Development previewFeatures and availability may change while we test.
Reach Managed
Open an enrolled endpoint from one browser tab.
Use an OS-running SSH session in Reach while Beam supplies the supporting outbound transport. Reach owns the session, protocol choice, and browser viewer.
Setup needed
The managed session path is available after administrator enrollment and protocol setup.
The example stays inside the shipped OS-running SSH path. It does not promote beta policy, audit-export, Direct Listen, or every-state coverage.
Reach managed SSH session
Setup needed for first use
An already enrolled, OS-running endpoint with SSH enabled is selected in aaDash. Reach opens a browser terminal over Beam, and the endpoint SSH service performs native authentication.
1
Step 1: Prepare the managed endpoint
An administrator enrolls the endpoint, keeps the agent connected over outbound 443, and enables SSH. No public setup command is shown.
2
Step 2: Choose SSH in Reach
A signed-in operator selects an accessible endpoint and the enabled SSH option. Unknown or disabled protocols must remain denied.
3
Step 3: Authenticate to local SSH
The browser terminal attaches to the endpoint local SSH service. Native SSH credentials still govern the inner session.
OS-running managed sessions are separated from setup, beta governance and integration work, and unavailable recording or full hardware-console paths.
Arivaran Reach public session coverage
Capability
Status
Condition
Managed browser SSH
Available
Available after setup when the enrolled agent is online, the OS and local sshd are running, SSH is enabled, and native SSH authentication succeeds.
RDP, VNC, and PowerShell over SSH
Available
Available on supported OS-running endpoints when each protocol, capability, and backing service is enabled. This is not a claim that every protocol exists on every OS.
Screen-share consent
Available
Available with the configured consent or credential gate. A denied user prompt or access gate must stop the session.
Public enrollment and activation
Setup needed
Setup needed. No accepted public enrollment, verification, or rollback command was found for this page.
Session ACL and per-protocol audit
Beta
Beta. RBAC and ACL enforcement remain partial. Current audit claims are metadata-only session fields, not session content or recording storage.
SIEM, posture, and Direct Listen
Beta
Beta. Decision and formatting cores exist, but live sender, tenant wiring, default-off posture configuration, and the full LAN listener path have separate integration gates.
Frozen, serial, and configured OOB states
Beta
Beta with platform and hardware gates. OS-running access is the available path; broad every-state coverage is not generally available.
Recording storage and full BMC or AMT KVM
Unavailable
Unavailable. This page does not claim stored session recordings or universal browser HTML5 KVM for hardware management controllers.
Failure states
A blocked session stays blocked.
Reach should explain the next safe check without weakening network, identity, consent, or endpoint policy.
Disconnected
Confirm transport before changing policy.
If the agent is offline or its outbound path is unavailable, no managed session opens.
Check endpoint power, agent state, DNS or proxy access, and outbound 443. Do not open an inbound endpoint port.
Permission denied
Keep the denial closed.
A rejected identity, consent prompt, or access decision must stop the session before control begins.
Confirm the signed-in identity and request access from a tenant administrator. Do not bypass consent or policy.
Setup needed
Have an administrator prepare the endpoint.
Enrollment, protocol enablement, and the local OS service are prerequisites, not steps performed by this public page.
Enroll the managed agent, enable the allowed protocol, and verify the local service. No public command is supplied here.
Capability and test evidence support these status labels. They are not a certification, authorization, service-level, or universal platform-coverage claim.