Connect the internal web app
Run the connector near the target app or in a segment that can reach it. The app itself does not need an inbound internet port.
Contractor access to internal web apps Guided onboarding
BusinessProxy helps publish controlled access to selected internal web apps for contractors, partners, auditors or support teams without giving their device broad network reachability.
On desktop, the primary managed path uses the BusinessProxy browser extension for session binding, browser policy and selected content controls. It is not a device VPN or an operating-system agent.
The problem
A contractor often needs one CRM, CMS admin area, service desk or staging panel. A network VPN can be segmented, but then the access model lives in routes, firewall rules, exceptions and cleanup tasks.
How it works
BusinessProxy sits between the external user and the selected internal web app. The user signs in, passes the configured checks and receives a short-lived browser session for that app.
Run the connector near the target app or in a segment that can reach it. The app itself does not need an inbound internet port.
Use your identity provider where needed, create groups, require extra verification and define who can open which app.
The user opens the approved address, passes authentication and receives a session scoped to the selected app and its policy.
Administrators can see sessions and audit events, revoke active sessions and remove future access from the group or identity-provider rule.
The connector runs inside your environment and establishes an outbound encrypted connection to BusinessProxy. It should be deployed with the least internal reachability needed for the apps it publishes.
A short session lifetime limits the current browser session, but project access ends only after the user is removed from the group, access rule or identity-provider process that grants new sessions.
Controls
Connect an identity provider when needed, use just-in-time account creation, group rules, extra verification and access keys.
App sessions are measured in minutes or hours and can be capped by policy. A three-week project should not mean a three-week browser session.
Access and security events are available in the product and can be sent to external processing through signed event notifications.
Watermarks, print and copy controls, download deterrence and screenshot friction help reduce casual mishandling of data. DLP remains a separate enterprise control.
Browser extension
For desktop users, BusinessProxy uses the browser extension to bind the browser session, apply policy and support selected content controls. The extension does not create a device-wide tunnel and does not route all system traffic through BusinessProxy.
Comparison
Use BusinessProxy when the practical task is to give external users controlled browser access to selected internal web apps. Larger enterprise access platforms may be a better primary system for company-wide programs across many traffic types and device-compliance requirements.
| Approach | Best for | What to consider |
|---|---|---|
| VPN | Network-level access for users who really need a network route. | For one web app, routes and firewall exceptions can become the access model. |
| Bastion host | Administrator access to servers and technical environments. | Useful for technical teams, usually heavy for ordinary browser access to CRM or CMS. |
| Ad-hoc reverse tunnel | Emergency or temporary connectivity during investigation. | Still needs ownership, documentation, identity, auditing and shutdown. |
| Cloudflare Access, Google IAP, Zscaler, Pomerium | Mature enterprise access programs and teams already invested in those platforms. | May be broader than needed when the immediate task is contractor access to a few internal web apps. |
| BusinessProxy | Focused contractor, partner, support and temporary access to internal web apps. | Built around app sessions, connector access, groups, revoke and audit. |
Use cases
We will review the target web app, users, groups, connector placement, session lifetime, revoke process and audit events before opening production access.