Control the session
Bind identity, project state, destination, requested authority, maintenance scope, and time into one explainable decision.
ENGINEERING SESSION GOVERNANCE
EWSP governs the Engineering Environment, application, project, controller, trust, policy, and evidence that define privileged engineering activity. It evaluates readiness before authorization, enforces the session decision locally, and preserves an explainable record before, during, and after the activity.
Deterministic policy Explicit engineering evidence Local Windows enforcement
The engineering connection passed every mandatory check.
THREE-MINUTE BRIEF
EWSP governs engineering work from readiness through verified outcome. OT security protects industrial systems; EWSP governs the industrial engineering operations performed against them.
Bind identity, project state, destination, requested authority, maintenance scope, and time into one explainable decision.
Revoke a valid session when its project, target, tool, or approved operating condition changes.
Current capabilities, controlled validation, source-built work, and field-validation needs are labeled separately.
It decides whether a defined engineering session should perform a privileged operation against an industrial asset.
Safety boundary: Authorization verified does not mean process safe. PLC, SIS, interlocks, permissives, operating procedures, and process-safety engineering remain responsible for physical-process safety.
Can this network traffic flow?
Is this endpoint or process malicious?
Who may use privileged credentials?
What is happening in the plant?
Should this engineering session perform this privileged engineering operation?
EWSP complements industrial engineering platforms, OT monitoring, EDR, PAM, and network access controls. These are architectural roles, not claims of current product integration.
THE FROZEN V1 CONTROL MODEL
An Engineering Session is the complete governed context—not merely a connection, credential, or workstation.
Trusted engineering software
Approved Windows identity
Verified industrial asset
Authorized project state
Time and operation permitted
Communication permitted
The failed condition is explained and unauthorized communication is prevented.
The EWSP Protection Service is the Control Point and sole policy authority. Connectors and readiness providers contribute evidence only.
Authorization belongs only to the Engineering Session. Engineering Environment state is referenced—not duplicated—and any mandatory context change can withdraw session authorization while preserving the evidence.
Collect evidence without granting trust.
Review identity, integrity, destination, operation, and time.
Enable only the bounded context and record the outcome.
Observation never promotes protected state.
ENGINEERING ENVIRONMENTS · FROZEN V1
An Engineering Environment is a first-class object with immutable identity. Its fingerprint, composition, lifecycle, health, readiness, evidence, drift, and relationships remain independent dimensions; only an Engineering Session can receive authorization.
Immutable identity and a governed inventory across native workstations, VMs, VDI, jump servers, RDP, and cloud engineering workspaces.
Administrator-controlled Discover, Learning, Under Review, Approved, Modified, Revalidation Required, Retired, and Archived transitions.
Independent health and readiness states distinguish Ready, Ready with Restrictions, Not Ready, and Unknown without creating authorization.
Expected and observed fingerprints remain separate; categorized drift preserves the exact evidence behind revalidation.
Level, Coverage, Freshness, Provenance, and Confidence remain independent and Unknown evidence remains Unknown.
References connect Engineer, Control Point, Application, Project, Controller, Permit, and Maintenance Window without duplicating authoritative state.
Deterministic boundary: Every accepted lifecycle transition requires administrator authority, an explicit reason, and a work order. The transition and supporting evidence are fully audited.
Inventory and details expose lifecycle, health, readiness, enrollment progress, expected-versus-observed fingerprint, drift history, evidence, relationships, and audit history.
Lifecycle, health distribution, revalidation, readiness, recent drift, evidence coverage, and enrollment progress remain visible without duplicating EE state.
Engineering Environment inventory and details are available through EWSP.Read.v1. Lifecycle changes remain administrator-controlled Management operations.
Unknown evidence remains Unknown. Decisions use explicit evidence and policy, never a risk score alone.
Execution coverageThe model supports native workstations, Hyper-V, VMware, VirtualBox, VDI, RDP, jump servers, cloud engineering workspaces, and future execution environments.
Backward compatibilityExisting deployments and Engineering Session evidence remain readable; sessions reference their associated Engineering Environment instead of copying its state.
PROTECTIONPOLICY V1
Authorization, explanation, and enforcement remain separate. One typed classifier prevents trust, evidence, controller, permit, project, signature, WFP, policy, or storage failures from being treated as system availability.
