<img src="https://ad.doubleclick.net/ddm/activity/src=11631230;type=pagevw0;cat=pw_allpg;dc_lat=;dc_rdid=;tag_for_child_directed_treatment=;tfua=;npa=;gdpr=${GDPR};gdpr_consent=${GDPR_CONSENT_755};ord=1;num=1?" width="1" height="1" alt="">

Security Proven, Not Promised: How RocketChat and Virtru Enable Continuous Access Control

Editorial Team
By Editorial Team

TABLE OF CONTENTS

    See Virtru In Action

    A new partnership enabling continuous access evaluation in classified collaboration environments—moving security from static decisions to real-time, attribute-based control.

    Organizations spend millions building zero trust architectures, hardening identity systems, and implementing continuous monitoring. Then someone gets clearance for a new program, joins a secured chat room, and nobody re-evaluates their access again. A person's attributes change constantly—clearances shift, program assignments rotate, security classifications evolve. But in most systems, the access decision made on day one stays frozen in time. That gap between "who was authorized when added" and "who is authorized right now" is a critical vulnerability.

    It's also the problem a new partnership between Rocket.Chat and Virtru was built to solve.

    This recap is based on the "Hash It Out" webinar:
    "How the ABAC Security Model Improves Classified Collaboration Environments."
    Watch the full conversation here. 

    The Problem: Access Frozen in Time

    A person is approved to access a classified program on Monday. On Tuesday, they rotate to a different assignment. By Wednesday, their clearance changes. But the secure chat room they joined on Monday? They still have access.

    This is a structural vulnerability that intelligence agencies, defense contractors, and coalition partners face every day. Personnel attributes shift constantly—clearances change, program assignments rotate, security classifications evolve. But access control decisions, made at a single point in time, stay frozen.

    "An access authorization event can't be simply made at a point in time. It has to be continuous. The real question is, does this subject have the authorization to access a particular resource at that moment in time?"
    — Chris Skelly, Chief Product Officer, Rocket.Chat

    The result: teams run up their budget hardening perimeters, implementing zero trust architectures, and managing identity systems. Then someone joins a room, gets access to classified data, and nobody re-evaluates whether they should still be there.

    That's the vulnerability a new partnership between Rocket.Chat and Virtru is built to close.

    Why This Matters for Classified Environments

    Organizations operating in SIPR, JWIX, or other classified networks can't rely on traditional perimeter-based security. They need continuous, attribute-based access control that works in real-time.

    Rocket.Chat, deployed globally in defense, intelligence, and critical infrastructure environments, became the natural partner for this because of how it's built: deployed anywhere, on any network, with full control over infrastructure. Virtru brought the policy engine—attribute-based access control (ABAC) expertise built on technology originally developed at the NSA.

    "The standard is not for each vendor to manage policy administration and policy decisions. That needs to be lifted up to a single source of truth."
    — Chris Skelly, Rocket.Chat

    What they built together addresses a problem that needs to be addressed: how do you enforce the same access policies across collaboration platforms, email, file sharing, and data stores without recreating policy in each tool?

    How the Partnership Works

    The architecture is simple in concept, powerful in execution:

    Rocket.Chat is the policy enforcement point (PEP).

    When someone tries to access a room, file, or channel, Rocket.Chat asks: "Can this person access this?"

    Virtru is the policy decision point (PDP).

    It holds the policies, integrates with identity systems, and returns a yes-or-no answer in real time based on current attributes.

    An identity provider (IDP)

    keeps entitlements current—pulling from ICAM systems, directory services, or other authoritative sources.

    Every access request triggers the same flow:

    1. User tries to access a room in Rocket.Chat

    2. Rocket.Chat sends a request to Virtru: user ID, room ID, required attributes

    3. Virtru retrieves the user's current attributes from the IDP

    4. Virtru compares attributes and returns yes or no

    5. Rocket.Chat enforces the decision immediately


    "Every time an individual tries to access a resource, we make a call to Virtru and say, 'Does this person have the authority to access an object with these selected attributes?' If yes, we let them in. If no, we simply deny the access. That segregation of duties where Virtru is the gold source for attributes—which can be rapidly changing—is really powerful."
    — Chris Skelly, Rocket.Chat

    The result: one policy, enforced everywhere. Instead of managing access rules in Rocket.Chat, then recreating them in email, then again in file sharing, organizations get a single policy plane that every system queries.

