Policy & governance
Define conditions, scope, staged rollout, and accountable change.
The administrator application behind Antara Secure Access. Manage the client, set policy across every capability, and connect each decision to the evidence that explains it.
Capabilities share one administrative model. The client and enforcement services apply the relevant controls; your team manages their scope, lifecycle, and evidence here.
Define conditions, scope, staged rollout, and accountable change.
Enrollment, configuration, posture, presence, and recovery.
Publish resources and govern private, web, and clientless sessions.
Client and server trust, hybrid profiles, renewal, and revocation.
Client, branch, cloud, gateway, and connector context together.
Follow session evidence and review proposed responses.
Antara Admin is the administrator application for the entire Antara platform. It controls the Secure Access client and the services that deliver VPN, ZTNA, RBI, PQC, web and data protection, and SASE connectivity. Administrators work with users, devices, applications, destinations, and policies instead of maintaining a different user population for each capability.
A policy starts with scope: the tenant, user or group, device condition, resource, and action. It then states the required protection and the response when a condition is not satisfied. For example, a finance application can require an enrolled device, fresh identity verification, a registered Bluetooth companion, and an approved cryptographic profile. An unrelated website can follow an isolation policy without changing that private-application entitlement.
Separate a policy being saved from that policy being enforced. The operating view needs to show assigned versions, acknowledgments, failed updates, and stale clients. Stage broad changes through a canary group and retain the previous approved version for rollback. Emergency restrictions and routine changes may need different approval paths, but both need an attributable record.
Secure Access is the single application employees install. Antara Admin manages its enrollment, assigned capabilities, configuration, connection behavior, and diagnostic context. Existing UEM remains the distribution channel where the enterprise already uses one. Enabling RBI or adding a posture condition changes the platform policy; it should not create another workforce client installation.
| Lifecycle stage | Administrator responsibility |
|---|---|
| Enrollment | Bind the client to tenant, user, device identity, and management context. |
| Policy assignment | Apply resource, routing, cryptography, web, data, and presence requirements to the intended cohort. |
| Health and troubleshooting | Review device posture, gateway selection, certificate state, DNS, and connection evidence. |
| Change and recovery | Stage configuration updates, handle exceptions, and retain an approved rollback path. |
| Offboarding | Remove entitlements, invalidate enrollment, revoke credentials, and verify session termination. |
Antara ZTNA publishes approved private applications through the platform’s connector architecture. Administrators map the application owner, origin, DNS, required protocols, and identity entitlements. VPN routing remains available in the same client for the network scope the organization permits. A broad network route and a narrowly published application have different reach, so the administrative view must make that scope visible.
For browser-based workflows, Antara Admin decides which destinations use RBI, which resources permit clientless access, and what data may move during the session. Clientless access is an approved entry method for partners and unmanaged devices; it is governed by the same platform. It does not imply that a browser-only session provides every device signal available from an enrolled native client.
Web access policy connects URL and domain controls to SaaS activity, file movement, and isolation. The useful question is often more specific than whether a domain is allowed: can this group upload this classification of document to this tenant, from this device, under this session policy? Antara Admin gives the security team one place to manage those related requirements.
RBI policy governs remote execution and the user’s NVR/Skia experience. DLP governs permitted transfers at the configured inspection boundary. CASB adds cloud-application context. FWaaS and DNS security cover network and name-resolution policy. Each function contributes evidence to the same session record while retaining its own reason for allowing, restricting, or blocking an action.
Inspection exceptions need owners, purposes, and review dates. Record when traffic is deliberately bypassed, when an application prevents inspection, and when content cannot be evaluated. These are different outcomes. The operator needs enough context to improve policy without misreading a visibility gap as proof that no sensitive data moved.
Client identity, gateway identity, and session key agreement are separate controls under one administrative workflow. Antara Admin governs trusted issuers, credential lifecycle, permitted algorithms, and staged migration. For PQC, track the negotiated hybrid group separately from the certificate and live signature algorithms. That separation makes a fleet’s cryptographic posture understandable.
Renewal and revocation must interact with existing sessions and eligible resumption. A valid ticket is not sufficient if the underlying identity has been disabled or its policy changed. Define authentication-age limits, credential validity, revocation freshness, and the behavior of clients that cannot reach current policy. Test enforcement across gateways and regions before claiming a fleet-wide change is complete.
The agentic packet auditor is an integrated capability surfaced through Antara Admin. It combines permitted flow, browser, identity, device, and policy evidence to investigate a session. Operators can ask why access changed, which destinations appeared, or how a data transfer was handled, then follow the answer back to its source records.
A finding should identify its time range, affected entities, available evidence, and alternative explanations. Payload visibility depends on the inspection path; encrypted traffic cannot be assumed to reveal its content. Keep source-linked observations separate from inferred intent. This is especially important when an automated investigation encounters unfamiliar applications, ambiguous flows, or text supplied by an untrusted source.
Investigation and remediation have different authority. The auditor can recommend a response; administrative roles and approval policy govern execution. Record the approved action, its scope, and the policy version that results. This connects investigation back into enforcement without making an AI-generated suggestion equivalent to an authorized production change.
Antara SASE extends administration from individual clients to branches, cloud connectivity, and distributed security services. Review gateway and connector health alongside route selection, inspection outcomes, and application timing. Existing SD-WAN and cloud networking remain part of the integration map; the admin application should make the responsible system and failure boundary clear.
| Administrative concern | What the operating model tracks |
|---|---|
| Roles and separation of duties | Scoped access to configuration, diagnostics, sensitive evidence, and policy promotion. |
| Tenant boundaries | Explicit tenant context for searches, exports, integrations, and administrative actions. |
| Observability | Shared session identifiers, policy versions, timestamps, and source-linked events. |
| Network continuity | Preferred and alternate paths, connector failure domains, and intended outage behavior. |
| SIEM integration | Event mapping, delivery monitoring, retention, redaction, and access permissions. |
| Experience | Connection completion, application task latency, and policy convergence by cohort and site. |
Bring identity, endpoint, networking, PKI, application, and SOC owners into the same deployment plan. Connect their existing systems to Antara Admin, enroll a small Secure Access cohort, and publish one application. Add web and isolation policy to that same client group, then extend the tested pattern to sites and workloads. The administration model stays consistent as the capability coverage expands.
A strong evaluation leaves the team with documented resource scope, verified identity and certificate lifecycles, a reversible policy rollout, and a traceable investigation. Use the SASE integration guide for the network handoffs and the Secure Access guide for the client experience. Both describe the same platform from the perspective of the team operating it.
Investigate a TLS timeout, isolate a slow DNS lookup, or trace an RBI download decision. Compare connections, inspect source events, and prepare a scoped evidence bundle from the same workflow.
Three interactive cases. One connected workflow.
Launch Packet Auditor Lab