Complex Zscaler environments.One shared operational context.
Built on the official Zscaler OneAPI, CentaurNexus connects supported workflows for help desk, end users, administration, security, MSPs and management in one role-based context.
The right context for every role.
Assess first, then escalate.
Diagnostic context without unnecessary administrator privileges.
View the help desk flow → Security & AdminDecide with the right context.
Connect the reason, risk, role and handoff in a traceable way.
View governance → MSPKeep client context visible.
Repeatable workflows without blurring client accountability.
View the MSP perspective →User Support Center / Unified Support Center
All user information from ZIA, ZPA, and ZDX in a single view - as a cohesive overview, without requiring Zscaler admin privileges.
View →Connectivity Triage Map
Merges available ZDXsignals and policy statuses for triage, and displays possible causes such as ISP, Wi-Fi, device, or Zscaler traceable.
View →Change Effect Preview & Configuration Rollback
Check the scope and expected effect of a selected individual change before approval and prepare the targeted return path in a comprehensible way.
View →Policy Health
Configuration health as a score plus a prioritized action plan - get more out of your existing Zscaler license.
View →Privileged Access Guard
The cockpit that protects itself: the administration layer secures itself using your tenant’s zero-trust signals.
View →PAC Configuration Studio
Assemble PAC files from building blocks instead of typing them: every rule is a click, the generated code sits next to it, and a linter checks along.
View →Log Verdict
Upload the client log bundle and get a clear finding back - instead of working through lines until the pattern shows.
View →Change Package Builder
Bundle changes from different areas into one change, explain it in the board and fill the fields in your ITSM system.
View →User context at a glance.
Support enters an email address. CentaurNexus runs the OneAPI queries in parallel and combines web status, application access and connection quality into one coherent finding with around 70 data points per user. No portal switch and no broad Zscaler admin rights.
Is it Zscaler - or not?
When a call stutters, merges CentaurNexus available ZDXsignals, device and policy status into a triage view. In this way, possible causes such as ISP, WLAN, device or Zscaler with their source context can be checked.
Test first. Roll back granularly when in doubt.
No more fear of policy changes - you can see the impact before a rule goes live and can undo every single step in granular detail.
Test first
Test the impact of a policy change against real usage patterns before a single rule goes live - across URL/cloud app, DNS, firewall, and file type masks.
- Preview the impact against real traffic patterns.
- Retrospective over 7, 14, or 30 days.
- Release and execution according to tenant policy.
Roll back granularly when in doubt
Changes in supported workflows are tracked individually. Where a take-back path is available, the affected change can be undone in a targeted manner.
- Granular rollback of individual changes.
- Diff preview before reverting - you can see in advance what will change.
- Audit records selection, approval status, target effect and read-back.
Get more out of your existing Zscaler license.
Policy Health classifies configuration findings as comprehensible indications. Source, status, data age and coverage remain visible; the selection and implementation of a change remains with humans.
Your dashboard fits in your pocket.
The native CentaurNexus admin app keeps you informed about your Zscaler environment and brings simple approvals to your smartphone. Complex rule changes deliberately remain in the full web cockpit.
For administrators, as a companion to the full web cockpit.
Right where the work happens.
Not every case starts in the portal. Two paths bring CentaurNexus to where the issue arises: into the browser and onto the user’s device.
Browser extension
The user works in the browser. The extension brings the most common actions there: request access to a blocked website, request an urgently needed app, and check the status of Teams, Zoom, and similar services before a call—all without opening the portal.
Endpoint Agent
The agent delivers only what the OneAPI does not expose: zero-trust signals from the administrator's device, which Privileged Access Guard uses to secure access to the administration layer, plus supplementary device data. The latter exclusively for customers with a licensed ZDX.
Directly in your workflows.
CentaurNexus connects supported Zscaler workflows with ticketing systems, team channels and the languages used by international organisations.
An interface for supported workflows.
Concrete availability depends on the Zscaler domain, licence and tenant configuration. Each view shows source, status, data age and coverage.
Internet Access
URL/DLP status, firewall & URL policies, shadow IT, bandwidth, geoblocking.
Private Access
App segments, vendor/partner access, PRA, microtenants, M&A clean room.