Architecture rule: Only AvailabilityFailure may enter the ProtectionPolicy branch. Every other failure class remains a security or evidence outcome.
TrustFailureBlockA security outcome; never converted to availability.
EvidenceFailureUnknownCurrent behavior when required evidence cannot establish trust.
EnforcementFailureCritical FailureFailure to apply a decision is treated as critical.
StorageFailureEvidence gapBest-effort persistence plus recovery reconciliation.
AvailabilityFailurePolicy eligibleThe only failure class that may enter ProtectionPolicy.
Deny new protected engineering activity when EWSP cannot evaluate or enforce. Existing behavior remains fail closed.
Does not permit engineering activity. It records a protection-gap event and surfaces recovery reconciliation state; allow behavior is not implemented.
EWSP governs new engineering access, not PLC runtime execution, SCADA or HMI behavior, physical-process safety, interlocks, or emergency shutdown.
Engineering remains available while EWSP records why authorization is unverified.
Protected communication is constrained; controller runtime remains outside EWSP’s scope.
Maintenance permits require an authorized administrator, reason, exact application and destination scope, duration, expiration, and audit evidence.
Failure and recovery behavior must be testable. Crash recovery, permit expiry, reboot behavior, project modification, enforcement cleanup, backup restoration, and uninstall are acceptance-test evidence—not marketing assumptions. A broader emergency-override workflow remains future work.
CURRENT VALIDATION BUILD · EWSP v1.3.19
The current source build preserves the frozen v1 object model while adding Engineering Work, Engineering History, engineering-data operations, metadata-only data references, Compliance & Governance projections, and Recovery & Operational Response. These views use existing sessions, evidence, audit, outcomes, and recovery without changing authorization behavior.
The Console opens around planned, active, blocked, failed, verification, recovery, change, and learned work using recorded Engineering Session evidence only.
Timeline, session history, replay, lessons, recovery, advisory references, and global search reconstruct governed work without manufacturing missing evidence.
Read-only coverage and governance summaries expose recorded authorization, readiness, evidence, verification, recovery, audit, and freshness boundaries.
Recorded evidence may support documentation relevant to IEC 62443, NERC CIP, FDA 21 CFR Part 11, or ISO 27001. EWSP does not claim compliance or certification.
A first-class inventory and workspace expose immutable identity, deterministic enrollment, lifecycle, health, readiness, fingerprint comparison, drift, evidence, relationships, and audit history.
Vendor Engineering Readiness Provider results are normalized into overall and per-component readiness evidence before Trust and Authorization. Siemens is the only v1 provider.
Each Engineering Session records a normalized operation such as PLC logic, drive parameters, firmware, HMI, safety, monitoring, diagnostics, backup, or recovery—without creating a new architecture object.
Pre-Flight evaluates the artifact, target identity, firmware, approval, rollback, or observe-only evidence required by the recorded operation. Unknown remains Unknown.
Authorization remains separate from operational success. Controller before/after evidence, faults, verification, recovery source, and version context are recorded only when observed.
Optional artifact-level readiness evidence distinguishes aligned, misaligned, incomplete, and unknown design context without replacing CAD, PDM, PLM, or vendor engineering tools.
Session-scoped evidence evaluates whether observed security prerequisites satisfy Engineering Session Policy. It does not monitor or diagnose infrastructure health.
Session-scoped application, dependency, catalog, license, and asset evidence is normalized without replacing vendor diagnostics.
Coverage, completeness, sufficiency, and decision confidence are reported independently, with a reason for every Not Evaluated item.
A generic contract preserves applicability, analysis mode, evidence quality, policy result, provenance, and provider boundaries across every readiness domain.
Typed failure classification precedes policy and enforcement. Availability Mode remains framework-only; Protection Mode continues to fail closed.
Installed by default with secure stdio transport. EWSP.Read.v1 fails closed and exposes no management or write operations.
Connected-client status, published tools and resources, version compatibility, diagnostics, and copy-ready MCP configuration.
Engineering Timeline and Case View connect trust, audit, session, project, permit, recovery, and candidate evidence.
Support Bundle packages diagnostics; Unified Evidence Export packages the evidence for one engineering event.
Recorded sessions drive timelines, readiness history, analytics, comparison, evidence confidence, decision replay, recovery history, lessons, and global search. Missing evidence is never inferred.
