Third-party maintenance

Complete the maintenance. Close the session boundary.

A third-party maintenance workflow begins with the required system state and defines the worker, approver, application, target, controls, crossings, duration, evidence, and closeout.

Review the workflow

Direct answer

Give the technician the named protected-system session.

The workflow presents the approved service application and target for a defined maintenance window. It evaluates interaction controls, transfer paths, target changes, closeout, and evidence without making standing network access or reusable general-purpose credentials the default task boundary.

  • Illustrative workflow pattern, not customer evidence or a product demonstration.
  • Primary SautX fit: Secure Workspace.
  • Identity, endpoint, network, target permission, and customer operating controls retain their own responsibilities.

Workflow definition

Define the session before the technician enters.

Required result
Complete approved maintenance during a defined window and return the named system to the required state.
Actors
Approved third-party technician, customer approver, and responsible protected-system owner.
Selected capability
Named service application and target, approved interaction controls, explicit transfer paths, and bounded duration.
Authority to avoid
Standing VPN access, reusable general-purpose accounts, broad network reach, and open-ended file movement.
Crossings
Identity route, clipboard, upload, download, credential use, target changes, and session closeout.
Evidence
Request, approver, route, target, granted capabilities, material actions, crossings, session bounds, and outcome.

Evaluation questions

Check the route, controls, and closeout.

01Was the worker approved for this task, application, target, and time window?

02Which view, control, clipboard, upload, download, credential, and recording capabilities were available?

03Which material actions and file movements crossed the session boundary?

04Was the intended system state restored and the session explicitly closed?

Sources and context

Primary sources used.

These sources support the problem framing and practitioner context. They do not endorse SautX or verify a SautX product claim.

  1. CISAGuide to Securing Remote Access Software
  2. NISTZero Trust Architecture (SP 800-207)
  3. NIST NCCoEImplementing a Zero Trust Architecture (SP 1800-35)

Start with the work

Bring one maintenance task. Define the session it should require.

Share only non-sensitive context about the result, technician, approver, application, target, controls, crossings, duration, evidence, and standing access to avoid.

Contact SautX