Digital Experience
Device health, ZDX Deep Tracing, Connectivity Triage Map, VIP check and Endpoint Action Center.
Current context. Better with growing history.
The official Zscaler OneAPI provides supported current context. Full use of history-based analysis and assessment additionally requires the relevant NSS and LSS feeds.
Features that make a real difference.
Self-service reduces the burden on the help desk, admin tools speed up operations, and security features close gaps - all without granting a single employee full Zscaler admin privileges.
Self-service brings supported requests directly to the user and relieves the helpdesk of avoidable portal changes and handovers.
“Why is this blocked?” + Self-unblocking
Traffic light result from the ZIA-urlLookup, plus temporary self-unblocking subject to internal rules - malware remains strictly blocked.
Most common ticketIAM Self-Service (ZIdentity)
Reset a password or temporarily suspend MFA without an IdP console and within the intended audit context.
Common help desk requestRequest App & SaaS Access
Request access to supported private applications or SaaS services; review and approval follow tenant policy.
Self-ServiceBYOD-Onboarding & Posture
Register a personal device yourself and check the compliance posture status.
Without the help deskService Tunnel Check - One-click diagnostics
Classifies available ZDX, link, and device signals, and makes the report exportable.
Source-based findingsCertificate Onboarding - developer tool setup
Zscaler Root CA Self-Service + ready-to-use config snippets for npm, pip, Docker, and git.
DeveloperView all self-service features
Access & approvals
- Time-limited website access request reviewed against tenant policy
- Application and SaaS access request under tenant policy
- DLP quarantine request
- Request an SSL/TLS inspection exception
- Travel mode activation
Diagnostics & transparency
- Service Tunnel Check - current ZDX context
- Conference Readiness - connectivity check before a video call
- Zero Trust Self-Protection - what can my IT team see?
- Service Health Overview - current Zscaler service status
- My Access - overview of assigned ZPA segments
Identity & device
- IAM self-service for supported identity workflows
- BYOD onboarding & posture check
- Certificate Onboarding - developer tool configuration
- Device self-service
Communication
- Report a categorisation issue
- Access request linked to an ITSM case
Around 70 data points in the user context – with source, status, data age and coverage. Write actions are only considered successful after target system action and read-back.
User Support Center / Unified Support Center
An Overview of ZIA/ZPA/ZDX - Unified Support Center Expanded to Include ZIdentity, PRA, EASM, and Workloads.
Core USPPolicy Hygiene Desk + Policy Conflict Review
Make orphaned, contradictory and hidden rules visible with context, impact and priority.
Test instructionsControlled policy workflow
Request a selected ZIA policy change, review it under tenant policy, log it and confirm it through read-back.
Policy & AuditKill Switch - Emergency Isolation
Trigger a supported isolation action for a compromised device in a controlled way and confirm the target-system status through read-back.
Controlled isolationChange Effect Preview - Preview rules before rollout
Review the scope and expected impact of a selected policy change before release.
Before rolloutConfiguration Rollback + Rule Set Backup
Roll back configuration changes individually - including those made directly in Zscaler.
RollbackView all admin features
Diagnose
- User Support Center / Unified Support Center
- ZDX Deep Tracing on Demand (ZDX)
- Connectivity Triage Map
- URL diagnostics & policy trace
- Shadow IT risk analysis
Policy & configuration
- Policy Hygiene Desk + Policy Conflict Review
- Controlled policy deployment under tenant policy
- Configuration Drift Review + Boost Scan
- Change Effect Preview across supported views
- Unified Deploy for selected individual changes
Deployment & Fleet
- Site Tunnel Setup for location onboarding
- Endpoint Action Center for scoped device actions
- PRA onboarding & approval
- Microtenant-Manager
Backups & resilience
- Rule Set Backup - configuration backup
- Configuration Rollback - granular recovery path
- Compliance Evidence Collector for internal evidence
- Audit stream export with asynchronous, filterable delivery
For CISOs, security teams and compliance officers: a role-based view of supported Zscaler signals without broad Zscaler admin rights.
Policy Health - Security Health Check
Assesses supported Zscaler domains with a score, prioritised findings, history and structured PDF export.
Security ReviewCompliance-Evidence-Collector
Assemble configuration, release, and audit information for internal audits in a structured manner. The legal assessment remains with the customer and his auditors.
