PlcConsole
PlcConsole Remote · Controlled rollout

Operate authorized Fatek PLCs remotely

Connect each site through an outbound agent or approved VPN without exposing a raw PLC port. PlcConsole Remote enforces tenant, permission and register-policy boundaries before commands reach the PLC.

  • No raw remote tunnel
  • Serialized per PLC
  • Correlated audit history
Local-first architecture One app, two connection paths
Operator client PlcConsole Local profiles or authorized Remote resources
Local direct access Operator-managed path
Connection context Local connection profile PLC coordinates stay on the device
Direct Fatek TCP on a trusted local network
Local target Fatek PLC No PlcConsole Remote dependency
Remote Server mode Backend-mediated path
Hosted control plane Authorize, validate and serialize
Tenant Permission Policy PLC queue Audit Connectivity
Approved operation only
Site Agent or VPN route
Restricted site route
Managed target Fatek PLC No public inbound PLC port
Connect · Control · Prove

Remote access with guardrails built into the path

PlcConsole stays local-first. Remote Server mode adds a managed operating path without handing raw site-network access to the operator.

01

Connect

Bring the site online through an approved route

Use an outbound site agent or existing VPN infrastructure while keeping PLC network coordinates out of the mobile client.

02

Control

Expose only the resources and operations each user needs

Tenant scope, roles, permissions and PLC command policies are evaluated before the backend executes an operation.

03

Prove

Keep operational outcomes reviewable

Correlated events distinguish administrative changes, authorization decisions, agent state and PLC command results.

Operational Visibility

See what needs attention before it becomes a site visit

Choose a time window that matches the question, separate denied commands from operational failures and move from a signal to its detailed evidence.

PlcConsole Remote dashboard showing unhealthy PLCs, failed and denied commands, active users and site-agent attention
Problem-oriented signals across the selected 10-minute, 1-hour, 24-hour, 7-day or 30-day window.
10m Active incident 24h Operating day 7d Recurring issue 30d Longer-term pattern
Site Connectivity

Choose the route that fits the site

Connectivity provides a route, not permission. Both models still carry PlcConsole-owned operations through the same tenant and policy checks.

Outbound

Site Agent

Keep inbound site access closed

A small site service opens the connection to PlcConsole Remote and identifies the site explicitly.

  • Good for distributed or independently managed sites.
  • Exposes health and installed agent version centrally.
Managed network

VPN Route

Reuse established site networking

Use an approved VPN path where routing, firewall policy and operational ownership already exist.

  • Good for centrally administered network estates.
  • Reachability remains restricted to approved devices.

Agent Estate

Manage site identity, release and connection state together

Keep lifecycle state separate from live connection health and retain a reviewable record when the authenticated agent version changes.

PlcConsole Remote Site Agents view with the signed installer expanded for Linux amd64, Linux arm64 and macOS arm64, plus a connected active agent
The installer provides signed packages for several supported CPU architectures, with matching SHA-256 checksums and Cosign verification bundles.
Authorization Guardrails

Allow the operation, then narrow what it may reach

Permission grants the ability to attempt an operation. The assigned PLC policy narrows register families and address ranges before authoritative backend validation.

01Resolve tenant and PLC
02Check operation permission
03Apply register policy
04Serialize and record

Policy-Bounded Commands

Keep effective register boundaries explicit

Policies describe allowed read, write and control rules per Fatek register family with optional ranges that respect the family address model.

PlcConsole Remote command policy catalog showing bounded register access policies
Command policies make register-family and address-range restrictions visible to administrators.
Audit Evidence

Move from a visible symptom to correlated evidence

Filter connection, configuration, authorization, version and command events, then inspect bounded request and result details without crowding the main table.

PlcConsole Remote audit history showing an expanded site-agent version upgrade event
Expanded audit history connects the event summary with request, result and correlation context.
Interested in PlcConsole Remote?

PlcConsole Remote is deployed for invited environments. Mobile Remote mode remains in private development and is not included in the current App Store release.