Guides

Start a Session

How to open a browser-based desktop or terminal session from an assigned resource.

Page type: GuideStart a sessionStatus: CurrentCurrent product behaviorLast reviewed: 2026-07-27

Session launch turns an assigned resource into a browser work surface or controlled private access path. Before the “Connect” action opens work, CerberusD evaluates identity, assignment, role responsibility, resource readiness, duration, policy, and credential custody state together.

Use this workflow to open an assigned resource and to verify what record remains when the work closes.

Prerequisites

  • the person is signed in to the panel,
  • the resource is connected and appears ready,
  • the person is assigned to the resource,
  • the selected protocol or work path is enabled for the deployment,
  • session time and policy allow launch,
  • credential custody or local account preparation is ready when required.

Before you begin

Seeing a resource in the list is the first visible step, not the whole decision. A resource can be visible while readiness, duration, policy, or revocation state still affects launch.

For the first run, start a short session and verify closure/evidence immediately after the session ends.

Steps

  1. Open the workspace. Use the resource view for the person who will work.
  2. Select the assigned resource. Check resource name, protocol, and access reason if shown.
  3. Read readiness state. Last-seen, connection health, and session type confirm whether launch is available.
  4. Review visible policy notes. Read-only, clipboard, duration, transfer, or observation rules shape the active session.
  5. Start the session. Send the launch request with the Connect action.
  6. Wait for the browser surface. Follow the status message while the session context is created.
  7. Work inside the policy. Use only the assigned resource and the visible session controls.
  8. End the session. Close work from the session surface or panel when the task is complete.
  9. Review the record. Confirm launch, closure reason, duration, and revocation if used.
Interface check: Assigned resource and connection button

The resource list shows launchable work only after assignment and readiness are clear enough for the current person. The connect action belongs to that resource row.

Interface check: Active session surface

When the browser-rendered session opens, visible session controls can show policy state such as read-only mode, clipboard behavior, and remaining duration.

Expected result

The session opens in the browser or configured controlled access path. The person works on the assigned resource, target credentials stay out of the everyday user workflow, and closure leaves a reviewable lifecycle record.

Failure notes

Common launch checks include:

  • missing assignment for the current person,
  • missing machine readiness,
  • missing local account preparation,
  • another active session conflicts with the launch,
  • policy blocks the selected session type.

Update the visible state, then start a new launch attempt. If the closure record is not visible, distinguish between a launch failure and a started session that later closed.

Cleanup

For temporary access, closing the browser tab is not enough. Confirm the session is closed, revoke the assignment when appropriate, and review the event record.