Import, export, tag, configuration, validation, transformation, synchronization, review, comparison, and deployment-preparation work remain governed Engineering Session attributes and evidence projections.
Sessions reference historian, SCADA, PLC trend, HMI, data-logger, and vendor-tool datasets using metadata only. EWSP does not ingest or duplicate historian samples.
Recorded outcomes, recovery evidence, session recommendations, timelines, and decision traces are projected from existing governed records. EWSP is not an incident-response platform.
Light, Dark, and System display modes apply app-wide with persisted selection, corrected dark-mode contrast, and consistent controls.

EVIDENCE AND VALIDATION
In a two-machine test environment, one Windows system acts as the engineering workstation and another as the simulated industrial endpoint. EWSP learns permitted behavior, creates an approved policy, allows the authorized service, and blocks attempts when mandatory checks fail.
Engineering Environment lifecycleDeterministic transitions require administrator authority, an explicit reason, and a work order. Identity remains immutable and accepted changes are persisted and audited.
Engineering Session Pre-Flight v1Compatible results preserve the downstream authorization path; provider readiness failures produce NotStarted with component scope, provenance, recommendations, audit evidence, and Auditor exports.
Engineering Operation TypeExplicit operations with missing required evidence produce NotStarted. Legacy sessions with no operation evidence remain Unknown and preserve existing behavior.
Authorization and operational outcomeA permitted operation may still fail; a denied or NotStarted operation is NotPerformed. Audit, API, MCP, reporting, and exports preserve the distinction.
Engineering Design ContextApplicable provider evidence is recorded per artifact. Misaligned, incomplete, or provider-unknown context produces NotStarted; no provider preserves existing behavior.
Security Infrastructure ReadinessObserved facts, evaluated scope, session policy result, recommendation, and provider provenance remain separate. Unknown never passes.
Engineering Readiness Framework v2A shared domain contract and Provider Capability Matrix disclose evaluation scope, limitations, evidence coverage, completeness, sufficiency, and confidence.
Engineering Environment ReadinessApplicable provider results identify Ready, Missing Dependencies, Unsupported Environment, or Unknown; no provider preserves existing behavior.
Evidence Domain reference providersDeterministic Behavior Verification and Interoperability fixtures validate the platform contract only; they do not parse vendor code, validate standards, or troubleshoot tools.
Engineering HistoryTimeline, history, comparison, analytics, lessons, recovery, and decision replay use recorded evidence only and distinguish Observed, Not Evaluated, Not Recorded, and Unknown.
Engineering governance projectionsEngineering Work Hub, Engineering History, Compliance & Governance, Standards Evidence Mapping, and Recovery & Operational Response add no authorization semantics or persistence model.
Engineering data operationsArtifact identity, object counts, warnings, validation, verification, outcome, and recovery evidence are recorded without storing artifact contents or altering authorization.
ProtectionPolicy failure boundaryTrust, evidence, enforcement, storage, and availability failures are classified before policy and enforcement; only AvailabilityFailure is policy-eligible.
Native Windows WFP enforcementAuthorized service permitted; unknown service blocked on its first attempt.
Continuous project-integrity controlSHA-256 baseline monitoring, access revocation, re-approval, and audit evidence.
Scoped maintenance permitsApplication- and destination-specific exceptions with duration, reason, revocation, and expiry.
Discovery-only application inventoryPath, publisher, signature, version, and SHA-256 evidence are recorded without creating approval or observation authority.
Environment and artifact evidenceSupporting components and selected artifacts are Observed evidence; compatibility and tool provenance remain Unknown.
Explainable environment snapshotsReadable manifests, individual hashes, canonical fingerprints, and exact component changes are preserved without blocking a session.
Transport-neutral observationTCP and scoped UDP activity can be recorded with visible provenance and high-volume aggregation; observation never promotes trust.
Hardened local managementRead-only and Management operations use separate local routes with Windows-token authorization, audit history, diagnostics, and offline enforcement.
Controlled technical validation is not plant-wide deployment or PLC-scale performance. Newer environment, artifact, snapshot, discovery, and network-observation capabilities are source-built and locally evidenced, but not yet installed and validated with a real OT engineering application, vendor artifact, controller, or second physical validation device. The current development package is unsigned.
