CriticalOps Cloud
The hosted DCOS Cloud operating plane
The hosted DCOS Cloud operating plane for identity, observability, workflow, data and customer operations — tenant-aware identity, private access, monitoring, dashboards, CALS, workflow, status, reports, evidence, APIs, backup, disaster recovery and cross-site operations.
- Delivery
- Hosted managed plane
- Access
- Private, SSO, role-scoped
- Scope
- Multi-site operations
- Resilience
- Local protection independent
Outcomes
What this component is designed to make true when it is in place.
Contract, run for you
The full operating contract is delivered as a hosted, managed plane with private access.
Multi-site by default
Federated monitoring, dashboards, CALS and evidence across every site and region.
Local protection independent
Local life-safety, protection and equipment autonomy never depend on CriticalOps Cloud.
Hosted services
Identity & tenancy
Tenant-aware identity, SSO and private access with role-scoped authority across the estate.
Monitoring & visualization
Federated monitoring and portfolio dashboards over every site and domain.
CALS & workflow
Hosted CALS event-to-work orchestration and workflow integrations driving events to verified closure.
Evidence & reporting
Aggregated, continuous evidence and assurance reporting across the portfolio.
APIs & data publication
Hosted, tenant-scoped APIs and streams for integration and analytics.
Backup, restore & DR
Managed backup, restore and disaster recovery for configuration, data and evidence.
Supported authority patterns
The authoritative monitoring location is selected by deployment; the hosted plane runs distinct, tested service groups.
Authority patterns
- Hosted authority — in Field + NX-Cloud and NX-Cloud Only, the hosted PrecisionDCMS monitoring and workflow layer is authoritative for the assigned domains
- Federation — a local NX authority may publish selected state, events and telemetry to CriticalOps Cloud without creating duplicate actionable monitoring rules
- Private deployment — dedicated service cells, customer-cloud and private/sovereign deployments support additional isolation, residency and recovery requirements
Service groups
- Identity and tenancy
- Private access and secrets
- Monitoring and visualization
- Asset and dependency
- CALS and workflow
- Status and customer communications
- APIs and data publication
- Evidence and reporting
- Backup, restore and disaster recovery
- Platform security and lifecycle
Technology architecture
- Representative technologies may include Keycloak, NetBird or customer ZTNA, Vault or an approved secret store, Zabbix, Prometheus-compatible telemetry, Grafana, NetBox or approved DCIM/CMDB sources, ITSM/CMMS integrations and status or notification platforms. The product is the integrated, tested, secured, versioned and supported operating behavior — not an unmanaged collection of tools.
Operating contract
How this component upholds the shared platform contract.
What this component upholds
- Identity and authority are consistent and centrally governed across the hosted plane.
- Private access replaces public exposure for every operating surface.
- The authoritative monitoring location is selected by deployment; local life-safety, protection and equipment autonomy never depend on CriticalOps Cloud.
- Configuration, data and evidence remain exportable to the customer at all times.
Service profile
| Service | Delivery | Access | Resilience |
|---|---|---|---|
| Identity & SSO | Hosted | Private, role-scoped | Cached at site |
| Monitoring | Hosted federation | Private | Local NX continues |
| CALS | Hosted orchestration | Private | Local lifecycle continues |
| Evidence | Hosted aggregation | Private | Local capture continues |
| APIs / streams | Hosted | Authority-scoped | Local endpoints available |
Scope & boundaries
What this component is — and deliberately is not — responsible for.
- CriticalOps Cloud is the authoritative monitoring and workflow layer where the deployment selects it, and a federation target where local NX remains authoritative.
- Local life-safety, protection, gas shutdown and equipment-local control never depend on the hosted service.
- Portal links use approved private paths and separate authorization; the portal does not become an unrestricted browser proxy to PLCs, BMCs or switches.
- Private access and residency are configured to the customer's governance requirements.
Technical FAQs
Frequently asked questions
Explore the family
Related products
DCOS Operations
24/7 NOC, SOC, service desk, CALS event orchestration, ITSM/CMMS/DCIM and field services under an accountable operating model.
DCOS Data Fabric
Normalized, contextualized operational data with governed APIs, streams and exports for analytics, AI/ML and digital twins.
DCOS Assurance
ISO/IEC 27001, SOC 2 Type II, PCI DSS extensions and a unified control fabric with continuous evidence operations.
DCOS Network
Engineered building-management, OT, campus, security and management networks — new build, overlay, managed or mixed-vendor.
Bring CriticalOps Cloud into your reference architecture
We map this component to your sites, existing systems and assurance obligations, then agree a delivery path.
