TroutTrout
Access Gate Architecture

Access Gate — Multi-Site Architecture

Federate multiple Trout Access Gate deployments across distributed sites with centralized policy. A single identity fabric spans every plant while each site keeps local enforcement and air-gap safety.

Zuletzt aktualisiert:

The multi-site architecture federates Access Gate deployments across distributed plants under one policy plane. A single identity fabric spans every site, while each site keeps enforcing access locally, so a lost link or an air-gapped location never loses protection.

You define who can reach what once, centrally, and it applies everywhere. Each site continues to authenticate users, scope access per asset, and record sessions on its own, which means central management without central dependency: nothing at a site relies on the internet or the head office to stay secure.

What this video covers

  • How one identity fabric and policy plane spans many sites
  • Why local enforcement continues even if a site is offline or air-gapped
  • Central management without central dependency
  • Rolling one access policy out across every plant at once
Proven in production

STBMA runs Zero Trust across 55 ski-lift sites with no dedicated security team.

  • 55 lift sites protected, spread across terrain from 850 m to 2,353 m
  • 1 central management plane over all distributed sites
  • 0 dedicated security staff: operated by the existing IT team
Read the case study

Questions and answers

What is the multi-site Access Gate architecture?

It federates Access Gate deployments across many sites under one identity fabric and policy plane, while each site enforces access locally so protection continues even when a site is offline or air-gapped.

Does a site stay secure if it loses its connection?

Yes. Enforcement is local at each site. Central management sets policy, but a site does not depend on the internet or the head office to keep authenticating users and controlling access.

Can one policy apply to every plant?

Yes. You define access policy once and it applies across every federated site, so a change propagates everywhere instead of being rebuilt per location.

Talk to an Engineer

See Access Gate in Your Environment.

The demos show the pattern. A live call shows what it looks like on your network — with your PLCs, your historian, your constraints.