
Portal switches lose context
A blocked website, an urgently needed application or uncertainty about connectivity before a video call starts in the browser. Yet the traditional route often leads to a separate portal, ticket form or help desk call. The URL, user context and timing can easily get lost.
The browser extension shortens that route. It exposes only the actions intended for end users. Broad Zscaler admin rights are not required.
Three common workflows
- Request website access: The current address and relevant context become a governed request.
- Request an application: The user starts a request for a required SaaS or private application.
- Check connectivity before a call: A preflight check helps classify the status of services such as Teams or Zoom.
The extension provides an additional entry point into supported CentaurNexus workflows and the organisation's established decision rules.
Self-service follows tenant policy
Tenant policy, roles and, where required, an approval determine the workflow. A write is successful only after the effect has reached the target system and a read-back confirms it.
What the help desk gains
The help desk receives the context that was already available at the user's point of work. This reduces follow-up questions and improves handovers. If deeper analysis is needed, the case can continue in the portal with the permitted user, device and connection context.
From the browser to a complete case
A useful self-service function does not end when a form is submitted. It carries enough work context forward so that the next operator does not have to start again. Depending on the workflow, this can include the current address, authenticated user, tenant, time and request type. Technical details are added only to the extent permitted by the role and tenant policy for that case.
CentaurNexus then routes the request into a defined workflow. A request that is directly permitted can continue immediately. If a decision is required, the responsible role receives a reviewable request. The user gets a clear status without navigating several vendor portals.
Website access with the right starting context
For a blocked website, the URL is only the beginning. A reliable decision can also require category, block reason, user context and the applicable policy context. When suitable historical NSS data is connected, the review can additionally show whether the access was isolated or part of a recurring pattern. If that history is unavailable, the coverage remains clearly identified.
The end user adds the business reason directly in the browser. The request reaches the intended decision path with the available context. An unspecific statement such as “the site does not work” becomes a structured case that the help desk or security team can assess more quickly.
Request applications without blurring product boundaries
An application request can concern a SaaS service or access to a private application. The available path depends on licensed Zscaler domains, configured scopes and tenant configuration. The extension therefore exposes only actions supported in the current context.
The decision remains traceable: request, reason, responsible role and outcome stay connected. If the workflow changes the target system, an accepted API request alone is not enough. Actual target-system effect and the subsequent read-back are required before the workflow is complete.
Preflight checks before Teams or Zoom
Shortly before an important call, there is no time for a full diagnostic session. A preflight check should not make a blanket attribution. It should structure the current state in plain language. Device, local network, Zscaler path and reachable service are treated as separate areas. Available ZDX data deepens this view, while CentaurNexus adds the endpoint and workflow context needed for the next action.
The result helps the user choose the next useful action. If a support case is opened, the same finding can travel with it, so the help desk does not have to collect the same information again.
Integrate the extension into daily work
- Define end-user actions and authorised roles for each tenant.
- Set the browser matrix and distribution path for supported enterprise browsers.
- Align approvals, status messages and escalations with the help desk.
- Test read-back and error states for write workflows.
- Verify coverage and data sources in the production environment.
The extension makes common requests easier to reach and starts the assigned CentaurNexus workflow where the issue or need first becomes visible. Roles, approvals and status remain connected throughout the process.
Adoption starts with understandable states
End users need to recognise whether a request has merely been recorded, is under review, was approved, was rejected or has been confirmed in the target system. Technical adapter states are translated into plain status messages. A pending review must not look like an error, and an accepted request must not appear effective before read-back.
Returning to the work context is also part of the experience. After submission, the extension should not stop at an empty confirmation. It shows the task and next useful step. If more information is requested, the user can add it without capturing URL and tenant context again.
Assess value with reviewable measures
Operational measures can show whether the extension improves daily work. Examples include complete handovers, avoided follow-up questions, time to first qualified assessment, the share of standard cases resolved and cases escalated because required coverage was unavailable.
These are not universal performance promises. They reflect the tenant, policy and connected data sources. A pilot should therefore begin with selected user groups and defined starting values. Only comparison in the customer's own environment shows which workflows deliver the strongest value.
Multilingual end-user interaction
The platform provides its interfaces in the languages built into the product. This matters in self-service because users should understand reasons and status without help desk translation. Domain terms, policy names and target-system values remain unambiguous while explanatory text follows the selected language.
For international tenants, acceptance testing checks that statuses, errors and calls to action carry the same domain meaning across the languages in use. Multilingual delivery becomes part of the workflow rather than a translated navigation layer.
Frequently asked questions
Does the extension replace the CentaurNexus portal?
No. It brings selected end-user functions into the browser. Deeper analysis and administrative workflows remain in the portal.
Does the user need Zscaler admin rights?
No. Access follows CentaurNexus roles and tenant policy.
Is a request approved automatically?
Only if tenant policy permits it for that workflow. Otherwise it follows the configured decision path.
Sources and further information
See the workflow in context
Choose the relevant role in the demo launcher. The demo uses prepared sample data.
Open demo launcher