One consistent connection pattern
Tunnel, forwarding, policy and approval follow the same sequence at every site. The fortieth site is built like the first.
We plan the deployment the way it will later be run: one pattern for every site, endpoint distribution as part of the engagement, waves with formal acceptance, and a handover that leaves operations able to work. As an official Zscaler partner we look after more than 100,000 users today, and that operational experience goes into the plan.
The first site defines the pattern and every further site follows it. Deviations are documented and justified. This covers the connection itself as much as endpoints, approvals and the evidence afterwards.
Tunnel, forwarding, policy and approval follow the same sequence at every site. The fortieth site is built like the first.
Distribution runs through your existing device management and belongs to the rollout rather than beside it.
Criteria are fixed before the first wave and checked after each one. The project stays steerable throughout.
Runbooks, ownership and measuring points are produced during the rollout and are complete at the end.
We take them with you before the first site goes live. Sequence, effort and ownership for everything that follows derive from them.
A mobile workforce and a branch office are connected differently. We fix the route per user group and plan both variants cleanly side by side.
Through existing device management or manually. This decision sets wave size, pace, and who is able to halt a wave.
Which values mark a wave as sound is fixed before the start, so releasing the next wave rests on figures.
A sequence that the business, operations and project management can all agree on. After the pilot there is a deliberate decision before the wider rollout follows.
We work inside your existing device management, build the packages, plan the assignment and evidence that it arrived.
Package, assignment, sequence and delivery evidence, including a rule for devices that do not check in for a longer period.
Separate management, separate approvals, the same standard: no action required from users, and a verifiable result.
We record them early and decide whether they are connected through the site or stay deliberately outside.
Internal application access behaves differently from internet traffic. Both are planned, counted separately and rolled out in their own waves.
The connecting component sits where the application runs. Count, placement and resilience are fixed before the first application.
Every user group moves on its own, with a rehearsed way back. A shared cut-over date is not needed.
Because we also run Zscaler environments after the project, we know the places that generate effort later. They are already accounted for in the rollout.
The groups needed from your identity management are in place before any rule references them.
Every exception is given an expiry date and a name, which keeps the set manageable.
The route back is played through once in full before the first wave goes into production.
Operations and project work together for a defined period rather than changing over in a single meeting.
The deliverables are cut so that your team can use them independently.
As an official Zscaler partner we plan the deployment, carry out the migration from your existing system, and take on operations on request. For that operation we developed our own cockpit. More than 100,000 users are looked after this way today.
Assessment of your current rules, target picture, pilot and every wave of the rollout through to the last site. You keep the decisions, we handle the implementation.
Survey, target picture, pilot, waves, handover: the same five stages whether it is one site or forty, with one stop after the pilot.
Runbooks, named ownership and, on request, ongoing operations. You are not dependent on us, but you can count on us.
Born out of our own project experience as a Zscaler partner: CentaurNexus brings ZIA, ZPA and ZDX together in one interface. One search, one view, hosting in Germany. We use it in the project ourselves, and you can keep running it afterwards.
We map your starting position, the two core decisions and the shape of the first wave.