Skip to main content
PrecisionDCOS — PrecisionX CriticalPrecisionDCOS home

Technical search

Jump to any product, solution or page

DCOS Network · DCOS-NET

DCOS Network

Four purpose-built network domains. One accountable fabric.

From a single edge data center to a multi-building compute campus, PrecisionDCOS designs, deploys, accepts and operates the complete communications environment: IT & security, facility management, transit & transport, and structured cabling. Each domain is engineered to its own trust, availability and authority requirements, then joined through one documented operating model.

Deploy it as a complete new network, an overlay on approved customer standards, a managed service for existing infrastructure, or a mixed-vendor federation.

Domains
IT/Security · Facility · Transport · Cabling
Scale
Edge · Data center · Campus
Delivery
New build · Overlay · Managed
Acceptance
Configured · Tested · Documented

Architecture principle

One fabric does not mean one flat network

The systems serving people, physical security, facility operations, carrier connectivity and the physical cabling plant do not share the same risk, traffic, lifecycle or recovery requirements. DCOS Network treats them as separate service domains with explicit interfaces.

Where common hardware is appropriate, routing, policy and authority remain isolated. Where independence is required, path, power, management and recovery dependencies are separated as well. The result is one accountable architecture without collapsing unlike systems into one undifferentiated network.

Purpose-built boundaries

Each domain has a declared trust model, routing policy, authority model, availability requirement and failure assumption.

End-to-end accountability

Logical services, physical paths, carrier dependencies, cabling records and operational ownership are engineered as one service chain.

Operable from day one

Topology, health, configuration, paths and dependencies are documented and monitored before the environment carries production traffic.

Four service domains

Separate what must remain separate. Coordinate what must work together.

The four domains share one engineering and operating contract, but they do not share one unrestricted trust zone. Each is designed, accepted and operated according to the systems, people and services it carries.

01

IT & Security Network

People, operations, customer management and protective systems

A site-services fabric for people, operations, customer management and physical-security devices. Wired access, Wi-Fi, voice, business systems and security transport are engineered for coverage and service quality, while identity, role, tenant and function determine reachability.

Includes

  • Operations, NOC and SOC workstations
  • Staff wired and wireless access
  • Isolated guest and contractor Internet access
  • Voice, collaboration, printing and business or IoT devices
  • PACS, VMS, cameras, intrusion, intercom, duress and ALPR transport
  • Customer and cluster-management networks where in scope
  • Identity, NAC, firewall policy, QoS, PoE and client-experience assurance
  • Network-management and approved remote-access paths

Product boundary

DCOS Network provides and operates the communications substrate. DCOS Secure governs physical-security applications, operator authority, response workflows and evidence.
02

Facility Management Network

The operational-technology substrate for systems that keep the site alive

BMS, EPMS, controllers, meters, power, cooling and packaged systems belong on a purpose-built operational-technology network—not on the enterprise LAN. Each zone has explicit routes, permitted flows and authority, while local operation is preserved when enterprise or hosted services are unavailable.

Includes

  • BMS, EPMS and PrecisionDCMS acquisition
  • PLC, PFC, RTU, gateway and packaged-controller networks
  • Metering, UPS, ATS, switchgear and generator interfaces
  • Cooling, CDU, pump, dry-cooler and packaged-system interfaces
  • Approved, generally read-only fire, gas and life-safety monitoring interfaces
  • OT time, naming, logging, collection and protocol-gateway services
  • OT DMZ and brokered north-south integration
  • Governed vendor access and protocol-aware monitoring
  • Dedicated zones, VRFs, firewall policy and dual-path design where required

Authority rule

Monitoring may be broad; command is explicit. Safety-rated protection, shutdown functions and local equipment interlocks remain autonomous and are not dependent on the enterprise network or hosted operating plane.
03

Transit & Transport Services

Delivered through DCOS Connect

Routed connectivity from the site demarcation to hubs, carriers, clouds and customers

DCOS Connect extends the architecture beyond the site demarcation. PrecisionX coordinates carrier procurement, optical and IP engineering, interconnection, routing, acceptance, monitoring, incident management and capacity across the complete external connectivity path.