EvidenceConfiguration Drift Review - configuration deviation findings
Expose configuration deviations as findings with source, status, data age and coverage.
Traceable findingsKill Switch - Emergency Isolation
Trigger a supported isolation action in a controlled manner and confirm its target system status via read-back.
Controlled actionAudit-Stream-Export
Export security-relevant actions asynchronously and filterable for internal evaluation and verification.
AuditData minimisation & source control
Tenant policy and adapter configuration control which data a connected source is allowed to process; Data paths remain documented.
Data pathsView all security features
Security posture
- Policy Health - health check & score
- Configuration Drift Review - configuration deviations
- Boost Scan - reviewable potential
- Risk score by user & device
Review & evidence
- Compliance Evidence Collector for internal reviews
- Audit stream export with asynchronous, filterable delivery
- Configuration Set Backup - Cross-Service-Backup
- Documented data sources and coverage
Incident Response
- Kill Switch - emergency isolation
- Configuration Rollback - granular rollback
- Rule Set Backup - configuration backup
Access & identity
- Key vault (AES-256-GCM, privileged access)
- MFA-Enforcement-Monitoring
Manage customers from one cockpit while tenant context, responsibility and separation remain visible for every managed customer.
Cross-tenant dashboard
Central overview of all managed clients - status, license tier, and utilization per client, without switching environments.
Core leversWhite-label branding
Your own branding for your end customers - CentaurNexus operates invisibly in the background.
WhitelabelDomain Scoping / Tenant Separation
Row-Level Security enforces the separation of your client tenants at the database level - not just in the user interface.
RLS EnforcedRule changes in the tenant context
Review, approve and confirm a humanly selected individual change per managed customer tenant.
Controlled individual changePer-tenant quotas
Assign API quotas and usage visibly and controllably for each tenant.
Fair-UseService and Operational Records
Document status, actions and accountability per managed client in a filterable and exportable manner.
Customer ProofView all MSP features
Administration
- Cross-Tenant-Dashboard
- Tenant and rule search across managed customers
- Roles and permissions across managed tenants
Branding & billing
- White-Label-Branding
- Domain scoping / tenant separation
- Per-tenant quotas & API usage
Operations & records
- Selected individual changes by tenant
- Audit trail by tenant
- Alerts across managed tenants
- Agreed service objectives & reporting
Partner
- MSP partner programme & enablement
- Deal registration
Built for enterprise and corporate structures.
Multi-tenant operation with granular separation and traceable audit information for complex organisational structures.
Regional production operation
CentaurNexus is provided in the agreed region. For EU customers, production operation runs entirely on STACKIT in the EU; regional rollout for the USA and APAC is approaching.
Qualified self-hosting
Deployment in customer infrastructure is qualified for the specific project. Architecture, responsibility boundaries, operations and support are defined in advance.
VIP & Executive
Priority Lane, Principal Horizon and Delegation Ledger support clearly assigned representation and protection processes with traceable audit.
Domain-Scoping
RLS-enforced tenant/domain separation - an admin sees only their own domain, not the sister domain.
Rule Set Backup
Rule set backup as JSON - anti-vendor lock-in. You retain control of your own configuration at all times.
Governance & Evidence
Tenant policy, traceable audit trail and exportable proof of operations support internal review and approval processes.
Protected access
Role-based access, MFA for privileged accounts, and secure sessions limit access to the features they need.
Fine-grained RBAC
Position-based role hierarchy plus custom roles - for complex organizational structures.
Integration
ITSM (ServiceNow / JSM / Freshservice / Zendesk) and SIEM feeds - your existing toolchain remains intact.
Support and Operational Channels
Clear responsibilities, status information and documented handovers support stable platform operation.
Custom-Domain
Access via your own (sub)domain - consistent corporate identity for your users.
Data residency & recovery
Region, backup and recovery paths are documented in the agreed operating model.
Onboarding & Professional Services
Guided onboarding plus configuration best practices - fast time-to-value.
Whitelabeling
Deploy CentaurNexus to subsidiaries under your own brand - group-wide rollout.
Privileged Access Guard
Patent-pending zero-trust self-protection at the administrative level - your trust anchor.
