Managed Browser Access

Managed browser access for teams — without a device VPN or OS agent

BusinessProxy gives teams a controlled browser path without rolling out SASE or a device-wide VPN. Users install the BusinessProxy browser extension for a supported desktop browser, sign in, and inherit the workspace policy automatically.

On unmanaged devices, BusinessProxy governs only the browser profile where the extension is installed and enabled. Enforced deployments require validated customer-managed browser or device policy before rollout.

Setup

Set up your team in five steps

  1. Create a workspace — your policy and audit boundary.
  2. Invite people by email and assign a role.
  3. Set one workspace policy: routing mode, work domains, internal web apps, bypass rules, categories and allowed egress regions.
  4. Users install the BusinessProxy browser extension for a supported desktop browser, sign in, and receive policy automatically.
  5. Monitor sessions, devices and audit events; revoke sessions from the dashboard.

Need a different ruleset for another group? Create another workspace. SSO/SAML, SCIM and dedicated enterprise controls are available through Enterprise conversations.

Routing

Routing modes

ModeHow it works
All browser traffic`proxy_all` uses a generated PAC snapshot. Routed browser requests go through BusinessProxy except local/API/update/bypass entries.
Work sites and internal web apps`work_only` uses a generated PAC script. Approved work domains and published internal web apps use BusinessProxy; everything else goes direct.
Internal web apps only`private_app_only` routes only published internal web app hosts such as crm.acme.internal through BusinessProxy; ordinary sites stay direct.
BypassLocal, API and admin-defined bypass entries go direct.
CredentialsRandom session credentials are short-lived and rotate automatically through the extension.

Access modes

Access modes at a glance

ModeWhat it isFor
Work sites and internal web apps (default)Approved work domains and published internal web apps use BusinessProxy; everything else goes direct.Contractors, BYOD, most teams
Specific appAccess to one or more apps through managed links / aliases (Private App / Partner Access).SaaS / ERP / hosting clients
Full work browser (admin-controlled)All managed-profile browser traffic goes through the gateway, except local/excluded addresses. Enabled by an admin, not sold as general internet browsing.QA, support, approved corporate scenarios
Free work demoA limited check of sign-in, session and work access to approved domains or a demo app — never general internet.Evaluation / pilot
Freelancer professional profileOne profile with several client workspaces; personal internet stays direct. Not a consumer proxy.Freelancers (Solo Professional)

What it controls

  • Browser proxy settings while connected
  • Workspace routing policy
  • Domain/category/region decisions
  • Session limits and revocation
  • Extension managed settings when pushed by browser policy or MDM

What it does not control

  • Whole-device traffic
  • Other browsers on unmanaged devices
  • OS-level network stack
  • Personal apps, calls, local tools
  • Removal or disablement on unmanaged devices

How it works

How access is opened and closed

A user signs in, opens an approved work path, and every active session remains visible to administrators.

App Gateway

Portal launch for selected apps

With App Gateway, the user opens the portal, chooses an app available to them and receives a short-lived app session. The internal address stays behind the connector.

Managed browser

Extension route for work browsing

For managed browsing, the browser extension applies routing policy, receives temporary access data and keeps the session tied to the signed-in user.

Security

Scoped security facts your reviewer can verify

  • No TLS/HTTPS content inspection on the browser-proxy path.
  • The extension declares one content-protection script for protected sessions: watermarking, copy/print controls, download deterrence, screenshot friction and private-app page controls.
  • The content-protection script is not an advertising, analytics or arbitrary DOM automation script.
  • All-sites host permission is used to answer proxy-auth challenges for routed requests.
  • Session credentials are separate from account credentials.
  • Private/internal network ranges are blocked by policy.
  • Workspace audit events are retained separately from usage events.

See the full security model →

FAQ

Is BusinessProxy a VPN?

No. BusinessProxy does not install a device VPN and does not route the whole machine. It manages a browser path through the BusinessProxy browser extension. Non-browser traffic, local apps, calls and other browsers stay outside the BusinessProxy path.

Do users install anything?

Yes. Users need the BusinessProxy browser extension for a supported desktop browser. The point is that there is no OS-level agent and no device-wide VPN client. Enforced deployments require customer-managed browser or device policy validation.

Do you inspect HTTPS page content?

Not on the browser-proxy path. BusinessProxy enforces browser policy using domains, network metadata, category decisions and allow/deny rules. It does not decrypt HTTPS page content, read the page DOM, or inspect form fields on that path.

Why does the extension request access to all sites?

Browsers require broad host access so the extension can receive proxy-authentication challenges for routed requests and run the declared content-protection script where a protected session requires it. The extension does not use a tabs permission or arbitrary page scripting permission.

Can users bypass it on unmanaged devices?

Yes, outside the managed browser path. On an unmanaged device, a user can use another browser, another unmanaged profile, or remove/disable the extension. If bypass prevention matters, validate the browser package through customer-managed browser or device policy before rollout.

Are session credentials the account password?

No. Account login and proxy access use different credentials. Session credentials are random and short-lived. BusinessProxy validates them with a server-side keyed one-way digest and does not store the raw session credential or reuse the account password.

Start with managed browser access

Validate customer-managed browser or device policy before relying on extension enforcement or locked settings.

Managed Browser Access is one layer of the BusinessProxy access gateway. To give your own clients managed access to your installations, see Partner Access. Partner Access →