Deployment
Managed Service Responsibilities
Product, resource, identity, evidence, and support responsibilities in the CerberusD managed service.
CerberusD operates the product layer as a managed service. Decision, resource readiness, session gateway, evidence retention, and revocation responsibilities have explicit owners.
Product responsibilities
- Decision surface: Manages workspace, person, resource, assignment, policy, launch, and closure decisions.
- Resource side: Carries readiness, last-seen, and reachability signals through an agent or gateway path.
- Session gateway: Runs browser sessions, short-lived session context, runtime policy, and closure paths.
- Evidence layer: Keeps launch, event, revocation, and closure records available for review.
Team responsibilities
In the managed service, the team defines resource scope, identity integration, assignment model, endpoint ownership, and evidence-review responsibility.
Healthy identity data, current resource state, and an explicit assignment model are the core inputs to session decisions.
Relationship to Zero Port
Resource ports do not become a general user access surface. Resource access runs through workspace scope, assignment, session decisions, and the managed gateway path.
Topics settled during onboarding
- the workspace each resource joins,
- who manages resource assignments,
- revocation and emergency-closure ownership,
- who reviews evidence,
- identity-integration scope,
- resource-side network policy ownership,
- support scope and communication path.
These topics define how the managed service operates and where each decision remains owned.
Pilot responsibility matrix
| Work | Cerberus | Deployment owner |
|---|---|---|
| Workspace, assignment, session decision, and closure flow | Operates the product surface and records | Defines role and scope |
| Windows Agent, gateway, or existing network path | Consumes product signals and visible states | Owns installation, egress, target reachability, and local permissions |
| Identity integration | Uses identity and assignment context in session decisions | Prepares the IdP, groups, and user lifecycle |
| Evidence review | Relates product events | Defines reviewer, retention policy, and export need |
Before a first pilot, name an operations owner, an identity/network owner, and an evidence reviewer. One person can hold more than one role, but each responsibility still has a named owner.
Pilot exit and support record
At pilot exit, close new assignments, review active sessions, and handle resource connection and metadata removal according to the deployment plan. Preserve decision, session, and closure records for review; video evidence, when available, depends on the selected policy and deployment capability.
A support or escalation record includes workspace, resource identity, session identity, connection path, last-seen time, visible failure state, and the safe checks already attempted. Keep passwords, tokens, private keys, and raw connection values out. This page does not promise a specific SLA or response time; scope and communication path come from the selected service agreement.
Evidence and operations notes
Access decisions, session events, revocations, and closure records are kept in the managed audit flow. Retention and support scope follow the selected package and current product policy.