Qualified self-hosting
Deployment in customer infrastructure is qualified for the specific project. Architecture, responsibility boundaries, operations and support are defined in advance.
Manage tenants securely in context.
CentaurNexus combines repeatable processes with clear customer responsibility. Access remains limited to the tenants that are actually managed.
Tenant context
Classify the status, source, data age and coverage of the actual managed customer tenants without unnecessary changes of environment.
Configuration Drift Review
Target-vs.-actual comparison across all tenants - configuration deviations are immediately reported as findings.
Compliance Coverage Matrix / Customer Risk Board
Audit status, existing evidence and risk warnings per managed client in an overview.
Domain-Scoping
Strict tenant separation at the database level - no customer can see even a single data point belonging to another.
Clear customer responsibility
The role, tenant, selected action, and target system status remain visible in each workflow.
The cockpit that protects itself.
Anyone who manages a Zscaler environment is a valuable target in their own right. That’s why CentaurNexus secures its own administrative level with your tenant’s Zero-Trust signals - the administrative functions are protected by your own Zero-Trust verification, not just by a password. Access and login identity are deliberately decoupled.
Enterprise security, built-in.
Hard client isolation
PostgreSQL row-level security enforces separation at the database level - not just in the UI, and cannot be bypassed via the API.
PostgreSQL RLSSecrets in the Vault
API keys and secrets are encrypted with AES-256-GCM; the keys are stored in the vault - never in the code, never in plain text.
AES-256-GCMTraceable audit trail
Security-relevant actions capture actor, timing, tenant, selection, target status, and read-back for internal review and verification.
Audit · Read-backMFA & Secure Sessions
MFA/TOTP for privileged access, JWT with refresh token rotation, httpOnly cookies, and CSRF protection via double-submit.
MFA · JWT · CSRFHardened input and session controls
Server-side validation, rate limits, secure session cookies, and CSRF protection limit abusive and erroneous requests.
Validation · Rate-Limit · CSRFProduction operation in the EU
For EU customers, CentaurNexus runs entirely on STACKIT in the EU. Additional data paths and subprocessors are disclosed in contractual and privacy documentation.
STACKIT · EULess friction in daily work.
CentaurNexus connects supported Zscaler workflows with the appropriate role and tenant context. Limits and missing coverage remain visible instead of being presented as full support.
What annoys users - here’s how we fix it
Show more
What’s holding admins back - and how we solve it
Show more
Honestly: Not everything can be solved through the platform. We clearly explain client and OS behavior and include this information in a Help Center article.
Measure operational benefits in a comprehensible way.
Compare processing time
Measure selected pre- and post-rollout tasks with the same start and end points.
Making handovers visible
Compare how often cases are resolved at the first level or handed over with the context relevant to the decision.
Classify coverage
Evaluate source, data age, coverage, and confirmed target system effect per workflow.
Calculate your own scenario
The calculation uses your inputs to show the resulting scenario.
Experience the platform. One click, no login.
Select a role and open a prepared example scenario for the respective day-to-day work.
Tools that make everyday work easier for Zscaler admins
Three free browser tools: no login, no install, nothing leaves the browser. For everyone who maintains PAC files and resolves ZCC tickets.
PacLens
Paste a PAC file, enter a test URL: instantly see which line matches and whether DIRECT or PROXY comes back.
Open tool → Free · no sign-upPAC Configuration Studio
Click PAC rules together or import an existing PAC file, test it right away and export for Zscaler or your own hosting.
Open tool → Free · no sign-upLog Verdict
Drop in a ZCC log bundle and get a readable verdict sorted by severity instead of ten thousand lines.
Open tool →Aligned with operational scope and roles.
The offer transparently describes the tenants, roles, supported workflows, integrations and operational services involved.
Tenant Scope
- Number and type of tenants included
- Enterprise or MSP Responsibility
- Clear tenant and data demarcation
Roles & Processes
- Required roles and authorization models
- Supported Read and Write Flows
- Tenant Policy, Audit and Read-back
Integration & Operations
- Available Zscaler domains per tenant
- Required ITSM and operating adapters
- Introduction and documented responsibilities
You will receive an offer with an explicitly described scope of services. Request a price talk →