Operational consequence
The system that grants access can become the point that cannot revoke it, while backup, upgrade, and key-recovery responsibilities remain unowned.
SELF-HOSTED ZERO TRUST
Separate policy services, coordination services, durable state, keys, and distributed enforcement, then assign availability and recovery ownership for every dependency.
System role: Customer solution owner + Oten solution architecture
Evaluation depends on: Requires a bounded component, platform, protocol, integration, migration, rollback, and evidence scope.
Organizations that require customer-operated control services for sovereignty, data residency, contractual, or infrastructure reasons.
A self-hosted access system is treated as one container even though policy, state, keys, Signal, Relay, Gateway, identity, audit, and recovery fail differently.
The system that grants access can become the point that cannot revoke it, while backup, upgrade, and key-recovery responsibilities remain unowned.
Customer-operated services use explicit failure domains, durable state, key custody, observability, backup, restore, upgrade, rollback, and distributed Gateway boundaries.
Define the subject, device, resource, protocol, policy version, enforcement points, confirmation requirement, and recovery owner.
Map services, state, keys, traffic, trust boundaries, data regions, and owners.
Deploy redundant services and dependencies across the defined failure domains.
Connect identity, resources, audit, certificates, Signal, Relay, Endpoint, and Gateway.
Run backup, restore, upgrade, rollback, partial failure, lease expiry, and key-recovery scenarios.
Monitor capacity, health, security, drift, release compatibility, and incident actions.
Customer-operated Access Control Plane services, state, Signal, Relay, Oten Endpoint, Oten Gateway, and required supporting infrastructure.
Identity provider, database, cache or queue where required, KMS or HSM, certificates, load balancing, DNS, observability, backup, SIEM, and protected resources.
Customer operation changes the responsibility boundary; it does not remove the need for supported versions, tested recovery, capacity planning, or Oten component compatibility.
Deploy the full dependency and ownership model.
Prove state and key recovery into a clean environment.
Validate policy, Signal, Relay, direct paths, LKG, and audit.
Add regions and Failover Sets only after failure evidence passes.
Next in Oten Access
Define success, limitation, failure, recovery, and rollback evidence before changing the production access boundary.