     

    Real-World Impact: Coalition Operations

    Where this becomes transformational is in coalition environments where personnel from different militaries, intelligence agencies, and programs need to collaborate on shared missions.

    Historically, organizations solved this by creating separate Rocket.Chat workspaces for each program. A person with SECRET clearance and TS//SCI clearance would need two separate instances, two distinct collaboration spaces. That created silos. It slowed communication. It made it harder to share context across programs.

    With continuous ABAC evaluation, a single Rocket.Chat workspace can host rooms for multiple programs, with different clearance requirements. The system continuously evaluates whether each user should see each room. Barriers that previously made cross-program collaboration impossible now dissolve.

    "ABAC continuous evaluation enables conversations that previously couldn't happen. Organizations would previously have to maintain distinct Rocket.Chat workspaces, creating barriers to communication. Those barriers are now coming down. Members of different programs, missions, units, militaries can operate within the same workspace."
    — Chris Skelly, Rocket.Chat

    Defense contractors managing subcontractors, intelligence agencies collaborating with international partners, military units coordinating across commands—all of these now happen in unified workspaces instead of siloed instances.

     

    The Onboarding Problem Nobody Solves

    In national security environments, adding a person to a classified program is slow. Background investigations, clearance verification, access approval workflows. All of that is legitimate and necessary.

    But after someone is cleared, the administrative overhead of granting access shouldn't add weeks.

    In traditional models, it does. Someone joins a program, an administrator manually adds them to the Rocket.Chat room, adds them to email distribution lists, provisions file access. Each system requires separate admin action.

    With Rocket.Chat + Virtru, it's simpler:

    "When you need to bring a new person into a national security program, the paperwork is significant. With Virtru, you're just changing an attribute on a person's entitlement store, and they automatically get access to all program material in Rocket.Chat. We've seen exercises where we reduced the time it takes to interoperate between networks from weeks down to minutes." — JP Ayyappan, Product Manager, Virtru

    Change one attribute in the identity system. Everyone who needs to act on that attribute—Rocket.Chat, email, file sharing, data stores—immediately reflects the change. No manual provisioning. No lag time.

    For mission-critical operations, that difference between weeks and minutes is transformational.

    What's Next: The Roadmap

    The partnership is live, but both teams are exploring edge cases that classified environments present:

    Attribute Mapping

    Different organizations call the same thing by different names. "Secret" in the US, "N.1" in Australia, "Fleecy Rabbit" in a coalition context. Virtru's tagging service maps equivalencies so policy works seamlessly across enclaves without recreating rules for each naming convention.

    Object Inheritance

    Rocket.Chat discussions (child channels) can inherit parent channel attributes, reducing administrative overhead.

    Real-Time Policy Sync

    When policies change in Virtru, Rocket.Chat rooms need to know. The teams are building event-based notifications so policy changes propagate immediately and downstream systems can re-evaluate access.

    Need-to-Know Attributes

    Some attributes are public; others are restricted. The partnership is addressing how to manage administrative workflows when need-to-know attributes can't even be disclosed to those managing the system.

    The Shift from Static to Real-Time

    There's a tension in security that most practitioners feel but few articulate: compliance used to live at the perimeter. Now it has to live on the data itself.

    That shift from perimeter-based security to data-centric security isn't optional anymore. It's driven by regulation, by operational reality (coalition operations require shared spaces), and by the speed at which attributes change in modern organizations.

    Rocket.Chat + Virtru represents that shift in practice. Not just talking about continuous access control, but building it into how classified teams actually collaborate at the speed of the mission.

    "Security doesn't have to slow down collaboration. When you have full confidence that everyone in a room is authorized right now, it reduces uncertainty. It enables conversations that were previously impossible." — Chris Skelly, Rocket.Chat

     

    About the Speakers

    Christopher Skelly is Chief Product Officer and Chief Commercial Officer at Rocket.Chat, the world's most widely deployed MIT open-source collaboration platform.

    JP Ayyappan is a Product Manager at Virtru, responsible for the Virtru Data Security Platform's attribute-based access control capabilities.

    This recap is based on the "Hash It Out" webinar: "How the ABAC Security Model Improves Classified Collaboration Environments." Watch the full conversation here

    Editorial Team

    Editorial Team

    The editorial team consists of Virtru brand experts, content editors, and vetted field authorities. We ensure quality, accuracy, and integrity through robust editorial oversight, review, and optimization of content from trusted sources, including use of generative AI tools.

    View more posts by Editorial Team

    See Virtru In Action