EWSP records immutable Engineering Environment identity and keeps lifecycle, health, readiness, fingerprint, composition, evidence, drift, and relationships independent. Authorization belongs only to the associated Engineering Session.
Approved and observed fingerprints remain separate. Readable manifests and exact changes explain drift without guessing.
Missing or unavailable evidence is never converted into a pass, an inferred fact, or a risk-score-only decision.
Connectors observe and contribute bounded evidence. The Protection Service remains the sole Control Point and policy authority.
Deterministic lifecycle management, administrator-controlled transitions, environment inventory and Dashboard summary, readiness, expected-versus-observed fingerprints, categorized drift, evidence quality, relationships, audit history, and Read API support.
Architecture boundaryThe model governs native and virtual execution environments without replacing vendor engineering software, hypervisors, remote-access platforms, or infrastructure management.
EWSP assumes a workstation credential, remote-access path, or network segment may be compromised. Authorization still depends on the complete engineering context satisfying policy.
Records can preserve project hash, workstation and endpoint identity, requested scope, maintenance reason, time window, decision rationale, enforcement result, integrity state, and recovery evidence.
The current release uses protected and tamper-resistant local evidence. It does not claim TPM-backed attestation, certificate-backed reports, or independently verifiable cryptographic timestamps.
“Source build available” means implemented and locally tested but not yet packaged into the installed validation release. “Build available” means implemented in the current test release. “Lab validated” means exercised in EWSP’s controlled Windows environment. None means production-plant validation.
Protected backup creation, integrity validation, corrupted-backup rejection, controlled live restore, and rollback-copy creation.
10 service restart cycles and 100 authenticated Management API requests completed successfully.
Dynamic Windows Filtering Platform cleanup and restoration validated through controlled service transitions.
Configurable retention, controlled log rotation, diagnostic bundle, and alarm-history export containing 34 records.
Service configuration, automatic startup, recovery actions, local roles, data permissions, and installed components validated.
Release-package manifest and SHA-256 checksums verified for the validated test release.
This validates controlled Windows reliability and operational safeguards—not plant deployment, production code signing, real-controller validation, or every industrial vendor ecosystem. Version-specific release evidence is maintained separately.
Protocol-specific identity is normalized into a common, protocol-independent Trust Engine model.
Current buildEWSP Simulator and EtherNet/IP (CIP) ListIdentity
Evidence boundaryCIP ListIdentity is direct protocol evidence classified High confidence, not cryptographic authentication. Real-controller validation remains pending.
FUTURE SOC INTEGRATION DIRECTION
EWSP is the authoritative source for engineering-session authorization events. SIEM, SOAR, XDR, and OT security platforms remain systems of record for correlation, investigation, retention, and response.
Event API v1 and the Microsoft Sentinel exporter are implemented in the source build. The affected Release build passes; ingestion into a configured Sentinel tenant remains pending validation.
Decision, reason code, correlation and session IDs, engineer, workstation, engineering application, controller identity, project hash, baseline ID, permit status, maintenance window, evidence reference, and EWSP version. Trust score is optional.
Project contents are never exported.
First: Microsoft Sentinel through the Azure Monitor Logs Ingestion API.
Second: Splunk HEC.
ServiceNow: via established SIEM/SOAR workflows.
Future provider interfaces may support CEF, LEEF, Syslog, OpenTelemetry, QRadar, Elastic, Chronicle, and webhooks.
Roadmap boundary: Sentinel has a source implementation but tenant ingestion is not yet validated. All other named providers remain future direction and are not current product capabilities.
LOW-RISK ADOPTION
Discover sessions without blocking.
Approve assets, services, projects, and scope.
Protect chosen applications and destinations.
Measure workflow impact, recovery, and effectiveness.
Extend authoritative EWSP events into governed enterprise workflows.
2-MINUTE PRODUCT WALKTHROUGH
The walkthrough follows EWSP from Learning through approval, policy generation, first-attempt protection, and verified enforcement.
The recorded walkthrough shows an earlier interface. The current source direction centers Engineering Work, Engineering History, readiness, evidence, verification, recovery, lessons, governance projections, and secure read-only MCP access while preserving the frozen v1 authorization model.
▶ Play full-screenVALIDATION PILOT
EWSP is seeking experienced OT security leaders, industrial operators, automation vendors, and design partners.