Architecture & security
The browser never touches the station.
Every read and every write goes through this server, which holds the station's own credentials. The browser has no route to a JACE and no account on one — so what a person can do is what this server will do on their behalf, and that is a far shorter list than a Workbench session.
Your network
reached by the server
JACE / Supervisor
wiresheetDriver-rt.jar
Field devices
BACnet · Modbus · Lon
Wiresheet.ai
holds the credentials
Server
the only thing that logs in
Agent runtime
proposes · never auto-applies
AuditHistory
read from the station
Security properties
The browser holds no credentials
It has no route to a JACE and no account on one. Every read and write goes through the server, which holds the station's own login — so a tab left open on a train is not a way into the station.
Per-station credentials, sealed
Each station carries its own address and account, encrypted with AES-256-GCM before it is stored. Change one and only that station is affected.
Read-only by default
Commissioning is an explicit per-session mode gated by role. Without it, the API refuses every write, including the agent's.
Nothing applied silently
The agent produces a diff against real ORDs. A human presses apply. There is no autonomous-write mode to turn on.
The station's own audit trail
Niagara records every change in the station's AuditHistory. The workspace reads that rather than keeping a second log beside it, so an agent edit and a hand edit appear the same way, in the record your auditor already trusts.
Histories stay where they are
Trends are read on demand from the station that recorded them. Nothing bulk-copies a history out of the JACE.
What we hold
The credentials for the stations you pair, sealed with AES-256-GCM, plus the component structure, slot metadata and point values read back from them. A browser is never given any of the credentials.
What we log
Nothing you cannot already see. Niagara writes every change to the station's own AuditHistory, and the workspace reads that rather than keeping a second record beside it — so the log an auditor trusts is the one the station kept.
What we never do
We do not bulk-copy histories, and we do not change control logic without a person pressing apply. The agent has no autonomous-write mode to switch on — its edits go through the same gated path a hand edit does.
Compatibility matrix
- Niagara versions
- 4.10 · 4.11 · 4.12 · 4.13 · 4.14 · 4.15
- Platforms
- JACE-8000 · JACE-9000 · Niagara Supervisor · Workbench
- NiagaraAX
- Reachable through an N4 bridge station
- Field protocols
- BACnet/IP · BACnet MS/TP · Modbus TCP/RTU · LonWorks · oBIX
- Station module
- wiresheetDriver-rt.jar · standard station module
- Station link
- HTTP(S) from the server · the station's own account
Let it build your first sheet.
Tell us which station you want to start with and we'll set it up with you. Pairing takes about ten minutes once the account exists.
Niagara 4.10 → 4.15 · credentials server-side · writes human-gated