Our architecture standard

One architecture standard, modified to fit how your business actually runs.

We do not hand every company an identical build, and we do not improvise a new design from nothing either. Identity, endpoint, email, network and business systems start from a proven standard, then get adjusted to your sites, your equipment and your people — which is why a new location takes days instead of months, and why support does not start with figuring out what is in the building.

What is the Machina IT architecture standard?

It is a five-layer reference design we use as the starting point for every customer and then modify to their needs: cloud identity with MFA and conditional access — scheduled-hours access for hourly staff, round-the-clock access for salaried staff — managed endpoints with centralized protection, an email security gateway, a segmented network behind redundant internet and a next-generation firewall, and business systems such as cloud productivity, ERP and reporting layered on top with verified backup and recovery underneath.

The standard stack

People verified first, controls in front, business systems behind them.

Every user passes MFA and conditional access before anything else happens — hourly staff inside their scheduled hours, salaried staff round the clock. Identity, endpoint and email controls sit in front of the network core, so nothing reaches cloud productivity or ERP without passing through them. The specifics of any one deployment stay in that customer's documentation, not on this page.

IDENTITY, ENDPOINT & EMAILSEGMENTED NETWORK CORECLOUD & BUSINESS SYSTEMSYOUR PEOPLE — VERIFIED, THEN SCOPEDIDENTITY & MFAENDPOINT PROTECTIONEMAIL SECURITYBACKUP & RECOVERYFIREWALL & ROUTINGCLOUD PRODUCTIVITYMANAGED DEVICESREPORTING & BIERPYOUR PEOPLEMFA VERIFIEDCONDITIONAL ACCESSHOURLY — SCHEDULED HOURSSALARIED — 24/7 ACCESSBROKERED ACCESS
01

Five layers as the baseline, then fitted to your operation

  • Identity and access — central directory, single sign-on, MFA on every account, and conditional access that scopes who can sign in, from what device, and when
  • Endpoint — managed devices, disk encryption, centralized antivirus and EDR
  • Email — gateway filtering for phishing, impersonation, ransomware and account takeover
  • Network — redundant internet, next-generation firewall, segmented switching and engineered wireless
  • Business systems — cloud productivity, ERP and reporting on top of the layers that protect them
02

Access is scoped to the person, not handed out uniformly

Everyone authenticates the same way — MFA on every account, no exceptions — but what happens after that is shaped by the role. Conditional access policies evaluate the user, the device they are on, its compliance state, and the time of the request before granting anything.

Hourly staff get access during scheduled working hours on managed devices, which removes off-hours credential abuse as an attack path and keeps time-clocked access aligned with the way they are paid. Salaried staff who genuinely need round-the-clock access get it, with stronger device and session requirements attached instead of a blanket allowance.

Contractors, equipment vendors and temporary users are handled the same way: a defined window, a defined device posture and a defined set of systems, expiring on a date rather than lingering as an open account.

03

Segmentation is designed, not improvised

Office traffic, production systems, operational technology, voice, wireless, cameras and management interfaces are separated from each other, and what may cross between them is written as firewall policy rather than assumed.

That is what keeps a compromised office workstation from having any route to a machine controller, and what lets an equipment vendor reach the equipment they support without reaching finance.

04

Everything is monitored and recoverable

Each layer reports to central monitoring, so degradation is caught before it becomes an outage. Backup and recovery sit underneath the whole stack with verified restore points and a documented recovery order across dependent systems.

05

Why a standard beats starting from scratch each time

  • A new site is a deployment, not a science project — identity, network, endpoint and ERP start from a known-good configuration and get adjusted from there
  • Onboarding a user or device is an unattended process
  • Support is faster because engineers already know the shape of the environment
  • Security controls stay consistent instead of varying by whoever set the location up
  • Documentation exists at handover rather than being reconstructed later
06

What we do not publish

This page describes the architecture in general terms on purpose. Firewall and switch models, segment numbering, address ranges, vendor tooling and the as-built topology are customer-specific security information. We walk through the detailed version with you during an assessment, and your own as-built documentation is delivered to you at the end of a project.