Includes

  • Carrier procurement and demarcation coordination
  • High-capacity wavelength and Ethernet services
  • Dark fiber, metro and inter-campus connectivity
  • Internet transit and multi-provider edge services
  • ASN, IP-addressing, BGP and route-policy engineering
  • Remote meet-me hubs and data-center interconnection
  • Cloud on-ramps, exchanges and customer cross-connects
  • DDoS and Internet-edge coordination where scoped
  • Active path monitoring, SLA evidence and carrier incident coordination
  • Documented physical, provider, equipment and logical diversity

Architecture rule

Transport remains transport-only. Production domains are not stretched across carrier services by default. Reachability is established through explicit routed boundaries, VRFs, BGP policy, route filtering, path-health detection and deterministic failover.

Carrier transport must not become an accidental transit path between IT, security, facility-management, OOB, customer-management or other protected domains.

04

Structured Cabling

The physical layer from rack patching to the campus backbone

The physical layer is part of the network product, not an undocumented construction handoff. PrecisionX designs and can furnish, install, terminate, label, certify and document the fiber, copper, pathways, enclosures and patching that connect racks, rooms, buildings, outdoor systems and remote campus assets.

Includes

  • Data-hall, row and rack fiber or copper distribution
  • MDF, IDF and telecommunications-room layouts
  • Inside-plant and outside-plant fiber backbones
  • Diverse building entrances and campus routes
  • Horizontal copper and local device connections
  • Security, wireless, facility-management and OT device drops
  • Outdoor edge cabinets, smart poles and industrial PoE extensions
  • Pathway, enclosure, grounding and environmental coordination
  • Optical-loss, link-distance and PoE-budget calculations
  • Termination, labeling, certification and as-built records
  • Spare-strand, spare-port and future-expansion planning

Physical-layer principle

Fiber is the preferred long-distance and building-to-building backbone. Copper remains local to endpoints wherever practical. Outdoor transitions occur through engineered, powered and protected edge infrastructure, with route, label and test evidence retained for the operating lifecycle.

Delivery may be engineering-only, full furnish and installation, testing and acceptance, or coordination with the project's civil, electrical and low-voltage trades. Responsibility is declared in the approved scope.

Cross-domain recovery

Out-of-band is a recovery plane—not a fifth production network

The out-of-band plane reaches selected IT and security, facility-management, and transit or transport assets without depending on the path being recovered. It is deliberately separated from normal production access and designed around named identities, independent reachability and tested recovery.

Where the risk requires it, OOB uses separate upstream connectivity, power, gateways, antennas, management paths and local services. Common dependencies are documented rather than assumed away.

  • Site operations gateway or uCPE
  • Console-server access
  • BMC, iDRAC and iLO management
  • Network and firewall management
  • Private ZTNA or VPN access
  • Cellular or secondary-ISP resilience
  • Local DNS and time services
  • Configuration backup and recovery
  • Upstream-path and power monitoring
  • Periodic recovery exercises and evidence

No public management endpoints. Named identities and MFA. Time-bounded break-glass. Recovery tested and evidenced.

Scalable reference architecture

One operating model from an edge data center to a multi-building campus

The number of racks, buildings, remote assets and carrier paths changes. The domain boundaries, acceptance discipline and operating contract do not.

Scale 01

Edge Data Center

A single rack, modular room or compact facility. Integrated edge switching, firewalling and OOB; explicit IT, security and facility segments as applicable; a controlled carrier handoff; and factory-staged patching with concise as-built records.

  • Integrated rack or cabinet
  • Compact routed and security edge
  • Local facility-system connectivity
  • Independent recovery access
  • Structured patch field
  • Designed for later expansion
Scale 02

Data Center / Facility

A production building with redundant core and distribution, MDF and IDF infrastructure, dedicated OT and security zones, high-availability service edges, structured cabling to racks and field systems, and complete operational visibility.

  • Redundant distribution
  • Dedicated IT, security and OT zones
  • Multiple telecommunications spaces
  • Rack and field-device distribution
  • Governed Internet and transport edge
  • 24/7 monitoring and lifecycle management
Scale 03

Multi-Building Campus

Multiple data halls, generation and utility areas, gates, yards and remote buildings joined by diverse fiber trunks, outdoor edge cabinets, routed transport, centralized operations and a scalable addressing, identity and authority model.

