Documentation Index

Fetch the complete documentation index at: https://docs.senhasegura.io/llms.txt

Use this file to discover all available pages before exploring further.

Vendor Access Portal

Prev Next

The Vendor Access Portal in Domum Remote Access lets third-party users register, authenticate, and request time-limited access to the resources an administrator publishes for them.

The portal adds a self-service channel on top of the existing Domum flows. It does not remove or change how administrators grant access. Both models coexist.

Key terms

  • Tenant: the organization that runs Domum Remote Access and operates the portal. To a third-party user, this is the customer they work for.
  • Vendor organization: a group of third-party users that an administrator configures, each with its own access limits.

Who uses the portal

  • Security administrator: activates and configures the portal for the tenant, defines limits per vendor organization, publishes resources, and approves registrations and access requests.
  • Portal administrator: a delegated role with scoped permissions to manage portal settings, vendor organizations, and published resources.
  • Third-party user: any Domum limited user, typically a vendor, MSP, or auditor, who self-registers, requests access, and connects to authorized resources.

What the portal enables

  • Self-registration: a third party registers through the portal's dedicated URL, instead of depending on the customer's team to create the account.
  • Administrator approval: a new registration stays pending and cannot see resources or sign in until an administrator approves it.
  • Scoped catalog: after approval, the user sees only the resources published for their organization.
  • Structured access requests: the user requests a resource with a justification, a session duration within the allowed limits, and an optional ITSM ticket reference.
  • Mediated, recorded sessions: approved sessions open through the Segura® Web Proxy, with no direct connection to the target and full session recording.

How access flows

  1. The administrator activates the portal and publishes resources to specific vendor organizations.
  2. The third party self-registers and waits for approval.
  3. After approval, the third party signs in with their corporate email and MFA.
  4. The third party requests access to a published resource, following the active approval policy.
  5. On approval, the platform issues a session link scoped to that user and request, opening through the Web Proxy under the resource's session policy.

Security and audit

  • Minimum disclosure: the portal never confirms whether an organization or email already exists, and blocked actions return generic messages.
  • Mandatory recording: sessions are recorded and audited to the same standards as other Domum sessions, and a session cannot start if recording is unavailable.
  • Dedicated audit trails: portal events (registrations, approvals, requests, session start and end, and blocked attempts) are recorded and can be exported to a SIEM.
  • Automatic enforcement: per-organization limits for users, time windows, and IP or GeoIP ranges are enforced by the platform.