Privileged maintenance
Let an administrator diagnose and repair a named system during an approved window.
Give a person the approved application, server, desktop, or web resource required for the task—ready through the workspace without local provisioning. Keep native execution and enforcement close to the protected target.
See where Secure Workspace fitsCustomer fit
Secure Workspace supports task-scoped remote work when the result depends on an existing protected system.
Let an administrator diagnose and repair a named system during an approved window.
Let a vendor use the approved service application and named target without a standing network foothold.
Reach legacy, isolated, or distributed resources through a supported browser without reproducing the native runtime on every endpoint.
Worker experience
For supported workflows, a worker enters through one browser workspace and receives the named application, target, task context, session limits, and currently allowed controls. An eligible administrator-approved image can supply the application or protocol runtime without local installation or configuration.
Browser entry does not make an unmanaged endpoint trusted. Endpoint security, browser integrity, local capture paths, identity-provider controls, and customer operating procedures remain deployment responsibilities.
Application, protocol, image, control depth, and endpoint requirements vary by product, integration, Site, deployment, and release.
Governed session boundary
The User Portal carries the approved presentation. The selected Resource Edge validates scoped authority, materializes an eligible administrator-approved runtime, owns the native target connection, and reconciles the live capabilities allowed for that session.
View, control, clipboard, upload, download, duration, recording, and related capabilities depend on the selected protocol and implementation. Crossings remain separate operations; the session ends through an explicit lifecycle decision.
Illustrative workflow
Illustrative workflow pattern, not customer evidence or a product demonstration.
Product boundary and current fit
Secure Workspace governs the selected presentation, native connection, live session capabilities, explicit crossings, duration, and attributable session evidence. Surrounding identity, network, endpoint, target-permission, and customer operating controls retain their own responsibilities.
It can coexist with VPN, ZTNA, SASE, VDI, DaaS, PAM, endpoint security, and target controls; it does not claim to replace the complete access or endpoint-security stack.
Start with the work
Describe the result, worker, target, interaction, crossings, duration, evidence, and standing access the workflow should avoid. Do not include sensitive operational material.
Contact SautX