CerberusD docs
Technical guide and operating model
CerberusD docs explain the resource, user, agent, assignment, session, closure, and evidence flow in one technical reading surface. Guides, security, architecture, and deployment behavior are documented here step by step.
Reading path
Docs sections
Sections follow a practical reading path. Behavior, operations, and evidence deepen across focused pages.
- Start with the core concepts and the first session flow.
- Then review Agent, architecture, security, and deployment behavior.
- Use reference and troubleshooting pages to verify operating behavior.
Start
First resource, first assignment, first session, and first evidence check.
Concepts
Workspace, resource, assignment, session, closure, and credential custody model.
- ComparisonHow CerberusD compares with VPN, remote support, PAM, ZTNA, browser gateway, identity platform, and VDI approaches.
- Core modelHow CerberusD connects workspace, resource, assignment, session, closure, and evidence concepts.
- Use CasesExamples of how Cerberus fits different access operations.
- Credential custodyHow the target credential stays out of the person-facing workflow while still supporting session launch, closure, and evidence.
- Windows AgentWhat the Windows Agent does for enrollment, readiness, secure connectivity, agentless access boundaries, and evidence.
- Access problemsA source-backed catalog of common access-operations problems, and how CerberusD handles them through governed workspaces, sessions, revocation, and evidence.
Guides
Connection, invitation, assignment, session, revocation, and evidence workflows.
- WorkspacesCreate or switch workspaces, accept or decline invitations, and work in the correct scope.
- Invite usersAdd a user to a workspace, resend an invitation, or cancel it.
- User rolesChange workspace member roles in a controlled and explainable way.
- User statusSuspend, reactivate, remove a member, or reset the member's resource access.
- Timed accessCreate, extend, and terminate a time-bounded access grant.
- Connect a machineHow to enroll a Windows machine and make it available as a governed resource.
- Resource managementAdd a resource, update its connection details, and archive it safely.
- Assign resourcesAssign a member the resource and session scope they need.
- Manage accessA compact index that routes workspace, people, resource, session, and record tasks to the right guide.
- Session approvalsReview, approve, extend, or deny a session request.
- Share a sessionRequest to join an active session, use read-only viewing, and end sharing.
- Start a sessionHow to open a browser-based desktop or terminal session from an assigned resource.
- Close resource accessHow to stop a resource from launching new sessions, remove assignments, and verify closure evidence.
- Support ticketsCreate a support ticket, add context, and follow replies.
- Ticket escalationRaise a ticket for deeper review when the first support pass is not enough.
- Audit logsReview access, session, assignment, and closure records in their event context.
- NotificationsInspect the title, message, time, and read state of access and operational notifications.
Architecture
Decision flow, resource readiness, session path, evidence flow, and operating responsibilities.
- Architecture evolutionExplains why Cerberus evolved from infrastructure management into governed desktop operations.
- OverviewSummary of control plane, resource/agent plane, session gateway, and evidence plane responsibilities.
- Control planeHow the decision area interacts with identity, resource, assignment, and policy inputs before a session opens.
- Machine connectionHow the Windows connection agent contributes to resource readiness.
- Browser sessionHow the CerberusLite runtime turns approved work into a session.
- Evidence planeHow decision, actor, resource, time, closure, and outcome become a readable record.
- Failure and revocationWhen a session does not open, closes, or requires a new decision.
- Mesh and private networkHow the Windows Agent, gateway paths, and Tailscale-compatible private connectivity keep reachability separate from session authority.
Security
Identity, scope, resource readiness, credential custody, session policy, revocation, and evidence.
- Identity and SSOHow SSO, MFA, person context, assignment, and session decisions stay separate in CerberusD.
- Security modelIdentity, assignment, resource readiness, credential custody, session policy, revocation, and records.
- Zero Trust / Zero PortHow CerberusD combines identity, assignment, readiness, and session decisions without making resource ports the normal user-facing access surface.
- Identity and assignmentHow the session decision combines person, role responsibility, resource scope, duration, and readiness signals.
- Envelope encryptionHow secret material stays out of plaintext work surfaces while remaining tied to credential custody and the session decision.
- Revocation and evidenceHow the work path, local preparation, closure reason, and records are read together after access closes.
- Resource readinessHow connected-machine registration, health, readiness, and controlled local action signals become part of the session decision.
- Local accountsHow CerberusD can prepare, rotate, disable, and remove managed local Windows accounts for governed sessions.
Deployment
Product, resource, identity, evidence, and support responsibilities in the managed service.
Reference
Supported protocols, states, roles, events, and responsibilities.
- RolesWorkspace roles, access scope, resource assignments, and session records in Cerberus.
- Session flowDecision, gateway, closure, and evidence path for browser-opened desktop, terminal, or Kubernetes sessions.
- Session policiesHow session duration, work mode, clipboard, transfer, closure, and recording behavior connect to the security decision.
- Without the AgentConnection model for Linux servers, network devices, terminal targets, Kubernetes endpoints, and existing RDP/SSH/VNC resources that enter CerberusD decisions, sessions, and records without the Windows Agent.
- Compatibility and versionsA reference for checking connection paths, protocols, and release alignment.
Troubleshooting
Symptoms, likely causes, safe checks, resolutions, and escalation notes.