Deployment

Managed Service Responsibilities

Product, resource, identity, evidence, and support responsibilities in the CerberusD managed service.

Page type: DeploymentManaged serviceStatus: CurrentCurrent product behaviorLast reviewed: 2026-07-27

CerberusD operates the product layer as a managed service. Decision, resource readiness, session gateway, evidence retention, and revocation responsibilities have explicit owners.

Product responsibilities

  • Decision surface: Manages workspace, person, resource, assignment, policy, launch, and closure decisions.
  • Resource side: Carries readiness, last-seen, and reachability signals through an agent or gateway path.
  • Session gateway: Runs browser sessions, short-lived session context, runtime policy, and closure paths.
  • Evidence layer: Keeps launch, event, revocation, and closure records available for review.

Team responsibilities

In the managed service, the team defines resource scope, identity integration, assignment model, endpoint ownership, and evidence-review responsibility.

Healthy identity data, current resource state, and an explicit assignment model are the core inputs to session decisions.

Relationship to Zero Port

Resource ports do not become a general user access surface. Resource access runs through workspace scope, assignment, session decisions, and the managed gateway path.

Topics settled during onboarding

  • the workspace each resource joins,
  • who manages resource assignments,
  • revocation and emergency-closure ownership,
  • who reviews evidence,
  • identity-integration scope,
  • resource-side network policy ownership,
  • support scope and communication path.

These topics define how the managed service operates and where each decision remains owned.

Pilot responsibility matrix

Work Cerberus Deployment owner
Workspace, assignment, session decision, and closure flow Operates the product surface and records Defines role and scope
Windows Agent, gateway, or existing network path Consumes product signals and visible states Owns installation, egress, target reachability, and local permissions
Identity integration Uses identity and assignment context in session decisions Prepares the IdP, groups, and user lifecycle
Evidence review Relates product events Defines reviewer, retention policy, and export need

Before a first pilot, name an operations owner, an identity/network owner, and an evidence reviewer. One person can hold more than one role, but each responsibility still has a named owner.

Pilot exit and support record

At pilot exit, close new assignments, review active sessions, and handle resource connection and metadata removal according to the deployment plan. Preserve decision, session, and closure records for review; video evidence, when available, depends on the selected policy and deployment capability.

A support or escalation record includes workspace, resource identity, session identity, connection path, last-seen time, visible failure state, and the safe checks already attempted. Keep passwords, tokens, private keys, and raw connection values out. This page does not promise a specific SLA or response time; scope and communication path come from the selected service agreement.

Evidence and operations notes

Access decisions, session events, revocations, and closure records are kept in the managed audit flow. Retention and support scope follow the selected package and current product policy.