  • Diverse campus fiber routes
  • Multiple building entrances
  • Remote gates, yards and utility areas
  • Outdoor edge cabinets and smart poles
  • Remote hub and carrier integration
  • Centralized NOC and SOC operations
Scale 01

Edge Data Center

IT & Security
  • Site firewall and switching
  • Staff and security devices
  • Customer-management access
Facility Management
  • Local controllers and meters
  • Facility gateway
  • PrecisionDCMS acquisition
Transit & Transport
  • Carrier demarcation
  • Routed site edge
Structured Cabling
  • Integrated rack patching
  • Local fiber and copper
Scale 02

Data Center / Facility

IT & Security
  • Core and distribution
  • Wired and wireless access
  • Security transport
Facility Management
  • OT access and distribution
  • BMS and EPMS
  • OT services and DMZ
Transit & Transport
  • Internet and transport edge
  • Diverse service interfaces
Structured Cabling
  • MDF and IDFs
  • Rack and field distribution
  • Building backbone
Scale 03

Multi-Building Campus

IT & Security
  • Operations and security services
  • Staff, contractor and customer access
  • Remote gates and buildings
Facility Management
  • Building, generation and utility zones
  • Campus OT distribution
  • Controlled integration
Transit & Transport
  • Remote hubs
  • Carriers, clouds and customers
  • Routed path diversity
Structured Cabling
  • Diverse OSP fiber trunks
  • Building entrances
  • Outdoor edge cabinets
OOB recovery plane
  • Private management access
  • Console and BMC
  • Alternate upstream path
  • Independent recovery

Independent path across selected managed assets in the three production lanes — never merged into them.

Reference pattern only. Exact topology, capacity, equipment, physical diversity and operating authority are engineered per site and governed by the approved Basis of Design.

Operated outcomes

What an accepted network environment makes true

Purpose-built separation

IT and security, facility-management, and transit traffic cross only at declared, monitored and policy-controlled boundaries.

No physical-layer blind spot

Routes, fibers, copper links, patch fields, optics, power dependencies, labels and test records are modeled with the services they support.

Accepted before production

Configuration, reachability, performance, failover, recovery, labeling and test evidence are complete before service commencement.

Operable through change

Topology, configurations, dependencies, incidents, capacity and as-builts remain governed throughout the operating lifecycle.

Engineering and operations

Designed, built, accepted and operated as one system

DCOS Network does not stop at topology design or equipment installation. The logical architecture, physical layer, external connectivity and recovery model move through one controlled lifecycle from discovery through steady-state operations.

01

Discover & engineer

  • Site and campus survey
  • Existing-system and standards review
  • Asset, user and traffic-flow inventory
  • Authority and responsibility mapping
  • Zone, conduit and trust-boundary design
  • IP, VLAN, VRF, routing and firewall planning
  • BGP and carrier-edge planning where scoped
  • Wireless coverage and capacity engineering
  • Cabling, pathway, optical-loss and PoE design
  • Resilience and common-mode analysis
02

Build & stage

  • Bills of material and submittals
  • Factory or office staging
  • Base configuration and hardening
  • Identity, certificates and credentials
  • Rack, room and field installation
  • Fiber and copper termination
  • Port, cable and asset labeling
  • Monitoring and configuration-backup enrollment
  • Cutover and rollback planning
03

Test & accept

  • Copper and fiber certification
  • Optical and physical-path verification
  • Wireless coverage and roaming validation
  • Permitted-flow and firewall testing
  • Routing and failover testing
  • Transport performance and path validation
  • Security-device and facility-device reachability
  • OOB and recovery exercises
  • Monitoring and alarm validation
  • As-builts, test records and turnover
04

Operate & improve

  • 24/7 health and path monitoring
  • Configuration backup and drift detection
  • Firmware and vulnerability lifecycle
  • Incident and problem management
  • Carrier escalation and coordination
  • Capacity and client-experience assurance
  • Periodic failover and recovery testing
  • Change control and maintenance coordination
  • As-built maintenance
  • Portable customer handback

Reference profiles

Four domains with explicit responsibilities

The following profiles are planning baselines. Exact segmentation, equipment, redundancy, physical diversity, service levels and operating authority are established during site engineering.

