Oten Access

DEVOPS PRODUCTION ACCESS

Replace standing production privilege with bounded, attributable authority.

Scope infrastructure access by person, qualified device, resource, role, protocol, approval, and time, then correlate the resulting session evidence.

System role: Customer solution owner + Oten solution architecture

Evaluation depends on: Requires a bounded component, platform, protocol, integration, migration, rollback, and evidence scope.

The Access Control Plane makes policy decisions; Oten Endpoint and Oten Gateway enforce at opposite sides; Signal coordinates paths and Relay only forwards encrypted fallback traffic.

Start with the operating failure, not a feature list.

Who this is for

Platform, SRE, database, Kubernetes, and infrastructure teams that reach production through standing accounts, shared keys, bastions, or chat-based approval.

The problem today

Long-lived credentials and always-on roles remain useful after the original task or approval has ended.

Operational consequence

A leaked key or compromised endpoint creates durable blast radius, while logs cannot reliably connect request, approver, device, credential, and session outcome.

Desired outcome

JIT authority is issued for the approved resource, role, protocol, and time from a device that satisfies the resource's current policy.

Decision boundary

Define the subject, device, resource, protocol, policy version, enforcement points, confirmation requirement, and recovery owner.

The Oten journey stays connected from evidence to outcome.

  1. Request

    Select the resource, role, reason, protocol, and duration.

  2. Approve

    Apply separation of duty, expiry, identity assurance, and device requirements.

  3. Issue

    Create protocol-appropriate short-lived authority without exposing a standing secret where supported.

  4. Connect

    Enforce at the Endpoint and Gateway or protocol boundary.

  5. Review

    Correlate request, approval, policy, credential, session, outcome, and expiry.

Components and integrations retain distinct authority.

Required Oten components

Oten Endpoint, Access Control Plane, Oten Gateway with the required protocol handler, identity services, and credential or certificate integration.

Required integrations

Identity provider, approval or ITSM system, certificate authority or vault, SSH, databases, Kubernetes, RDP or web administration, and audit storage.

Known limitation

Credential issue, injection, renewal, recording, revoke, and active-session termination differ by protocol and connection mode.

Migration preserves a tested way back.

  1. Inventory standing access

    Map accounts, keys, roles, bastions, resource owners, and emergency paths.

  2. Introduce JIT beside existing access

    Pilot a resource and protocol without removing the recovery path.

  3. Shorten and remove standing authority

    Rotate credentials and reduce role lifetime after the JIT path is proven.

  4. Drill emergency access

    Test stronger authentication, notification, audit, expiry, and post-event review.

Use the evaluation to collect proof, not impressions.

  • Request and separation-of-duty approval.
  • Device failure at production policy.
  • Short-lived credential scope and expiry.
  • Protocol-specific revoke and session behavior.
  • Recording privacy and playback audit where used.
  • Break-glass drill, rollback, and post-event review.

Turn this journey into a bounded proof of concept.

Define success, limitation, failure, recovery, and rollback evidence before changing the production access boundary.