Skip to content

Customer Isolation and Access Control

MyOwnProxy scopes customer users, resources, and supported operations to a Customer. A signed-in customer user operates in the Customer context assigned to that account. Current customer operations do not provide a way to switch or change that assignment.

Resource ownership

Current authorization behavior applies Customer ownership checks to reads and changes for Gateways, Nodes, Proxies, Pools, Proxy Credentials, users, audit activity, and Observability information. A customer request for a resource outside its assigned Customer is rejected or treated as unavailable.

Relationships are also ownership-checked. For example:

  • A Node and its assigned Gateway must belong to the same Customer.
  • A Node added to a Pool must belong to the same Customer and be assigned to that Pool's Gateway.
  • Customer users cannot use supported operations to create a relationship to another Customer's Gateway, Node, or Pool.

These controls describe current authorization behavior. Customers remain responsible for protecting user accounts, choosing appropriate roles, and reviewing access when personnel or responsibilities change.

Customer roles

Customer-facing access uses two roles:

Capability ADMIN VIEWER
View normal Customer resources, status, connection information, Audit, and Observability Yes Yes
Create or change Gateways, Nodes, Proxies, and Pool membership Yes No
Access Users and manage supported user actions Yes No
Access or manage Proxy Credentials Yes No
Run the Proxy live test Yes No
Request temporary SSH access to a Node Yes No

VIEWER access is read-only on supported pages and does not imply access to every page. See Roles and Permissions for the complete current boundary.

Proxy Credential scope

Temporary Proxy Credentials are limited to Pool entry points on the Gateway that issued them. Persistent Proxy Credentials are scoped to one Customer and can authenticate at that Customer's applicable Pool and direct Node entry points. Credential verification checks the Customer associated with the Gateway; a credential from one Customer is not accepted as a credential for another Customer.

See Understanding Proxy Credentials for credential scope and Managing Proxy Credentials for lifecycle and secret handling.

MyOwnProxy administrator boundary

Some sensitive account-management, support, software-maintenance, and emergency-recovery actions are restricted to MyOwnProxy administrators. These privileges are separate from the customer-facing ADMIN role and are used for supported platform administration and support workflows.

Contact MyOwnProxy Support when an operation is not available to a Customer ADMIN. Do not share passwords, private SSH keys, Gateway enrollment material, Node provisioning material, or other secrets as part of a normal support request.