How XoT Works

← Back to start
Technology

How XoT Works

Step by step

How a secure session is established

1

Access defined by policy

Administrators define precisely who may access what, by which method, and for how long. No access exists without an explicit policy.

2

Authorised users connect

Access is scoped to the specific asset the user requires — nothing beyond it. Initiable from any location, inside or outside the network.

3

Both parties verified

The user and the asset endpoint are mutually verified before any data flows. Identity cannot be assumed or spoofed.

4

Only permitted traffic passes

The asset accepts only what policy explicitly allows. All other traffic is denied — the asset remains invisible to everything else.

5

Access expires per policy

Policies can expire automatically — by timer, schedule, or time window. No lingering access, no manual revocation required.

Request. Approve. Auto-revoke.

Access Request Portal

Users don’t need standing access — they can request it when the job requires it, and approvers stay in control of every grant.

1 · Request

The user browses available policies in a self-service portal and submits a request with a time window and a business justification.

2 · Approve

Designated approvers are notified by email and approve or reject the request — scoped so each approver only handles their own assets.

3 · Auto-revoke

Access activates at the start of the approved window and is automatically revoked at the end. The full request lifecycle is audit-logged.