Authorization and access enforcement

Vigilance Sentinel

Apply access rules against the entitlement in use.

Vigilance Sentinel extends NIVOMAX authorization with session validation, companion-license protection and rules across users, devices and publications. Administrators manage the rules in Axis.

For platform and security administrators, and customer data-license administrators responsible for technical-publication access.

Datasheet available upon requestRequest a datasheet

Authorization and access enforcement
  1. Axis records and rules
  2. Authorization decision
  3. Publication access
Conceptual workflow illustration.

Keep the access decision consistent across the installation.

Sentinel checks that a session still matches the entitlement under which access was granted. Platform components use that authorization decision model when evaluating access to licensed content.

Axis retains the administrative records for organizations, users, roles, data licenses and entitlements. Shared NIVOMAX identity services handle authentication. Sentinel adds the enforcement rules evaluated against those records.

Role
Additional authorization and enforcement
Administration
Axis
Coverage
Licensed applications and deliveries
Required by
FleetPass
Capabilities

What Vigilance Sentinel adds.

Session validation

Check active sessions against their assigned entitlement and control session behavior when the entitlement changes.

Companion-license protection

Restrict use to the pairing or secondary-license arrangement for which a companion license was issued.

Rule-based access

Evaluate organization, user, role, device, publication and entitlement information using the configured authorization policy.

Licensed boundaries

Let local rules narrow access within the installation’s signed profile. Rules cannot grant a capability the installation does not license.

Review before enforcement

Review and simulate the effective rule set before applying it. Authorization fails closed when the required access cannot be verified.

Working sequence

Define, review and apply the authorization policy.

  1. Define in Axis

    Express the organization’s rules against the users, roles, devices, publications and entitlements maintained by the platform.

  2. Review the decisions

    Check the effective rule set and simulate it before enforcement. Confirm intended access and restricted cases.

  3. Enforce consistently

    Apply the authorization decision at entitlement checks across the licensed applications and Horizon deliveries.

Before configuration

Give the rule set an owner and a review cycle.

  • Document the access policy in terms of organizations, roles, devices and publications.
  • Nominate administrators to own the effective rules and test changes.
  • Agree how the policy is reviewed as customer organizations and entitlements change.
Optional, separately licensed extension module

Add enforcement within the licensed installation.

Vigilance Sentinel is licensed separately. FleetPass requires it. The rules are administered in Axis and remain bounded by the installation’s licensed capabilities.

Offline devices receive applicable rules in their signed entitlement. Plan how changes reach devices as they reconnect; an offline device uses the signed information it already carries.

Questions

Frequently asked questions

Does Sentinel replace Axis or the identity provider?

Axis remains the administrative system of record, and shared identity services handle sign-in with the configured identity provider. Sentinel evaluates additional authorization rules.

Can a local rule enable an unlicensed capability?

Local rules can narrow access. They cannot extend access beyond the installation’s signed license profile.

Does Sentinel provide the access-evidence archive?

Sentinel decides whether access is allowed. Vigilance Watcher provides the separately licensed tamper-evident access and activity record.

Related modules

Continue exploring the workflow.

Review your technical-publication access policy.

Bring representative users, devices and entitlement cases, including the access you intend to restrict. We will review the decision model with you.