explore Endpoint Defense →Endpoint data-in-use controls for supported channels, coordinated with Oten Protector policy.
Explore Data Protection →Device-trust-gated credential brokering and JIT privilege for supported operating systems and workflows.
Explore Privileged Access →LAYER 01
Trust state, available resources, remediation, access requests, approval, and transparent offline or failure status.
LAYER 02
Authenticated local control, least-privilege method surfaces, authorization per method, and an explicit event contract.
LAYER 03
ogc-core maintains local desired state, last-known-good state, reconciliation, module health, update, audit, and telemetry coordination.
LAYER 04
Connectivity, Device Trust, Endpoint Defense, Data Protection, and PAM logic with separate authority boundaries.
LAYER 05
macOS ESF and Network Extension, Windows ETW/WFP/minifilter, and Linux eBPF/LSM/TUN where required.
LAYER 06
Secure Enclave, TPM, Keychain, DPAPI, keyring, code signing, system services, and platform update trust.
Install signed software through an approved distribution and update channel.
Bind the device to the organization and a distinct device identity.
Receive signed policy, observe posture, and expose evidence freshness and reasons.
Apply resource policy, local controls, and bounded cached authority.
Update with signature verification, staged activation, health checks, and recoverable rollback.
Preserve approved management paths while explaining blocked resources and remediation.
Invalidate the device authority and record the final state independently from enrollment credentials.
FAQ
It can if module privilege, IPC, policy, signing, update, and rollback boundaries are vague. Oten uses a shared core to reduce duplication, but the architecture must keep module authority and platform-specific enforcement explicit.
No. Headless Linux journeys prioritize Setup Key bootstrap, service lifecycle, resource connectivity, and server-appropriate posture. Interactive desktop UI and browser-based enrollment are not defaults for every server node.
The Agent may use signed, versioned cached policy within a bounded lease. Critical resources can fail closed when trust or policy expires. The user experience must show the last successful sync, expiry, and current enforcement state.
Next in Oten Access
Understand enrollment, evidence quality, trust state, and the endpoint-side enforcement boundary before adding deeper security modules.