Cloud ERP and on-floor web apps, granted from one place.
A confectionery and snacks manufacturer retired an OpenVPN and put its cloud-hosted ERP and its on-premise web applications behind a single access console.

Where they started.

The customer is one of India's leading sweets and snacks manufacturers, running its own retail chain and a range of restaurants across tier 1 and tier 2 cities, with exports to a long list of countries.
Its ERP moved to a public cloud while two web applications stayed in the data centre, and both were reached through an OpenVPN. That arrangement worked, and it was also the thing making every change slow: a move between on-premise and cloud meant re-doing the access rather than re-pointing it.
Retail stores needed encrypted access to the ERP modules, the two on-premise web applications had to be secured the same way, and the SAP consultants working alongside the company needed a role rather than a general entry.
What was in the way.
- Rigid pathA move between on-premise and cloud changed more than where an application lived: how people reached it had to be rebuilt as well.
- Stores to cloudEvery retail store needed encrypted access to the ERP modules hosted in a public cloud.
- Apps left behindTwo web applications stayed in the data centre and had to be governed the same way as the cloud ones.
- ConsultantsExternal SAP consultants needed application access scoped to their role, not a general-purpose login.
What was put in place.
Each control below has its own page. If a row makes a claim, the link is where you check it.
- One consoleCloud and on-premise applications are published and granted from the same place, so a workload that moves does not need its access rebuilt.More
- Device bindingAccounts are tied to registered devices and checked against several system parameters before a session opens.More
- Roles across domainsPolicies are written per role for users spanning multiple domains and for third-party agents, rather than per network segment.More

What consolidation buyswhen the estate is split
Three consequences of putting one access layer under both halves of a hybrid estate instead of one tool per half.
Traffic you can see
Third-party users and SAP consultants show up in the same view as everyone else.
Devices accounted for
Device binding and system checks decide whether a machine is fit to open a session.
Who reaches what
Access is stated per role in one console, so the answer is a policy rather than an archaeology exercise.
“With retail and FMCG based chains increasingly being targeted by malicious actors, it was necessary for us to follow an integrated, simplified approach to security. With InstaSafe, access to our SAP modules as well as our on-prem web apps was secured with a single solution, and management of access with one dashboard has made the entire security experience cost effective and seamless”
Seven more stories, filtered by sector and by the problem they started with.
All customer stories//Ready when you are//
Put both halves of your estate behind one console.
Bring a workload that is halfway to the cloud. We will show you what the access looks like before and after it finishes moving.
Regulated, air-gapped, or on-premise? See deployment options