Self-hosted consoles, vendor admin panels, license-locked tools — publish them to the tailnet instead of the internet.
Internal tools don't belong on public IPs with basic auth hoping for the best. Publish them to the tailnet and they become reachable by name — for exactly the people your IdP says should see them, from anywhere, invisible to everyone else.
Third-party consoles with IP allowlists and no SSO are a quiet compliance problem. Put a subnet router in front of the vendor and access rides your network with your identity — the vendor never changes a thing and your auditors get real logs.
Grafana, Airflow, internal dashboards — reachable by your team from anywhere, invisible to scanners.
That one app that only does HTTP? It stays on a private tailnet address; access is identity-gated anyway.
Test instances shared with contractors via scoped tailnet access, not public URLs with basic auth.
Microservices consumed by both laptops and other services, all on one private network with one policy file.
Third-party SaaS with IP allowlists or no SSO — front them with a subnet router and your own identity.
Software licensed to office IPs keeps working from home through an exit node at the office.
Contractors reach exactly one app for exactly as long as the project runs — then the grant expires.
Stand up private access to a target's systems in an afternoon, revoke it the day the deal closes.
Grant the external auditor a scoped account for the review window; it evaporates when the engagement ends.
Sensitive briefing material on a private address that exists for the meeting, not in some vendor's cloud.
The app keeps its private address; authorized users reach it directly through the mesh with MagicDNS names. No public exposure at all.
Need to share with someone outside the tailnet? Publish a specific service through the funnel with TLS — public only for exactly that path.
Move one internal tool behind the tailnet today — free in ten minutes.