Systems & ownership
Which systems report, who owns them and which need attention.
Connection state, assigned policy and latest evidence by system.
Publish signed policies, see which systems have applied them, and investigate missing or mismatched evidence. Prepare policy and workstation evidence for compliance reviews. Enforcement stays in your environment.
Your team restricts a tool for a group of systems. Publishing the change does not tell you whether every system is using it. Cloud compares the expected assignment with each node’s evidence so you can find the systems that still need attention.
Define the protections and access for a group of systems. Cloud signs and publishes the release.
Desired stateThe node retrieves and verifies the policy, applies it locally and reports its state.
Reported stateCloud compares the expected assignment with returned evidence and surfaces differences.
Verified adoption| What Cloud shows | What it means | What your team does next |
|---|---|---|
| Not configured | What it meansA system has no policy assignment. | Next actionAssign the policy that matches its workflow. |
| Awaiting evidence | What it meansThe expected state has not been confirmed. | Next actionCheck enrollment, reporting and local application. |
| Needs review | What it meansEvidence is stale, different or unverified. | Next actionInspect the system and resolve the specific mismatch. |
| Verified | What it meansThe reported evidence matches the expected policy. | Next actionReview ongoing changes and evidence freshness. |
Move from a policy or alert to the system, owner and evidence behind it.
Which systems report, who owns them and which need attention.
Connection state, assigned policy and latest evidence by system.
Which policy should run, and which version was actually reported.
Signed releases, assignment, distribution and verification state.
Which agent clients, MCP tools and capabilities the nodes report.
Inventory tied to the reporting system and its available evidence.
Which held actions or changed tool descriptions need a decision.
Review the reported context, approve or reject, and follow the next sync.
What happened and whether the evidence supports the expected policy.
Trace decisions, inspect verification state and review policy reports.
Who can manage policy and resolve reviews.
Organization membership and role-based access to the console.
Cloud coordinates the rollout and review. Oktsec Node makes the local decision before a routed request reaches a tool.
The node initiates the connection: policy in, evidence out. No inbound control channel or remote shell.
Review the deployment architectureAn approved MCP tool can change its description or input schema. Cloud brings the reported change into review with its system and prior approved version.
The decision is bound to the reviewed content. The environment applies the approval on its next sync.
Retain the previously approved version and investigate the change with the team that owns the system.
Use the observations already collected by Node and organized in Cloud to prepare evidence for SOC 2, ISO 27001 and internal reviews. Give the reviewer a system, an owner, an observation time and a record to examine.
Review eight checks across enrolled workstations: seven host observations from Node and device ownership recorded in Cloud. Find failed and unobserved controls by system or group.
CSV · systems, owners, controls and observation datesReview coverage, policy state, exceptions, activity and change history for a selected group and period. Report sections include references to relevant SOC 2 and ISO 27001 controls.
Markdown · review periods of 30, 90, 180 or 365 daysExport recorded activity and administrative changes. Use a signed action-evidence bundle when the reviewer needs to verify node identity, signatures and the included action lifecycle.
CSV / JSON exports · independently verifiable action bundlesFor a broader handoff, an organization owner can also download a ZIP of systems, policies, members, alerts and audit/activity records, with a manifest identifying export limits.
Enable baseline reporting for the workstations in scope. Unsupported or unreadable checks remain unobserved; non-applicable systems are excluded. These eight checks are Oktsec’s workstation baseline, not the complete SOC 2 control set.
Export from Oktsec, select the records for the review period, and attach them to the relevant controls in your compliance platform or auditor workspace. Review file format, access and scope before sharing.
This is an export-and-upload workflow. Vanta and Drata support custom evidence uploads; a native Oktsec connector is not currently provided.
Oktsec provides supporting evidence. Your organization and auditor determine the applicable controls, sufficiency of evidence and audit outcome.
Agree on what must be applied and what evidence will demonstrate it. Measure the time to investigate an exception and prepare an evidence package against your current process, using the same scope.
Identify the workflow, owner, agent clients and tools in scope.
Agree on permitted actions, review cases and the policy to publish.
Check reporting, policy alignment and evidence; resolve gaps before expansion.
Cloud manages policy publication, system adoption, evidence and review across your organization. Oktsec Control applies the configured policy to routed agent requests locally. Cloud is outside the tool execution path.
No. Cloud distinguishes the desired policy from the state reported by each node. Adoption is checked against returned evidence. A missing, stale, different or unverified report requires review.
Central quarantine review includes credential-redacted message content. Step-up approval review includes full tool arguments. Routine activity and action-receipt exports use reduced metadata or hashes; agree on reviewer access and data handling before rollout.
Nodes initiate outbound connections to retrieve signed policy and send evidence. Cloud does not open a remote shell or execute commands on the node. Deployment requirements are agreed for the environments in scope.
Connected systems and their owners, policy releases and adoption, reported agent and tool inventory, held requests, changed tool descriptions, activity and policy reports. Available context depends on what each configured node reports.
Cloud organizes workstation baseline observations, policy reports and exportable activity. Reports reference relevant SOC 2 and ISO 27001 controls. Use exports in your auditor workspace or upload them as custom evidence to a compliance platform.
Yes. Start with one workflow and a defined group of systems. Agree on ownership, policy, connection requirements and evidence before expanding the rollout.
Bring a workflow, its owner and the actions you need to govern. Together we define the rollout, the evidence to review and what successful adoption looks like.