Stable

Route work domains through the right country

Route selected work domains through approved exit countries with exact host, suffix and TLD rules, plus temporary user exceptions.

Steps

Follow these in order.

  1. 01Rules are evaluated before the fallback routeRegional rules can override the normal work-domain route for a matching destination. Administrators choose whether the domain routes through an egress location, goes direct or is blocked.
  2. 02Temporary requests are boundedUsers can request temporary regional exceptions where the workspace allows it. The exception is time-limited and should be visible to administrators.
  3. 03Egress control, not stealth browsingRegional routing is a compliance and operations control for work domains. It should not be described as anonymity, anti-detection or a guarantee that third-party platforms will accept the traffic.

Reference

Implementation details for setup and review.

Per-domain egress policyWhen LinkedIn, vendor portals or QA targets need a specific egress country, the rule should be explicit: which domain, which action, which location and for how long an exception is allowed.
  • Exact, suffix and TLD matching
  • Route, direct or block actions
  • Approved egress locations
  • Temporary user requests up to 24h
Rules are evaluated before the fallback routeRegional rules can override the normal work-domain route for a matching destination. Administrators choose whether the domain routes through an egress location, goes direct or is blocked.
  • Exact host: Use for one precise destination, such as crm.vendor.example.
  • Domain suffix: Use for a controlled group of subdomains owned by the same work service.
  • TLD / zone: Use carefully for broad country or zone patterns when the policy owner accepts the blast radius.
Temporary requests are boundedUsers can request temporary regional exceptions where the workspace allows it. The exception is time-limited and should be visible to administrators.
  • Temporary exceptions are capped at 24 hours.
  • Rules should be tied to approved work domains.
  • Blocked decisions should produce reviewable events.
Egress control, not stealth browsingRegional routing is a compliance and operations control for work domains. It should not be described as anonymity, anti-detection or a guarantee that third-party platforms will accept the traffic.
  • No guarantee against third-party traffic denial.
  • No consumer VPN positioning.
  • Full egress decision history is planned separately.