- Create a workspace — your policy and audit boundary.
- Invite people by email and assign a role.
- Set one workspace policy: routing mode, work domains, internal web apps, bypass rules, categories and allowed egress regions.
- Users install the BusinessProxy browser extension for a supported desktop browser, sign in, and receive policy automatically.
- Monitor sessions, devices and audit events; revoke sessions from the dashboard.
Managed Browser Access
Managed browser access for teams — without a device VPN or OS agent
BusinessProxy gives teams a controlled browser path without rolling out SASE or a device-wide VPN. Users install the BusinessProxy browser extension for a supported desktop browser, sign in, and inherit the workspace policy automatically.
On unmanaged devices, BusinessProxy governs only the browser profile where the extension is installed and enabled. Enforced deployments require validated customer-managed browser or device policy before rollout.
Setup
Set up your team in five steps
Need a different ruleset for another group? Create another workspace. SSO/SAML, SCIM and dedicated enterprise controls are available through Enterprise conversations.
Routing
Routing modes
| Mode | How it works |
|---|---|
| All browser traffic | `proxy_all` uses a generated PAC snapshot. Routed browser requests go through BusinessProxy except local/API/update/bypass entries. |
| Work sites and internal web apps | `work_only` uses a generated PAC script. Approved work domains and published internal web apps use BusinessProxy; everything else goes direct. |
| Internal web apps only | `private_app_only` routes only published internal web app hosts such as crm.acme.internal through BusinessProxy; ordinary sites stay direct. |
| Bypass | Local, API and admin-defined bypass entries go direct. |
| Credentials | Random session credentials are short-lived and rotate automatically through the extension. |
Access modes
Access modes at a glance
| Mode | What it is | For |
|---|---|---|
| Work sites and internal web apps (default) | Approved work domains and published internal web apps use BusinessProxy; everything else goes direct. | Contractors, BYOD, most teams |
| Specific app | Access to one or more apps through managed links / aliases (Private App / Partner Access). | SaaS / ERP / hosting clients |
| Full work browser (admin-controlled) | All managed-profile browser traffic goes through the gateway, except local/excluded addresses. Enabled by an admin, not sold as general internet browsing. | QA, support, approved corporate scenarios |
| Free work demo | A limited check of sign-in, session and work access to approved domains or a demo app — never general internet. | Evaluation / pilot |
| Freelancer professional profile | One profile with several client workspaces; personal internet stays direct. Not a consumer proxy. | Freelancers (Solo Professional) |
What it controls
- Browser proxy settings while connected
- Workspace routing policy
- Domain/category/region decisions
- Session limits and revocation
- Extension managed settings when pushed by browser policy or MDM
What it does not control
- Whole-device traffic
- Other browsers on unmanaged devices
- OS-level network stack
- Personal apps, calls, local tools
- Removal or disablement on unmanaged devices
How it works
How access is opened and closed
A user signs in, opens an approved work path, and every active session remains visible to administrators.
App Gateway
Portal launch for selected apps
With App Gateway, the user opens the portal, chooses an app available to them and receives a short-lived app session. The internal address stays behind the connector.
Managed browser
Extension route for work browsing
For managed browsing, the browser extension applies routing policy, receives temporary access data and keeps the session tied to the signed-in user.
Security
Scoped security facts your reviewer can verify
- No TLS/HTTPS content inspection on the browser-proxy path.
- The extension declares one content-protection script for protected sessions: watermarking, copy/print controls, download deterrence, screenshot friction and private-app page controls.
- The content-protection script is not an advertising, analytics or arbitrary DOM automation script.
- All-sites host permission is used to answer proxy-auth challenges for routed requests.
- Session credentials are separate from account credentials.
- Private/internal network ranges are blocked by policy.
- Workspace audit events are retained separately from usage events.
Contractors
Managed browser access for external people
Use the browser extension when project work needs a managed browser route, domain policy, traffic limits and session history.
BYOD
Work browsing without device takeover
Keep work browsing accountable on personal laptops while personal apps, calls, banking, and local tools stay outside the proxy route.
Support & Ops
Controlled work browsing for support teams
Give support and ops teams a stable managed browser path for SaaS without breaking calls or non-browser work.
FAQ
Is BusinessProxy a VPN?
No. BusinessProxy does not install a device VPN and does not route the whole machine. It manages a browser path through the BusinessProxy browser extension. Non-browser traffic, local apps, calls and other browsers stay outside the BusinessProxy path.
Do users install anything?
Yes. Users need the BusinessProxy browser extension for a supported desktop browser. The point is that there is no OS-level agent and no device-wide VPN client. Enforced deployments require customer-managed browser or device policy validation.
Do you inspect HTTPS page content?
Not on the browser-proxy path. BusinessProxy enforces browser policy using domains, network metadata, category decisions and allow/deny rules. It does not decrypt HTTPS page content, read the page DOM, or inspect form fields on that path.
Why does the extension request access to all sites?
Browsers require broad host access so the extension can receive proxy-authentication challenges for routed requests and run the declared content-protection script where a protected session requires it. The extension does not use a tabs permission or arbitrary page scripting permission.
Can users bypass it on unmanaged devices?
Yes, outside the managed browser path. On an unmanaged device, a user can use another browser, another unmanaged profile, or remove/disable the extension. If bypass prevention matters, validate the browser package through customer-managed browser or device policy before rollout.
Are session credentials the account password?
No. Account login and proxy access use different credentials. Session credentials are random and short-lived. BusinessProxy validates them with a server-side keyed one-way digest and does not store the raw session credential or reuse the account password.
Start with managed browser access
Validate customer-managed browser or device policy before relying on extension enforcement or locked settings.
Managed Browser Access is one layer of the BusinessProxy access gateway. To give your own clients managed access to your installations, see Partner Access. Partner Access →