Control you can evidence — device by device.
Regulators and internal audit do not ask whether you have your endpoints under control, but what you use to prove it. octoja records access, change, approval and patch level as a continuous body of evidence.
- Every privileged access is documented — including the justification
- Permissions end where the task ends
- Point-in-time reports instead of reconstructed answers
permissions individually assignable
device actions separately permissioned
security checks
of administrative interventions logged
Sound familiar?
As long as nobody asks, it goes unnoticed. The question comes anyway — usually with a deadline.
Permissions have grown organically — nobody can explain them any more.
Who accessed a workstation remotely, and when, cannot be evidenced cleanly.
Encryption is mandatory, yet the evidence is still missing.
External service providers work alongside you, but outside your logs.
Every audit question turns into a special analysis.
Internal audit is reviewing privileged access. The question: which individuals accessed workstations in payment processing last quarter, under what permission — and was the affected person informed?
The access overview shows, per device, which groups have access and which rule grants it. The device log lists every session with person, time and action. Where consent was overridden, the recorded justification sits alongside it — without a dedicated permission it would not have been possible at all.
The patch compliance report evidences the position as at the reporting date, and the audit log evidences the changes to policies and groups. No collecting things together.
Evidence as a design principle
Not logging bolted on after the fact, but a model that cannot be circumvented.
Logging with no back door
Entries are created as a side effect of processing, with user and time set by the framework — not by application code on a case-by-case basis.
Who sees what — and why
Access in two stages: first the tenant, then the device, refined by 17 action permissions. The justification chain can be traced at any time.
Remote access with consent
Enforceable centrally. Overriding it requires a dedicated permission and a logged justification. The screen locks automatically when the session ends.
Strong authentication
Two-factor authentication via TOTP, enforceable in the SSO flow as well. OpenID Connect with PKCE, passwords hashed with BCrypt, secrets never readable via the API.
Integrity monitoring
Baselines for directory permissions, files and the registry report deviations. Open SMB shares are surfaced along with their permissions.
Approvals with a decision-maker
Patch cycles carry the approval type, decision-maker, timestamp and a note — manual, automatic, promoted or emergency.
And that is not all
- A dedicated instance instead of a shared tenant database
- User audit and SLA report as PDF
- Signed webhooks with HMAC
- Checks for default administrator accounts
- Certificate expiry with advance warning
- Account audit across Windows, Linux and macOS
The permission and evidence model is hard to convey in writing. Against your structure, it is not.
Get trial accessThe alert lands where your team already works.
An alert is only worth something once it reaches the right person at the right time — and closes itself again when the problem has gone.
Ticketing systems & PSA
Alerts raise a ticket where your team already works — and close it again on all-clear. Customer records can be imported.
- DocBee
- TANSS
- TOPdesk
- c-entron Service-Board
- HaloPSA
- Autotask
- Jira Service Management
- Freshservice
- Inserve
- Odoo Helpdesk
- Codemeta
Alerting
Separate service hours per channel. Into the ticketing system during the day, by phone call to the on-call engineer at night — alerts outside those hours are held back, not discarded.
- Microsoft Teams
- Signierte Webhooks
- SMS
- Sprachanruf
- App-Push
- Internes Ticket
Documentation & ITAM
The device estate is mirrored into your existing documentation rather than creating a second register.
- Hudu
- IT Glue
- woasi
- Jira Assets
Antivirus, EDR & vulnerabilities
Protection status and vulnerabilities come together in the same view as the rest of the estate — regardless of whose security software the customer runs.
- Microsoft Defender
- Bitdefender GravityZone
- SentinelOne
- CrowdStrike Falcon
- Sophos
- ESET
- G DATA
- Securepoint Antivirus Pro
- ThreatDown (Malwarebytes)
- Lywand Schwachstellenaudit
Backup — monitored across vendors
Firewalls & appliances
Hardware, storage and network without an agent
Server workloads
Requirements and matching evidence
octoja holds no certification and does not replace an audit. The platform supplies the technical evidence these requirements rely on.
DORA
Management of ICT and third-party risk
Separate access profiles for external service providers, a log of every intervention, availability and incident reports.
BAIT / VAIT
Authorisation management and traceability
Two-stage access model with a justification chain, 26 logged object types, user audit report.
NIS2
Vulnerability handling and patch process
Documented patch cycles with approval, exclusion lists and success rates per ring.
GDPR Art. 32
Evidence of technical measures
Encryption status per drive, account audit, password policy checks, access logs.
Would something else suit you better?
Put your audit question to us
In the meeting we will show you which report and which log answers it — using real data from a trial instance.