Per-domain egress policy

Route work domains through the right country

When LinkedIn, vendor portals or QA targets need a specific egress country, the rule should be explicit: which domain, which action, which location and for how long an exception is allowed.

Regional routing works inside the managed browser policy. It is not a promise to defeat third-party abuse systems or access restrictions.

Exact, suffix and TLD matchingRoute, direct or block actionsApproved egress locationsTemporary user requests up to 24h

Policy shape

Rules are evaluated before the fallback route

Regional rules can override the normal work-domain route for a matching destination. Administrators choose whether the domain routes through an egress location, goes direct or is blocked.

Exact host

Use for one precise destination, such as crm.vendor.example.

Domain suffix

Use for a controlled group of subdomains owned by the same work service.

TLD / zone

Use carefully for broad country or zone patterns when the policy owner accepts the blast radius.

Exceptions

Temporary requests are bounded

Users can request temporary regional exceptions where the workspace allows it. The exception is time-limited and should be visible to administrators.

  • Temporary exceptions are capped at 24 hours.
  • Rules should be tied to approved work domains.
  • Blocked decisions should produce reviewable events.

Current boundary

Egress control, not stealth browsing

Regional routing is a compliance and operations control for work domains. It should not be described as anonymity, anti-detection or a guarantee that third-party platforms will accept the traffic.

  • No guarantee against third-party traffic denial.
  • No consumer VPN positioning.
  • Full egress decision history is planned separately.

Next step

Review the rollout details before turning it on

The documentation page shows what to configure, how to verify the setup and which operational boundaries to review before rollout.