Security through explicit boundaries

Protect identity, credentials and infrastructure changes at every layer.

IntelliconOps combines scoped access, encrypted multi-cloud credentials, controlled OpenTofu execution, private workload connectivity and connected audit evidence within a customer-selected deployment boundary.

Discuss your security requirements
Customer environment
Identity and permissionsRoles · group scope · elevation · API tokens
IntelliconOps control planeApprovals · policy · jobs · audit · inventory
Private execution workerPython · Ansible · OpenTofu · redacted output
AWSMicrosoft AzureGoogle Cloud

Implemented security controls

Defence in depth from sign-in to cloud outcome.

Scoped identity

Role permissions and VM group membership decide which platform actions and resource contexts a user can reach.

Encrypted credentials

AWS, Azure and Google Cloud credential payloads are encrypted by the application and hidden from serialised models.

Reviewed execution

Blueprint publication and OpenTofu saved-plan approval create visible decision points before infrastructure changes.

Protected IaC artifacts

OpenTofu plans and state remain encrypted, while browser views receive parsed and sanitised projections.

Private guest access

Guided WireGuard paths reach private workloads across AWS, Azure and Google Cloud for SSH and Ansible.

Connected audit evidence

Requests, permission changes, approvals, rejections, execution events and managed outcomes retain their context.

Identity and least privilege

Make standing access smaller and temporary access accountable.

Role and group permissions

Granular permissions control virtual machines, groups, jobs, cloud accounts, discovery, consoles, costs and Infrastructure as Code. Group membership adds the resource scope.

OIDC and local identity

Deployments can use OIDC sign-in and role synchronisation while retaining guarded local account workflows where required.

Just-in-time elevation

A user supplies a justification and requests a role for 15 minutes to 8 hours. A designated approver cannot approve their own request.

Automatic expiry and revocation

Approved elevation expires at its recorded time and can be revoked by the requester, an approver or an administrator.

Administrator safety invariant

Access-control changes are rejected if they would remove the final active user with durable full-platform administration.

Granular IaC authority

Do not treat OpenTofu access as one all-or-nothing switch.

iac.viewView deployments and execution history
iac.planCreate, validate and plan controlled deployments
iac.applyApprove and apply a valid saved plan
iac.destroyAuthorise plans that destroy or replace infrastructure
iac.importAdopt existing resources into managed state
iac.adminAdminister execution and state operations
These permissions can be assigned to match the customer’s separation-of-duties model; IntelliconOps does not claim that every deployment must use the same role design.

OpenTofu execution protection

Bind approval to one configuration and one saved plan.

IntelliconOps controls the complete route from module selection to managed-resource synchronisation rather than exposing a general-purpose shell or raw IaC artifacts to the browser.

1

Constrain

Use a versioned, allow-listed module and typed inputs rather than arbitrary uploaded HCL.

2

Identify

Bind the deployment configuration hash, saved-plan hash, parsed actions and expiry.

3

Authorise

Require apply permission and additional destroy permission for destructive or replacement actions.

4

Execute

Lock the deployment and apply the exact approved encrypted saved plan before it expires.

Worker boundary

Bounded commands and diagnostics

  • OpenTofu runs through one fixed command runner without invoking a shell
  • Sensitive values are redacted from command and diagnostic output
  • Output length and execution time are bounded
  • Conflicting operations are rejected while the deployment lock is active

Browser boundary

Useful evidence without raw state exposure

  • The browser never invokes OpenTofu directly
  • Raw encrypted plan and state artifacts are not downloadable
  • Plan actions and diagnostics are parsed and sanitised
  • Managed resources expose only an allow-listed state projection

Credential and token handling

Keep secrets out of ordinary interfaces and logs.

Cloud accounts retain encrypted credential payloads behind the application model. Worker commands receive the provider material they need while redaction and temporary-file cleanup reduce accidental exposure.

  • AWS uses its configured identity boundary, including IAM Roles Anywhere support
  • Azure service-principal credentials remain inside the selected cloud account context
  • Google Cloud service-account material uses isolated temporary files that are removed after use

API access

Scoped tokens with a one-time secret.

API tokens select explicit permissions and may include an expiry date. The raw token is displayed once; IntelliconOps stores its hash and allows the owner to revoke it.

Nameautomation-client
PermissionsSelected scopes
Stored valueToken hash
LifecycleOptional expiry · revocable

Private workload path

Separate cloud control APIs from guest network access.

Provider APIs use scoped cloud credentials. Where SSH or Ansible must reach a private guest, guided WireGuard connectivity creates an encrypted route into the selected AWS VPC, Azure VNet or Google Cloud VPC.

Explore private networking
Cloud APIScoped provider authentication and approved operations
WireGuardEncrypted route from worker to cloud router
Private VMSSH and Ansible over a private workload address
VerificationReachability, workload route and handshake checks

Deployment isolation

Choose a deployment boundary that matches the customer environment.

IntelliconOps supports a dedicated deployment model with a customer-specific application stack, domain, database, persistent volumes and backup policy. The final topology is agreed as part of deployment design rather than assumed for every installation.

Infrastructure isolation does not replace operational controls. TLS, secrets management, backup testing, patching, monitoring and access review remain deployment responsibilities.
Customer-selected secure domain
customer.intelliconops.com
TLS

ApplicationDedicated stack option
DatabaseCustomer boundary
VolumesPersistent artifacts
BackupsEnvironment policy

Security evidence

Make important decisions reviewable after the event.

Audit records connect access changes, temporary elevation, Blueprint requests, OpenTofu planning and approval, apply outcomes and inventory synchronisation to the responsible user and resource context.

Explore auditable operations

See IntelliconOps in action

Give every cloud request a clear, controlled path.

Tell us how your teams manage infrastructure today. We will show you how IntelliconOps can simplify the work.

Book a demonstration