Stable
Controlled egress for approved public-origin apps
Route approved public SaaS and web apps through an allowed egress location while keeping the app visible in workspace policy and usage.
Steps
Follow these in order.
- 01Route the work app, not the entire deviceA workspace can define a public-origin application for a public business URL and select an approved egress location. The result is easier to review than a broad proxy-all exception.
- 02Make public app traffic visiblePublic-origin access events can be counted in workspace usage breakdowns as app traffic, which separates approved work app traffic from ordinary browsing.
- 03Not a general-purpose unblock proxyPublic-origin egress is for approved business apps under workspace policy. It is not anonymity, scraping infrastructure or a way to bypass third-party access rules.
Reference
Implementation details for setup and review.
- Approved SaaS as an app
- Region-aware egress
- No private upstream abuse
- Usage counted as app traffic
- Business app inventory: Public SaaS destinations become named apps with owners, policy and usage context.
- Selected egress location: The app can use a selected available location when the workspace entitlement allows it.
- Policy guardrails: The upstream must be public; the feature is not a back door to private network addresses.
- Keep entitlement and available locations explicit.
- Use public-origin mode only for approved business destinations.
- Detailed egress decision history is planned separately.
- No private IP, localhost or internal DNS upstreams.
- Universal service compatibility is validated per service.
- This is not anonymity or anti-detection tooling.