SautX Secure Workspace

Work inside the protected system. Avoid a standing foothold.

Give a person the approved application, server, desktop, or web resource required for the task—ready through the workspace without local provisioning. Keep native execution and enforcement close to the protected target.

See where Secure Workspace fits

Customer fit

Let the work reach the system. Keep broad access out.

Secure Workspace supports task-scoped remote work when the result depends on an existing protected system.

Privileged maintenance

Let an administrator diagnose and repair a named system during an approved window.

Third-party support

Let a vendor use the approved service application and named target without a standing network foothold.

Constrained entry

Reach legacy, isolated, or distributed resources through a supported browser without reproducing the native runtime on every endpoint.

Worker experience

Open the assigned application. Keep the native runtime off the endpoint.

For supported workflows, a worker enters through one browser workspace and receives the named application, target, task context, session limits, and currently allowed controls. An eligible administrator-approved image can supply the application or protocol runtime without local installation or configuration.

Browser entry does not make an unmanaged endpoint trusted. Endpoint security, browser integrity, local capture paths, identity-provider controls, and customer operating procedures remain deployment responsibilities.

The worker receives

  • Approved application and named target
  • Visible view, control, clipboard, transfer, and duration capabilities
  • Explicit task context and output paths

The workflow can avoid

  • Per-worker native runtime provisioning
  • Reusable target credentials on the endpoint
  • Standing VPN access or broad network reach for the selected task

Application, protocol, image, control depth, and endpoint requirements vary by product, integration, Site, deployment, and release.

Governed session boundary

Present approved interaction. Keep native execution close to the target.

The User Portal carries the approved presentation. The selected Resource Edge validates scoped authority, materializes an eligible administrator-approved runtime, owns the native target connection, and reconciles the live capabilities allowed for that session.

View, control, clipboard, upload, download, duration, recording, and related capabilities depend on the selected protocol and implementation. Crossings remain separate operations; the session ends through an explicit lifecycle decision.

Secure Workspace task pathA person starts an approved task in a user browser and enters through the User Portal. The Resource Edge validates the request, materializes an approved image as a ready session application, and connects it to the protected target. The worker does not manage the runtime, while the application, task, time, interaction, and transfer limits remain visible.SECURE WORKSPACEuser browserUSER PORTALVendor maintenanceOPEN TASKRESOURCE EDGEVALIDATE + LAUNCHAPPROVED IMAGEREADY SESSION APPTARGETVISIBLE LIMITSView + controlONService window45 MINFile transferOFF

Illustrative workflow

Third-party maintenance without a standing foothold.

Illustrative workflow pattern, not customer evidence or a product demonstration.

Required result
Complete approved maintenance during a defined window and return the named system to the required state.
Actors
Approved third-party technician, customer approver, and responsible system owner.
Selected capability
Named application and target, approved interaction controls, explicit transfer paths, and bounded session duration.
Authority to avoid
Standing VPN access, reusable general-purpose accounts, broad network reach, and open-ended file movement.
Crossings
Clipboard, upload, download, credential use, target changes, and session closeout.
Evidence
Request, approver, route, target, granted capabilities, material actions, crossings, session bounds, and outcome.
Review the third-party maintenance pattern

Product boundary and current fit

Govern the protected-system session. Keep the surrounding controls explicit.

Secure Workspace governs the selected presentation, native connection, live session capabilities, explicit crossings, duration, and attributable session evidence. Surrounding identity, network, endpoint, target-permission, and customer operating controls retain their own responsibilities.

It can coexist with VPN, ZTNA, SASE, VDI, DaaS, PAM, endpoint security, and target controls; it does not claim to replace the complete access or endpoint-security stack.

Start with the work

Bring the protected system. Define the task boundary.

Describe the result, worker, target, interaction, crossings, duration, evidence, and standing access the workflow should avoid. Do not include sensitive operational material.

Contact SautX