Industrial Outcomes¶
L2Proxy is designed around operating outcomes rather than packet volume. It helps plant owners control remote work, protect consequential operations, reduce investigation time, and demonstrate what occurred without asking every stakeholder to interpret protocol trees.

Figure — Industrial operation control model: Raymon evaluates operation context, intent, and outcome—not only connectivity.
Outcomes by industrial responsibility¶
| Stakeholder | Practical outcome |
|---|---|
| Operations | Understand which asset and operation were involved and whether activity was permitted or blocked |
| Control and protection engineering | Express permitted commands, values, sequences, prerequisites, and equipment states as reviewable policy |
| Maintenance management | Limit a remote user to the equipment and operations required for an approved task |
| OT cybersecurity | Connect authenticated identity and session activity to decoded industrial behavior and policy results |
| Asset owner | Retain a searchable record of access, operations, deviations, and enforcement decisions |
| Audit and investigation | Trace a readable industrial event back to the session, rule decision, and detailed protocol evidence |
Remote work with industrial least privilege¶
Traditional remote access can establish who connected and which network was reachable. L2Proxy Connect adds the industrial question: What did that user attempt to do after connecting?
A customer can distinguish monitoring from control, restrict access to assigned equipment, apply value and sequence conditions, record approved activity, and block a specific prohibited operation without treating every authenticated session as equally trusted.
Protection aligned with equipment¶
Policies can begin with equipment that plant teams already understand: breakers, transformers, relays, reclosers, regulators, capacitor banks, busbars, and DER interties. Their points, operating ranges, commands, expected states, and prerequisites provide the context for practical baseline protection.
Examples include:
- permit monitoring while restricting control;
- require a valid Select-Before-Operate sequence;
- prevent a setpoint outside an approved engineering range;
- detect a command without expected status feedback;
- constrain maintenance actions to the assigned user and session;
- record restart, recovery, alarm, and configuration-change sequences.
Faster, more defensible policy engineering¶
The Equipment and Protection Library, Guided Policy Composer, reusable industrial rule templates, contextual autocomplete, inline help, and expression validation reduce the effort required to move from an operating requirement to a reviewable policy. Generated policy remains manageable, testable, and traceable through its deployment lifecycle.
Evidence in the language of the plant¶
L2Proxy preserves detailed protocol facts while presenting equipment, point, operation, direction, category, severity, criticality, tags, and a readable industrial description. With L2Proxy Connect, the same evidence can include authenticated user and session context.
This helps answer:
- Who performed or attempted the operation?
- Which equipment and point were affected?
- Was the activity monitoring, control, maintenance, or configuration?
- Which policy matched and what decision was made?
- What protocol evidence supports that conclusion?
Controlled adoption in operating plants¶
Customers can begin with passive observation and recorded decisions, validate policy against representative traffic, and activate blocking only after operational review. L2Proxy Connect and standalone services can coexist, allowing each access path and industrial boundary to use the enforcement model appropriate to its risk and ownership.
Continue with Product Architecture, L2Proxy Connect, or Deployment Choices.