DNS verification
The app domain is created only after the customer proves domain ownership through the required DNS record.
Customer-owned app domains
A user opens crm.apps.customer.com instead of a technical BusinessProxy link. The app domain is verified through DNS, the sign-in surface belongs to that app address and the internal upstream remains hidden behind the connector.
This is app-level branding: domain, launch and sign-in for a selected private app. The dashboard, support, transactional email and legal identity remain BusinessProxy-branded.
Trust at the URL bar
For partners, MSPs and customer-facing private apps, the public address matters. A verified customer domain is easier to approve, send in onboarding material and recognize in the browser.
The app domain is created only after the customer proves domain ownership through the required DNS record.
The app domain has explicit status, certificate lifecycle and launch-mode configuration.
Passkeys are scoped to the app domain; they do not silently move between unrelated domains.
Launch modes
Each app domain can use branded portal, BusinessProxy portal or extension-required launch depending on the customer rollout and risk boundary.
Current boundary
Branded app access does not replace the BusinessProxy dashboard, legal publisher identity, email sender or billing relationship. It brands the selected app entry point while preserving BusinessProxy product and legal boundaries.
Next step
The documentation page shows what to configure, how to verify the setup and which operational boundaries to review before rollout.