Stable
Route work domains through the right country
Route selected work domains through approved exit countries with exact host, suffix and TLD rules, plus temporary user exceptions.
Steps
Follow these in order.
- 01Rules are evaluated before the fallback routeRegional rules can override the normal work-domain route for a matching destination. Administrators choose whether the domain routes through an egress location, goes direct or is blocked.
- 02Temporary requests are boundedUsers can request temporary regional exceptions where the workspace allows it. The exception is time-limited and should be visible to administrators.
- 03Egress control, not stealth browsingRegional routing is a compliance and operations control for work domains. It should not be described as anonymity, anti-detection or a guarantee that third-party platforms will accept the traffic.
Reference
Implementation details for setup and review.
- Exact, suffix and TLD matching
- Route, direct or block actions
- Approved egress locations
- Temporary user requests up to 24h
- Exact host: Use for one precise destination, such as crm.vendor.example.
- Domain suffix: Use for a controlled group of subdomains owned by the same work service.
- TLD / zone: Use carefully for broad country or zone patterns when the policy owner accepts the blast radius.
- Temporary exceptions are capped at 24 hours.
- Rules should be tied to approved work domains.
- Blocked decisions should produce reviewable events.
- No guarantee against third-party traffic denial.
- No consumer VPN positioning.
- Full egress decision history is planned separately.