IT & Security

Primary responsibility
People, operations, business services, physical-security transport and approved customer-management services
Typical boundary
Identity-, role-, tenant- and function-based segmentation with isolated security zones
Resilience model
Redundant uplinks and service edges where required, with independent OOB recovery
Primary PrecisionDCOS relationship
DCOS Network + DCOS Secure

Facility Management

Primary responsibility
BMS, EPMS, controllers, meters, power, cooling, packaged systems and PrecisionDCMS acquisition
Typical boundary
Dedicated OT zones and VRFs with brokered north-south integration
Resilience model
Local-first operation and dual paths where process risk justifies them
Primary PrecisionDCOS relationship
DCOS Network + PrecisionDCMS

Transit & Transport

Primary responsibility
External carrier, hub, Internet, cloud, exchange and customer connectivity
Typical boundary
Routed demarcations with explicit BGP, VRF, firewall and route policy
Resilience model
Documented physical, carrier, device and logical diversity as contracted
Primary PrecisionDCOS relationship
DCOS Connect

Structured Cabling

Primary responsibility
Physical connectivity within racks, rooms, buildings, outdoor areas and the campus
Typical boundary
Labeled and documented pathways, patch fields, entrances and enclosures
Resilience model
Diverse routes where required, certified links, spare capacity and expansion planning
Primary PrecisionDCOS relationship
DCOS Network Engineering

Shared operating contract

Every domain follows the same rules of accountability

The domains remain technically distinct, but they share a common operating contract for identity, authority, events, dependencies, evidence and portability.

Stable identity

Every device, interface, port, circuit, path, fiber strand, patch, segment and service carries a stable identity that survives configuration and vendor changes.

Declared authority

Visibility and change authority are declared separately. Access to network health or operational data never implies unrestricted authority to modify a protected system.

Shared event lifecycle

Network, cabling, carrier and recovery events join the same detect → validate → correlate → coordinate → restore → prove lifecycle.

Explicit dependencies

Logical services are related to switches, firewalls, optics, circuits, fibers, pathways, power sources, carriers and upstream services so blast radius and restoration order are known.

Portable evidence

Configurations, labels, test records, topology, as-builts, incident history and acceptance evidence remain exportable and available for customer handback.

Scope and boundaries

Clear ownership at every interface

  • DCOS Network is the umbrella architecture for internal IT and security networking, facility-management and OT networking, the structured-cabling plant, and their integration with the site connectivity edge.
  • External carrier, optical, Internet, cloud, hub and customer-interconnection services are delivered and operated through DCOS Connect. They are shown on this page because they are integral to the end-to-end architecture.
  • DCOS Secure governs physical-security applications, protective workflows, operator authority, response and evidence. DCOS Network provides the underlying communications substrate unless the approved order assigns responsibility differently.
  • PrecisionDCMS acquires and operates facility data within an explicit authority model. It does not replace safety-rated protection, shutdown, fire, gas or life-safety controls.
  • Customer-management networks may be included. The customer's internal production GPU, InfiniBand or high-performance Ethernet fabric is included only when expressly scoped.
  • Structured-cabling delivery may include engineering, furnishing, installation, termination, certification, acceptance or coordination with project trades. Pathway, trenching, duct-bank, grounding and electrical responsibilities are explicitly assigned in the approved scope.
  • DCOS Network may federate suitable existing infrastructure and approved customer standards. It does not require a single network vendor or an automatic rip-and-replace.
  • Redundancy is only claimed where the physical routes, carriers, power sources, equipment and management dependencies have been documented and accepted. Ordering two services does not by itself prove diversity.

Technical FAQs

Frequently asked questions

Explore the family

Related products

Engineer the network as one system—without flattening its boundaries.

Whether the requirement is a single edge data center, a new production building or a multi-building compute campus, PrecisionX maps the four network domains, their physical and logical interfaces, and their operating authority into one accepted reference architecture.