Private Control Surface. An administrative or operational interface that is intentionally reachable only through governed paths, such as a private network, tunnel, identity gate, and application-level allowlist. It treats reachability itself as part of security, not as a convenience left to deployment folklore.
Private control surfaces should combine network reachability, identity, and application-level checks. They also depend on an operational state boundary, because the source repository may describe the control surface without becoming the home for live credentials, generated client configs, or host state.