The baseline in numbers

Decided once, then deployed the same way every time.

0

Layers in the baseline

Identity, endpoint, email, network, business systems

0%

Accounts under MFA

No exceptions, including admins and vendors

0/7

Monitoring on every layer

Degradation caught before it becomes an outage

0

Network segments by default

Office, production, OT, voice, wireless, cameras, management

Layer by layer

Every layer exists for a business outcome, not for its own sake.

  1. 01

    Identity & access

    Central directory, single sign-on, MFA on every account, and conditional access scoped by role — scheduled-hours access for hourly staff, round-the-clock access for salaried staff, expiring windows for contractors and equipment vendors.

    Stolen credentials stop being enough to get in

  2. 02

    Endpoint

    Managed devices with disk encryption, centralized antivirus and EDR, patching on a schedule, and a build image that makes replacing a machine a same-day task.

    A failed or infected device is a swap, not an outage

  3. 03

    Email

    Gateway filtering for phishing, impersonation, ransomware payloads and account takeover, plus alerting on suspicious mailbox rules and sign-in behavior.

    The most common attack path is filtered before people see it

  4. 04

    Network

    Redundant internet, next-generation firewall, segmented switching and engineered wireless, with office, production, control, voice, camera and management traffic separated by policy.

    One compromised area cannot reach the rest of the business

  5. 05

    Business systems

    Cloud productivity, ERP and reporting running on top of the layers that protect them, with verified backup and a documented recovery order underneath the whole stack.

    Recovery has a tested time, not a hopeful estimate

Separation, enforced

One physical plant, several networks that cannot see each other.

FIREWALL POLICYOFFICEPRODUCTIONOT / CONTROLVOICEWIRELESSCAMERASMANAGEMENTONE POLICY SET, ENFORCED PER SEGMENT

Common questions

Straight answers, no sales theater.

Do you deploy identical infrastructure for every customer?

No. We start from a standard so nothing important gets missed, then modify it to what your operation actually needs. The layers and design principles carry over; the sizing, segment list, access policies, recovery objectives and ERP configuration are all fitted to you — a single-site professional services firm and a two-plant manufacturer end up with very different builds off the same standard.

How is access handled differently for hourly and salaried staff?

Every account uses MFA. Conditional access then scopes it: hourly employees sign in during their scheduled hours on managed devices, while salaried employees who need round-the-clock access get it with stronger device and session requirements. It reduces the off-hours attack surface without getting in the way of people who work late.

What if we already have equipment we do not want to replace?

We inventory what is in place and keep what still fits the standard. Replacement is driven by lifecycle, support status and whether the device can enforce the design — not by a preference for new hardware.

Can we see the detailed architecture diagram?

Yes, in an assessment. The full version names models, segments and addressing, which is exactly why it is not on a public web page. You receive complete as-built documentation for your own environment.

Does this work with operational technology and machine vendors?

That is a core part of it. Control equipment sits in its own zone with brokered access, so vendors keep their support model and the rest of the business stays isolated from it.

Does this baseline line up with compliance frameworks and cyber insurance?

Yes — the controls insurers and auditors ask about are in the baseline rather than bolted on later: MFA everywhere, EDR on managed endpoints, email filtering, segmented networks, least-privilege access, offsite backups with tested restores, and documented change and recovery procedures. That maps cleanly onto cyber insurance questionnaires and to CIS-style controls, and gives you evidence to point at for SOC 2, HIPAA or customer security reviews. We do not issue certifications, but we build so the answers exist before someone asks.

How long does a new site take to stand up?

Because the design is already decided, a typical new location is a days-long deployment rather than a months-long project. Timeline is driven by circuit delivery and equipment lead time far more often than by design work.

Schedule an IT assessment.

We review your network, security posture, cloud tenant and recovery plan, then hand you a plain-language report of what we found and what it means for the business.