Use cases
Four ways Cloud Area Networking replaces the network you've been forced to live with.
One policy plane. One identity model. From a branch in Bavaria to a hyperscaler region — the same everywhere.
Use Case 01 — Locations
Branch offices, without the baggage.
Your home office runs on a basic router and an endpoint you trust with your most sensitive work. So why does every new branch still demand a firewall, an SD-WAN box, a NAC stack, and a VPN concentrator before a single employee can log in?
Every new site means hardware, VLANs, tunnels to HQ, contracts, attack surface. Then someone opens a laptop in a café and the whole construct is bypassed anyway. You're paying firewall prices to defend a building, not the data.
Security belongs at the endpoint, not the entrance. Every device carries a cryptographic identity, and policy travels with the user — home, office, customer site. The location gets deliberately boring: a router, internet, a Gate. Nothing public, nothing to attack.
A 12-person branch in Munich, behind a basic business router:
- The Gate is plugged in — the site is live that afternoon
- The NAS is a Dark service: only the team that owns it can see it
- Printers work on site, and nowhere else
- A legacy MES terminal on SMB-v1 — only named engineers reach it
- No public IP, no firewall rules, no site-to-site VPN
What you get
Branch CapEx collapses
A Gate replaces the firewall, NAC, and VPN concentrator in one device.
Roll-out in minutes, not weeks
Plug in, claim in Core, define services, done.
Zero public attack surface
What can't be seen can't be attacked.
Modern, legacy and OT — one site
Isolated by identity, not VLAN.
Use Case 02 — Multi-Cloud & Datacenter
Multi-cloud, without the hub-and-spoke tax.
The cloud was supposed to be elastic. Then we wrapped it in NAT, IPSec tunnels, and a hub-and-spoke topology designed for a world that no longer exists.
Every hyperscaler adds a contract, a tunnel, a routing table. Dev, Test and Prod can't share an address space without breaking something. M&A stalls on overlapping CIDRs. The agile cloud story dies the moment the network team gets a ticket.
CanMe takes the network out of the decision. Machines and people reach services because policy says so, not because two subnets happen to be routable. IP overlap stops mattering — there are no routes between zones to begin with. Any cloud, any hoster, one policy plane.
Three Azure subscriptions all on 10.0.0.0/16, one OT machine in Ingolstadt, one load test at Hetzner:
- A developer at home pushes a container from Hetzner to Ingolstadt
- Traditional path: re-IP, change requests, firewall exceptions — three weeks
- CanMe path: their identity grants service-level access for the test window
- Window closes, access is gone. The network never knew the workload existed
What you get
No hub-and-spoke tax
Traffic goes where it needs to go — not through a central choke point.
Overlapping IPs are a non-issue
Routing is identity-driven, not range-driven.
New environments in hours
Any cloud, any hoster, any partner — same policy.
Sandbox without exposure
Let teams experiment anywhere, without opening a single port.
Use Case 03 — Identity & Access
PIM is done. PAM is what's next.
You spent two years getting Entra ID right. Then you walked into a server room and realized access to the things that actually matter still depends on a firewall rule someone wrote in 2017.
PIM got users into applications cleanly. PAM — the network and infrastructure layer — is still jump hosts, VPN accounts and firewall tickets. Onboarding is fast. Off-boarding is a prayer. Every auditor, crew and vendor technician is a credential waiting to be forgotten.
Access becomes a property of identity, and identity lives in your IDP. Add someone to a group in Entra ID and exactly the access that group is entitled to appears. Remove them and it's gone everywhere, in real time. No ticket, no firewall change.
Three people, three very different needs, all handled by group membership:
- An auditor needs a reporting database for five days — the group expires on its own
- A new engineer needs SCADA from day one — inherited from their team's role
- A vendor technician needs a CNC controller at 22:00 on a Sunday — time-bound group, in within seconds
- Zero firewall changes. Full audit trail per identity, per service, per session
What you get
Deterministic off-boarding
One source of truth. No orphaned accounts.
Access reviews stop being a fire drill
Entra ID is the report.
Real-time response
Emergency vendor access measured in seconds, not hours.
One model across IT, OT, cloud, SaaS
PAM that finally matches PIM.
Use Case 04 — OT, Legacy & Compliance
Bring production into zero trust — without touching a single machine.
NIS-2 doesn't care that your highest-revenue machine still speaks SMB-v1. Your auditor doesn't either.
Industrial and legacy systems can't be patched or wrapped in an agent. The air gap is fiction the moment a vendor plugs in for remote maintenance. NIS-2, KRITIS and IEC 62443 demand segmentation; operations demands uptime. The network team loses either way.
A Hardware Gate sits in front of the machine, the line or the cell. The machine doesn't change. The PLC doesn't change. The protocol doesn't change. What changes is who can reach it — decided by identity, in real time. One controller, one audit trail, one story for the regulator.
A factory floor: 40 machines, three protocols, twelve vendors who each need occasional remote access:
- Gates sit per line, fronting the machines
- Each vendor reaches their own machines only — never the line next door, never the MES
- Internal maintenance engineers get broader, role-based access
- Zero public IPs, zero open inbound ports
- "Who touched machine 14 last Tuesday at 03:47?" is one query away
What you get
NIS-2 & KRITIS, no machine swaps
Segmentation and access control without touching production.
Vendor remote support, managed
Stops being your largest unmanaged risk.
Brownfield, greenfield, cloud, OT
One policy model across the estate.
Compliant by construction
Operationally simple, audit-ready by default.
One network. One policy. One identity model.
From the home office to the factory floor, from a hyperscaler region to a branch in Bavaria — Cloud Area Networking is the same everywhere, because security should be a property of identity, not a property of location.