Contractor access to internal web apps Guided onboarding

Give contractors internal web apps, not a route into your network

BusinessProxy helps publish controlled access to selected internal web apps for contractors, partners, auditors or support teams without giving their device broad network reachability.

On desktop, the primary managed path uses the BusinessProxy browser extension for session binding, browser policy and selected content controls. It is not a device VPN or an operating-system agent.

Access to selected web apps, not the whole networkConnector dials out from your networkShort-lived app sessions with administrator revokeGroups, identity-provider rules and audit events

The problem

When the task is app access, VPN is the wrong unit

A contractor often needs one CRM, CMS admin area, service desk or staging panel. A network VPN can be segmented, but then the access model lives in routes, firewall rules, exceptions and cleanup tasks.

  • The user needs one web service, not a network segment.
  • Temporary exceptions are easy to open and easy to forget.
  • The useful object is visible: user, app, conditions, session, revoke.

How it works

Access is scoped to the app session

BusinessProxy sits between the external user and the selected internal web app. The user signs in, passes the configured checks and receives a short-lived browser session for that app.

Connect the internal web app

Run the connector near the target app or in a segment that can reach it. The app itself does not need an inbound internet port.

Set identity and groups

Use your identity provider where needed, create groups, require extra verification and define who can open which app.

Give access to the contractor

The user opens the approved address, passes authentication and receives a session scoped to the selected app and its policy.

Review and revoke

Administrators can see sessions and audit events, revoke active sessions and remove future access from the group or identity-provider rule.

Connector: no inbound port for the internal app

The connector runs inside your environment and establishes an outbound encrypted connection to BusinessProxy. It should be deployed with the least internal reachability needed for the apps it publishes.

  • No inbound firewall rule for the target app.
  • Allowed internal addresses are fixed and checked.
  • If the expected path is unavailable, access closes instead of falling through to a wider route.

Offboarding has two parts: active sessions and future access

A short session lifetime limits the current browser session, but project access ends only after the user is removed from the group, access rule or identity-provider process that grants new sessions.

  • Revoke active sessions to stop current browser access.
  • Remove the user from the group or identity-provider rule to block new sessions.
  • Manage the account inside CRM, CMS or the target app through that app or your provisioning process.

Controls

Controls that matter for temporary external access

Identity and groups

Connect an identity provider when needed, use just-in-time account creation, group rules, extra verification and access keys.

Short-lived sessions

App sessions are measured in minutes or hours and can be capped by policy. A three-week project should not mean a three-week browser session.

Audit events

Access and security events are available in the product and can be sent to external processing through signed event notifications.

Content controls

Watermarks, print and copy controls, download deterrence and screenshot friction help reduce casual mishandling of data. DLP remains a separate enterprise control.

Browser extension

Desktop enforcement model

For desktop users, BusinessProxy uses the browser extension to bind the browser session, apply policy and support selected content controls. The extension does not create a device-wide tunnel and does not route all system traffic through BusinessProxy.

  • No operating-system VPN client.
  • Personal traffic and other programs stay outside BusinessProxy.
  • Managed browsers can install and lock the extension through enterprise policy.
  • Extension-free access can be enabled for selected scenarios with additional verification.

Comparison

Where BusinessProxy fits

Use BusinessProxy when the practical task is to give external users controlled browser access to selected internal web apps. Larger enterprise access platforms may be a better primary system for company-wide programs across many traffic types and device-compliance requirements.

ApproachBest forWhat to consider
VPNNetwork-level access for users who really need a network route.For one web app, routes and firewall exceptions can become the access model.
Bastion hostAdministrator access to servers and technical environments.Useful for technical teams, usually heavy for ordinary browser access to CRM or CMS.
Ad-hoc reverse tunnelEmergency or temporary connectivity during investigation.Still needs ownership, documentation, identity, auditing and shutdown.
Cloudflare Access, Google IAP, Zscaler, PomeriumMature enterprise access programs and teams already invested in those platforms.May be broader than needed when the immediate task is contractor access to a few internal web apps.
BusinessProxyFocused contractor, partner, support and temporary access to internal web apps.Built around app sessions, connector access, groups, revoke and audit.

Use cases

Common starting points

  • A contractor works in CRM for three weeks.
  • An integrator needs a staging panel during setup.
  • External support checks a CMS admin area.
  • A partner team needs a single internal portal.
  • An auditor needs temporary browser access with reviewable events.

Show us the app and the access rules you need

We will review the target web app, users, groups, connector placement, session lifetime, revoke process and audit events before opening production access.