Stable

Controlled egress for approved public-origin apps

Route approved public SaaS and web apps through an allowed egress location while keeping the app visible in workspace policy and usage.

Steps

Follow these in order.

  1. 01Route the work app, not the entire deviceA workspace can define a public-origin application for a public business URL and select an approved egress location. The result is easier to review than a broad proxy-all exception.
  2. 02Make public app traffic visiblePublic-origin access events can be counted in workspace usage breakdowns as app traffic, which separates approved work app traffic from ordinary browsing.
  3. 03Not a general-purpose unblock proxyPublic-origin egress is for approved business apps under workspace policy. It is not anonymity, scraping infrastructure or a way to bypass third-party access rules.

Reference

Implementation details for setup and review.

Approved public appsSome business apps are public SaaS, but still need a predictable corporate egress country. BusinessProxy lets administrators model those apps as approved public-origin resources instead of sending the whole browser through a broad proxy.
  • Approved SaaS as an app
  • Region-aware egress
  • No private upstream abuse
  • Usage counted as app traffic
Route the work app, not the entire deviceA workspace can define a public-origin application for a public business URL and select an approved egress location. The result is easier to review than a broad proxy-all exception.
  • Business app inventory: Public SaaS destinations become named apps with owners, policy and usage context.
  • Selected egress location: The app can use a selected available location when the workspace entitlement allows it.
  • Policy guardrails: The upstream must be public; the feature is not a back door to private network addresses.
Make public app traffic visiblePublic-origin access events can be counted in workspace usage breakdowns as app traffic, which separates approved work app traffic from ordinary browsing.
  • Keep entitlement and available locations explicit.
  • Use public-origin mode only for approved business destinations.
  • Detailed egress decision history is planned separately.
Not a general-purpose unblock proxyPublic-origin egress is for approved business apps under workspace policy. It is not anonymity, scraping infrastructure or a way to bypass third-party access rules.
  • No private IP, localhost or internal DNS upstreams.
  • Universal service compatibility is validated per service.
  • This is not anonymity or anti-detection tooling.