Oten Access terms, explained by their role in the system.
Search Zero Trust policy, identity and enrollment, encrypted connectivity, Gateway topology, and security operations terminology. Each definition states what the term means inside Oten Access and what it must not be confused with.
34 terms
Zero Trust & Policy
Access Policy
Also: authorization policy, resource policy
A versioned rule that maps subject, device, resource, and conditions to an action.
Oten evaluates WHO × DEVICE × RESOURCE × CONDITIONS × CURRENT SESSION to produce bounded authority and required enforcement behavior.
Evidence about platform or device state that can be verified by another party.
Claims are platform-specific. Hardware-backed storage or platform evidence does not by itself prove that enrollment was authorized or the device is currently compliant.
A versioned, signed desired-state artifact for Gateway listeners, routes, policy references, and operational settings.
Profiles are assigned to Data Plane Groups, staged and verified by nodes, then reported as active only after successful activation and health confirmation.
The recorded result showing whether intended enforcement took effect and what access state followed.
A distributed decision is not complete merely because it was issued. Required enforcement points report applied, limited, failed, pending, or unknown outcomes for the relevant policy version.
A closed evidence-to-enforcement system in which access remains bounded and revocable.
Qualified evidence drives a decision, bounded authority, Endpoint and Gateway enforcement, confirmation, and evidence-based recovery. A revoke command without acknowledgement does not close the loop.
A set of Gateway nodes assigned the same Configuration Profile and rollout policy.
The group is a configuration and rollout boundary. Group membership does not automatically create takeover authority; eligible Failover Set members are selected explicitly.
The explicit, versioned state that a component is expected to apply.
The Oten Access Control Plane distributes desired state. Local components validate, apply, and confirm it according to their authority and continuity boundaries.
A distinct cryptographic and organizational identity assigned to an enrolled device or server.
Device identity remains separate from user identity and posture freshness. Hardware-backed storage is claimed only where platform evidence supports it.
Distinction: User identity; Setup Key; Posture state
An explicit set of compatible Gateway nodes permitted to take over for one another.
Membership, health criteria, priority, failure domain, configuration compatibility, fencing, and session behavior are explicit. Deployment or group membership alone does not create takeover authority.
The policy-bounded period during which evidence or state remains acceptable for a named decision.
Freshness is evaluated for a specific evidence source, resource policy, and system state. Stale evidence remains distinct from failed or missing evidence.
An explanatory aggregate of qualified posture and risk signals.
Health Score can inform policy and trends but cannot override mandatory gates such as revoked identity, invalid signature, expired authority, or a critical verdict.
A bounded secret used to bootstrap enrollment for a headless or server node.
The enrolled node receives a distinct identity and key. Revoking a Setup Key blocks new enrollment but does not automatically revoke existing nodes unless an explicit action does so.
Distinction: Device identity; Long-term server credential
A protocol for encrypted network tunnels between authenticated peers.
WireGuard protects the Oten data path. Resource authorization, device trust, route scope, and continuous decisions come from the surrounding Oten policy and enforcement model.