Use cases

Four ways Cloud Area Networking replaces the network you've been forced to live with.

One policy plane. One identity model. From a branch in Bavaria to a hyperscaler region — the same everywhere.

LocationsMulti-Cloud & DCIdentity & AccessOT & Compliance

Use Case 01 — Locations

Branch offices, without the baggage.

Your home office runs on a basic router and an endpoint you trust with your most sensitive work. So why does every new branch still demand a firewall, an SD-WAN box, a NAC stack, and a VPN concentrator before a single employee can log in?

every site = new attack surface · every laptop = VPN credential

Today's reality

Every new site means hardware, VLANs, tunnels to HQ, contracts, attack surface. Then someone opens a laptop in a café and the whole construct is bypassed anyway. You're paying firewall prices to defend a building, not the data.

The CanMe way

Security belongs at the endpoint, not the entrance. Every device carries a cryptographic identity, and policy travels with the user — home, office, customer site. The location gets deliberately boring: a router, internet, a Gate. Nothing public, nothing to attack.

In practice

A 12-person branch in Munich, behind a basic business router:

  • The Gate is plugged in — the site is live that afternoon
  • The NAS is a Dark service: only the team that owns it can see it
  • Printers work on site, and nowhere else
  • A legacy MES terminal on SMB-v1 — only named engineers reach it
  • No public IP, no firewall rules, no site-to-site VPN

What you get

Branch CapEx collapses

A Gate replaces the firewall, NAC, and VPN concentrator in one device.

Roll-out in minutes, not weeks

Plug in, claim in Core, define services, done.

Zero public attack surface

What can't be seen can't be attacked.

Modern, legacy and OT — one site

Isolated by identity, not VLAN.

Use Case 02 — Multi-Cloud & Datacenter

Multi-cloud, without the hub-and-spoke tax.

The cloud was supposed to be elastic. Then we wrapped it in NAT, IPSec tunnels, and a hub-and-spoke topology designed for a world that no longer exists.

one hub per cloud · standalone Devices orphaned

Today's reality

Every hyperscaler adds a contract, a tunnel, a routing table. Dev, Test and Prod can't share an address space without breaking something. M&A stalls on overlapping CIDRs. The agile cloud story dies the moment the network team gets a ticket.

The CanMe way

CanMe takes the network out of the decision. Machines and people reach services because policy says so, not because two subnets happen to be routable. IP overlap stops mattering — there are no routes between zones to begin with. Any cloud, any hoster, one policy plane.

In practice

Three Azure subscriptions all on 10.0.0.0/16, one OT machine in Ingolstadt, one load test at Hetzner:

  • A developer at home pushes a container from Hetzner to Ingolstadt
  • Traditional path: re-IP, change requests, firewall exceptions — three weeks
  • CanMe path: their identity grants service-level access for the test window
  • Window closes, access is gone. The network never knew the workload existed

What you get

No hub-and-spoke tax

Traffic goes where it needs to go — not through a central choke point.

Overlapping IPs are a non-issue

Routing is identity-driven, not range-driven.

New environments in hours

Any cloud, any hoster, any partner — same policy.

Sandbox without exposure

Let teams experiment anywhere, without opening a single port.

Use Case 03 — Identity & Access

PIM is done. PAM is what's next.

You spent two years getting Entra ID right. Then you walked into a server room and realized access to the things that actually matter still depends on a firewall rule someone wrote in 2017.

Auditor added to Audit-Q3Wait for ticket · firewall change · jump host setup

PIM solved · PAM still tickets, jump hosts, and tribal knowledge

Today's reality

PIM got users into applications cleanly. PAM — the network and infrastructure layer — is still jump hosts, VPN accounts and firewall tickets. Onboarding is fast. Off-boarding is a prayer. Every auditor, crew and vendor technician is a credential waiting to be forgotten.

The CanMe way

Access becomes a property of identity, and identity lives in your IDP. Add someone to a group in Entra ID and exactly the access that group is entitled to appears. Remove them and it's gone everywhere, in real time. No ticket, no firewall change.

In practice

Three people, three very different needs, all handled by group membership:

  • An auditor needs a reporting database for five days — the group expires on its own
  • A new engineer needs SCADA from day one — inherited from their team's role
  • A vendor technician needs a CNC controller at 22:00 on a Sunday — time-bound group, in within seconds
  • Zero firewall changes. Full audit trail per identity, per service, per session

What you get

Deterministic off-boarding

One source of truth. No orphaned accounts.

Access reviews stop being a fire drill

Entra ID is the report.

Real-time response

Emergency vendor access measured in seconds, not hours.

One model across IT, OT, cloud, SaaS

PAM that finally matches PIM.

Use Case 04 — OT, Legacy & Compliance

Bring production into zero trust — without touching a single machine.

NIS-2 doesn't care that your highest-revenue machine still speaks SMB-v1. Your auditor doesn't either.

vendor plugs in → reaches every machine · air-gap is fiction

Today's reality

Industrial and legacy systems can't be patched or wrapped in an agent. The air gap is fiction the moment a vendor plugs in for remote maintenance. NIS-2, KRITIS and IEC 62443 demand segmentation; operations demands uptime. The network team loses either way.

The CanMe way

A Hardware Gate sits in front of the machine, the line or the cell. The machine doesn't change. The PLC doesn't change. The protocol doesn't change. What changes is who can reach it — decided by identity, in real time. One controller, one audit trail, one story for the regulator.

In practice

A factory floor: 40 machines, three protocols, twelve vendors who each need occasional remote access:

  • Gates sit per line, fronting the machines
  • Each vendor reaches their own machines only — never the line next door, never the MES
  • Internal maintenance engineers get broader, role-based access
  • Zero public IPs, zero open inbound ports
  • "Who touched machine 14 last Tuesday at 03:47?" is one query away

What you get

NIS-2 & KRITIS, no machine swaps

Segmentation and access control without touching production.

Vendor remote support, managed

Stops being your largest unmanaged risk.

Brownfield, greenfield, cloud, OT

One policy model across the estate.

Compliant by construction

Operationally simple, audit-ready by default.

One network. One policy. One identity model.

From the home office to the factory floor, from a hyperscaler region to a branch in Bavaria — Cloud Area Networking is the same everywhere, because security should be a property of identity, not a property of location.

Found your scenario? There's more underneath it.

The platform page shows the five building blocks every one of these use cases is assembled from. The whitepapers make the argument in full — 13 pages each, free, no call required.