Enterprise security. Built for what’s next.
Antara SASE / SASE operations

Operate the whole session, not a collection of consoles.

Use Antara Admin to govern policy changes, investigate access and data events, manage continuity, and measure the experience across clients and sites.

Technical edition · Updated 7 September 2026 · 4 min read

Give every operational question a home

Antara Admin is the management application for the integrated platform. An operator can begin with a user, device, application, site, or session and follow the relevant policy and evidence. The goal is to keep an incident understandable across capabilities: a blocked file transfer, a revoked client certificate, and a failed private connector should not all appear as an unexplained VPN disconnect.

QuestionOperational viewAction to govern
Who cannot connect?Identity, client enrollment, certificates and device posture.Restore eligibility or explain the required remediation.
Why was this site isolated?Destination classification, identity and RBI rule.Review the decision and the workflow impact.
Where did sensitive data go?Permitted transfers, denied attempts and available inspection evidence.Investigate scope and change the relevant policy.
Which branch is degraded?Network path, gateway, connector and application timing.Resolve the failing segment without bypassing inspection.
Did the new policy reach the fleet?Assigned, acknowledged and enforced policy versions.Handle stale clients and failed promotion explicitly.

Treat policy as an operational change

A single control plane reduces duplicated administration, but also makes policy scope important. Separate the person drafting a broad change from the person authorized to promote it. Preview affected users, resources, and locations. Pilot the rule, observe its decisions, and promote a version that has a recorded owner and reason. A rollback should identify the previous approved policy rather than merely toggling a capability off.

An accountable policy change
AdministratorAntara AdminEnforcementAuditor / SIEM1. Draft scope, conditionsand actions2. Return validation andaffected scope3. Approve a version for thepilot4. Distribute the approvedpolicy5. Report applied versionand failures6. Emit decisions linked topolicy and session7. Provide evidence for promotion or rollback
Read the sequence as text
  1. AdministratorAntara Admin: Draft scope, conditions and actions
  2. Antara AdminAdministrator: Return validation and affected scope
  3. AdministratorAntara Admin: Approve a version for the pilot
  4. Antara AdminEnforcement: Distribute the approved policy
  5. EnforcementAntara Admin: Report applied version and failures
  6. EnforcementAuditor / SIEM: Emit decisions linked to policy and session
  7. Auditor / SIEMAdministrator: Provide evidence for promotion or rollback

Role-based administration should scope tenants, resources, evidence access, and change authority separately. A help-desk role may need connection diagnostics without access to sensitive uploaded content. An investigator may need historical events without authority to change live policy. For MSP operations, keep tenant context explicit in every search, export, and action.

Make the agentic auditor part of the operating loop

The Antara agentic packet auditor correlates permitted client, gateway, browser, network, and policy evidence. Start with a concrete question: why did an upload fail, why did a workload contact a new destination, or which sessions were affected by a changed posture rule? A useful answer identifies the relevant records, their time range, and the limits of what they show.

Preserve the distinction between observed facts and inferred intent. A large transfer can be an approved backup. A new domain can be a legitimate dependency. An encrypted flow may reveal timing and endpoints without revealing payload content. Evidence-linked investigation lets the operator judge these possibilities instead of accepting an unexplained score.

Keep proposed remediation separate from execution authority. An auditor can assemble a case and suggest a scoped response; the administrative policy decides who may apply it. Record any approved change alongside the evidence that prompted it. This makes the investigative capability part of the same client-to-control-plane story while preserving accountable operations.

Continuity without accidental bypass

Define the intended response to unavailable gateways, broken branch links, stale policy, failed inspection, and a missing companion signal. Not every failure should have the same action. A critical private application may require a redundant connector; a sensitive upload may need to wait for inspection; a known low-risk service may have a pre-approved exception. The outcome belongs in policy before the incident.

PQC operations add certificate expiry, issuer rotation, revocation propagation, and algorithm compatibility to this picture. Track resumption eligibility separately from whether a transport can reconnect. A client that still holds a ticket must not regain access after its identity is revoked. Test the propagation interval across regions and stale clients rather than assuming a saved admin change has already been enforced everywhere.

Measure the path the user actually experiences

Separate client processing, access network delay, security-edge work, isolation rendering, connector delay, and application response. A single end-to-end average cannot identify the owner of a slow experience. Track a median and tail percentiles by user cohort, site, application, and enforcement path; compare equivalent workloads when evaluating a policy change.

MeasureWhy it mattersUseful breakdown
Connection completion timeShows enrollment, authentication or transport friction.Full authentication versus eligible resumption; client OS and network.
Application task latencyCaptures what the person actually waits for.Direct private access versus isolated browser workflow.
Policy convergenceMeasures how quickly intent reaches enforcement.Assigned, acknowledged and active versions by site or client.
Revocation enforcement intervalExposes the longest stale authorization window.Gateways, resumed sessions and disconnected clients.
Inspection outcome coverageDistinguishes inspected, bypassed and unsupported traffic.Application, protocol, rule and documented exception.
Investigation completenessShows whether findings are supported.Source availability, clock alignment and traceable event identifiers.

Review these measures with the teams that own identity, endpoints, networking, applications, and the SOC. The advantage of integrated SASE is operational: one client experience, one administrative policy model, and enough shared evidence to explain the whole session. Keep the service review focused on those outcomes as the deployment grows.