The platform is broader than the tunnel
A remote employee, a branch office, and a service running in a cloud network all need connectivity. They do not all have a person available to click Connect. Antara SASE brings these entry points into the same policy model while preserving the distinction between a user, a device, a workload, and a site. The Secure Access client handles workforce access; connectors and network integrations extend the architecture to infrastructure.
Security Service Edge describes the security functions applied to access: ZTNA, secure web gateway, cloud application controls, and related data and threat protection. SASE adds the networking paths that bring branch, cloud, and remote traffic to those functions. An existing SD-WAN can remain the network underlay during migration. The design must state which routes enter Antara enforcement, where traffic exits, and which system owns failover.
- 01Enter
Secure Access client, approved clientless session, branch connection, or workload connector.
- 02Evaluate
Use tenant, identity, posture, destination, data context, and active policy.
- 03Enforce
Apply the relevant private-access, web, data, firewall, isolation, and cryptographic controls.
- 04Observe
Return attributable session evidence to Antara Admin and the agentic auditor.
One client does not mean every security process runs on the endpoint. RBI executes page code in the remote browser service. Web and data inspection run at the configured enforcement point. The client establishes context and steers the session; the admin application sets policy and receives evidence. This division keeps the user experience unified without hiding the actual security boundaries.
A coordinated security stack
| Capability | Role in the session | Relationship to the unified client |
|---|---|---|
| ZTNA | Authorize a named private resource using identity and current device context. | Secure Access supplies identity, posture, and the application request. |
| SWG + DNS security | Apply destination, URL category, domain, and web-threat policy. | Client steering sends the selected traffic to the inspection path. |
| CASB | Govern the use of cloud applications, corporate tenants, and sensitive actions. | The session retains the user and device context required for policy. |
| DLP | Evaluate sensitive data movement and enforce permitted destinations and actions. | Client and isolation workflows expose the relevant controlled transfer path. |
| FWaaS | Apply network and protocol rules beyond browser-only traffic. | Application-aware routing connects non-web traffic to the relevant policy. |
| RBI | Execute untrusted web content remotely with NVR and Skia presentation. | Isolation is delivered through Secure Access and its governed browser workflow. |
| PQC + mTLS | Protect the negotiated tunnel secret and authenticate its endpoints. | The same enrolled client negotiates transport and proves its identity. |
| Agentic packet auditing | Correlate access and inspection evidence into reviewable investigations. | Client context and service telemetry meet in Antara Admin. |
These controls are not a mandatory chain of eight serial appliances. The destination and policy select the path. A private database flow needs resource authorization and network policy; a risky website may need isolation; a document upload may need destination and content controls. Carrying a common session identity across the selected services makes their decisions explainable without forcing every protocol through a browser pipeline.
Follow the data, not just the connection
Allowing a SaaS domain is not the same as approving every activity on it. A user may read a public document, upload a confidential file to the corporate tenant, or move the same file into a personal account. Antara’s SASE policy combines application identity, destination, action, and data context so those cases can have different outcomes. Approved AI tools belong in this same governance model.
DLP policy needs a classification method and an enforcement point. Labels, content patterns, exact-data comparisons, and file characteristics each have different visibility and evaluation requirements. When designing advanced matching or image-text inspection, validate the specific file formats and processing limits of the deployment. Put unknown, encrypted, and unsupported files into an explicit policy outcome rather than silently interpreting an inspection failure as permission.
Inline controls govern a transaction while it crosses the access path. API-based SaaS inspection addresses stored data and configuration after a provider grants the required access. They have different timing and permissions. Plan any API connector per application, including scopes, rate limits, retention, and remediation authority; a network session alone does not grant access to an entire SaaS repository.
Read the sequence as text
- Secure Access → Security edge: Upload request with session context
- Security edge → Data policy: Evaluate destination, action, and inspectable content
- Data policy → Security edge: Allow, restrict, or block with a reason
- Security edge → Secure Access: Return the permitted result to the user
- Security edge → Antara Admin: Publish decision, session, and policy version
- Antara Admin → Data policy: Approved policy change for future evaluations
Put inspection boundaries on the architecture map
PQC protects the access tunnel; it does not give a security service permission to read arbitrary encrypted application traffic. Authorized TLS inspection requires an explicit termination and re-encryption design, trusted certificates where applicable, and policy for excluded destinations. Certificate pinning, mutual TLS, encrypted payloads inside TLS, and application compatibility can all affect visibility.
Record the client-to-edge, edge-to-isolation, connector, and origin segments separately. A hybrid access tunnel does not prove that an external SaaS origin also negotiates hybrid cryptography. Antara Admin should expose the negotiated profile and the inspection disposition so an operator can tell the difference between protected transport, inspected content, and a deliberate exception.
In RBI, page code runs remotely and NVR carries the representation back to the user. Uploads, downloads, clipboard events, and session teardown still need their own policy. The advantage is the combination of execution isolation and data governance within the same access context, not an assumption that a remote picture makes every transfer safe.
Extend to branch, cloud, and non-user traffic
A branch connection represents a location and its permitted network scope. It is not a substitute for an authenticated person. Preserve user identity where it is available; apply site, device, subnet, and resource segmentation when traffic comes from printers, sensors, shared systems, or workloads. Do not assign every device behind a branch tunnel the rights of its administrator.
Connect existing routers or SD-WAN infrastructure through an agreed supported handoff. Map route advertisements, source address translation, DNS resolution, MTU, and egress allowlists. Keep local application dependencies explicit. Application-aware path selection and network failover should preserve the intended security path instead of moving traffic to an uninspected route during an outage.
Antara Admin unifies the operating view: which clients and sites are connected, which resources are published, which policy is active, and where a session failed. The agentic auditor can then investigate across those records. Hardware models, routing protocols, cloud connectors, and deployment regions belong in the integration acceptance matrix, where compatibility can be demonstrated for the actual estate.