Governed desktop and terminal access

Manage server, desktop, and terminal access from one panel.

Cerberus brings RDP, SSH, VNC, terminal, and Kubernetes resources into a centralized access plane. Agent or gateway models keep resource ports away from direct user access. Approved sessions open in the browser while assignment, credential custody, revocation, and auditable records stay in one flow.

MA
RDP, SSH, VNC, and Kubernetes accessExample resource access flow
ResourceProtocolAuthority / credentialStatusAction
ERRDPTimed accessActive
PLSSHDynamic passwordAudit on
K8KubernetesRole-basedActive
HPVNCWaiting approvalClosed
Record summary

RDP access to erp-windows-02 is open with a timed permission; start and closure events are tracked.

Where does the need begin?

Access is granted. But is it clear when access ends?

Access operations require the credential, network path, user assignment, work duration, and resulting evidence to be governed together with the connection.

  1. Credential and local-account sprawl

    RDP, SSH, and local-account material circulates across teams while credential use becomes detached from the access decision.

    PAM-governed credential custody and dynamic credentials
  2. VPN, firewall, and port overhead

    Each location and resource adds another client, profile, NAT rule, or inbound connection path.

    A private access path through an Agent or gateway
  3. People and scope tracking

    Employees, vendors, and temporary support access live in separate accounts while a single maintenance task can expand into broad network reach.

    Assignment combining identity, role, resource, and duration
  4. Tool and record fragmentation

    RDP, SSH, VNC, terminal, and Kubernetes work spans separate screens while decision, start, and closure events remain in separate records.

    Multi-protocol access with an auditable event trail
  1. 01

    Credential and local-account sprawl

    RDP, SSH, and local-account material circulates across teams while credential use becomes detached from the access decision.

    PAM-governed credential custody and dynamic credentials
  2. 02

    VPN, firewall, and port overhead

    Each location and resource adds another client, profile, NAT rule, or inbound connection path.

    A private access path through an Agent or gateway
  3. 03

    People and scope tracking

    Employees, vendors, and temporary support access live in separate accounts while a single maintenance task can expand into broad network reach.

    Assignment combining identity, role, resource, and duration
  4. 04

    Tool and record fragmentation

    RDP, SSH, VNC, terminal, and Kubernetes work spans separate screens while decision, start, and closure events remain in separate records.

    Multi-protocol access with an auditable event trail

Cerberus brings credential handling, the private access path, resource assignment, work duration, session control, and closure records into one governed access flow.

Explore the other access problems we address

The CerberusD operation path

Access begins before connection and closes when work ends.

A connection protocol establishes the access path. PAM determines who may use it, for which resource and duration, how access closes, and what evidence remains. Cerberus brings connection, authorization, session, and record into one access operation.

01User
PAMCerberus PAM control
  • Identity
  • Assignment
  • Duration
  • Live session
  • Record
  • Terminate access
02Assigned resources
  • RDP
  • SSH
  • VNC
  • Kubernetes

Users connect to assigned resources. Access decisions, session starts, state changes, revocation, and closure events remain in auditable records.

Scattered connections
One control point
Lingering permission
Timed, revocable access
Missing evidence
An auditable session trail

Connection models

Two connection models. One governed access flow.

Existing resources can connect through a gateway with the agentless model. The Windows Agent enriches readiness and health signals. Both models work together in the same workspace.

Swipe to compare both connection models

Agentless connection

Bring existing RDP, SSH, VNC, terminal, and Kubernetes targets under management through a gateway or defined access path.

  • RDP
  • SSH
  • VNC
  • K8S

Agent-assisted connection

Use the Agent on Windows machines when resource preparation, service health, and private connectivity signals are required.

  • Readiness
  • Health
  • Private path
COMMON

Assignment, duration, session, and record

In both models, the resource enters the panel, is tied to a person and time window, opens for work, and leaves a visible closure record.

  1. 01Resource
  2. 02Assignment
  3. 03Session
  4. 04Record

The Agent is an optional connection model that adds resource preparation and richer machine signals when needed. Read the Agent documentation.

First month TRY 1 campaign

Secure desktop operations from one control panel.

Choose an Agent or gateway connection model, use the verified fast setup, and govern remote machines, terminal sessions, and Kubernetes resources through one PAM-controlled flow. Start with the first-month TRY 1 campaign.

  • Optional Agent
  • Setup in minutes
  • Session lifecycle records