Oten Access

CAPABILITY DEPENDENCIES

Capabilities unlock in the dependency order of trust.

Deep enforcement depends on qualified identity, device evidence, policy integrity, and a reliable control path. This sequence explains technical dependency and evidence ownership; exact release scope comes from platform and protocol qualification.

  1. Sequence1

    DEPENDENCY 1

    Device Trusted

    Enroll, identify, manage, and evaluate the posture of each device before it becomes an access subject.

    • Shared Agent foundation and secure IPC
    • Device enrollment and inventory
    • Posture evidence and group policy
    • Role-based administration and audit
    • Health Score validation and reason model
  2. Sequence2

    DEPENDENCY 2

    Zero Trust Connectivity

    Connect trusted devices to authorized resources through an encrypted, identity-aware overlay.

    • WireGuard data plane and resource routing
    • Signal, STUN, and encrypted relay fallback
    • Internal DNS and default-deny resource policy
    • OIDC native-client enrollment with PKCE
    • Setup Key and Linux connect-only journey
    • Gateway foundation
  3. Sequence3

    DEPENDENCY 3

    Verified Access

    Enforce private application, infrastructure, and privileged access near the resource.

    • Identity-aware reverse proxy
    • Resource and route policy matrix
    • Signed Configuration Profile and group rollout
    • Explicit Data Plane Group and Failover Set topology
    • JIT certificates and brokered credentials
    • PAM server and Agent integration
  4. Sequence4

    DEPENDENCY 4

    Protected Endpoint

    Bring endpoint-security and data-protection evidence into the shared trust context.

    • Platform-native sensors and normalized telemetry
    • Detection, response, and guarded isolation
    • Application and local network controls
    • Endpoint data-in-use Policy Enforcement Point
    • Oten Guard and Oten Protector integration
  5. Sequence5

    DEPENDENCY 5

    Autonomous Defense

    Correlate cross-product evidence and execute bounded, recoverable response playbooks.

    • Cross-product correlation and investigation
    • Threat hunting and security evidence graph
    • Guarded SOAR and response playbooks
    • Closed-loop access, endpoint, and data response
    • Enforcement confirmation and evidence-based recovery

SECURITY EVIDENCE

External claims require evidence and an accountable owner.

Device Trust

Confirm platform-specific enrollment, identity, posture, remediation, and Health Score behavior.

Connectivity

Validate direct and relayed path behavior across NAT, firewall, capacity, route, DNS, and reconnect conditions.

Gateway

Validate route modes, signed rollout, node eligibility, fencing, explicit failover, and session behavior.

Active-session response

Publish behavior by network, HTTP, WebSocket, SSH, database, Kubernetes, and privileged-access mode.

Self-hosted operations

Publish install, upgrade, backup, restore, responsibility, support, availability, and residency boundaries.

Cryptography

Define algorithm negotiation, downgrade resistance, key lifecycle, interoperability, and scoped assurance evidence.

Use the Product Availability and Platform Support page to define the exact release and enforcement record. For term definitions, use the Technical Glossary.

Define the evaluation evidence for your required outcomes.

Map identity, device evidence, policy integrity, platform scope, protocol behavior, and confirmation requirements before rollout.