The Vendor Access Portal in Domum Remote Access lets third-party users register, authenticate, and request time-limited access to the resources an administrator publishes for them.
The portal adds a self-service channel on top of the existing Domum flows. It does not remove or change how administrators grant access. Both models coexist.
Key terms
- Tenant: the organization that runs Domum Remote Access and operates the portal. To a third-party user, this is the customer they work for.
- Vendor organization: a group of third-party users that an administrator configures, each with its own access limits.
Who uses the portal
- Security administrator: activates and configures the portal for the tenant, defines limits per vendor organization, publishes resources, and approves registrations and access requests.
- Portal administrator: a delegated role with scoped permissions to manage portal settings, vendor organizations, and published resources.
- Third-party user: any Domum limited user, typically a vendor, MSP, or auditor, who self-registers, requests access, and connects to authorized resources.
What the portal enables
- Self-registration: a third party registers through the portal's dedicated URL, instead of depending on the customer's team to create the account.
- Administrator approval: a new registration stays pending and cannot see resources or sign in until an administrator approves it.
- Scoped catalog: after approval, the user sees only the resources published for their organization.
- Structured access requests: the user requests a resource with a justification, a session duration within the allowed limits, and an optional ITSM ticket reference.
- Mediated, recorded sessions: approved sessions open through the Segura® Web Proxy, with no direct connection to the target and full session recording.
How access flows
- The administrator activates the portal and publishes resources to specific vendor organizations.
- The third party self-registers and waits for approval.
- After approval, the third party signs in with their corporate email and MFA.
- The third party requests access to a published resource, following the active approval policy.
- On approval, the platform issues a session link scoped to that user and request, opening through the Web Proxy under the resource's session policy.
Security and audit
- Minimum disclosure: the portal never confirms whether an organization or email already exists, and blocked actions return generic messages.
- Mandatory recording: sessions are recorded and audited to the same standards as other Domum sessions, and a session cannot start if recording is unavailable.
- Dedicated audit trails: portal events (registrations, approvals, requests, session start and end, and blocked attempts) are recorded and can be exported to a SIEM.
- Automatic enforcement: per-organization limits for users, time windows, and IP or GeoIP ranges are enforced by the platform.