โ Solution Packs
Secure Network Access ยท Preview surface
Policy-first remote network access
This surface defines how DeskRemote should expose policy-first workspace network access: explicit
enrollment, route allowlists, trusted devices, MFA, revocation, kill switch, and audit. It does
not claim an active packet tunnel until the runtime adapter is proven. No general-availability
claim and no payment checkout on this page.
Access prerequisites
- Workspace owner approval
- Trusted device required
- MFA before network access
- Per-user revocation path
Route policy
- Allowlisted subnets only
- No default full-tunnel claim by default
- Workspace-scoped routes
- Readable route summary for users
Safety controls
- No silent tunnel enrollment
- No OS permission bypass
- Visible connected state
- Kill switch and audit trail
Launch gate
- Route policy saved and read back
- Unauthorized route blocked
- Disconnect removes access
- Audit records every change
Safety boundary:
Workspace network-access features may only provide explicitly authorized, revocable, and
auditable remote network access. No hidden tunnels, no permission bypass, no silent enrollment,
and no unauthorized subnet activation without workspace approval. Route allowlist and kill switch
remain mandatory before any stronger network-access claim.