One Node Per Team, One Dashboard for All

Each team gets a fully isolated dedicated VPN - managed together from a single admin view

One Dedicated Node Per VPN

Each VPN you deploy gets its own dedicated VPN node and its own static IP address. Dev traffic never touches the Accounting node - they are completely separate at the infrastructure level.

All Managed from One Dashboard

Every VPN your organisation deploys is visible and controllable from a single admin dashboard. Provision a new team VPN, manage users, or revoke access - all in one place.

Same Credentials, Different Profiles

Users keep the same credentials across every VPN they have access to. The only difference between profiles on their device is the DNS endpoint - switching teams is as simple as selecting a different VPN profile.

Admin Controls Access Per VPN

You decide which users have access to which VPNs. A developer can be on the Dev and DevOps VPNs simultaneously. An accountant has no access to either - only the Finance VPN.

A VPN for Every Team in Your Organisation

Each department gets its own isolated node, its own static IP, and access scoped to exactly what that team needs

Engineering

Developers connect through the Engineering VPN - accessing source control, internal APIs, staging environments, and cloud infrastructure. No other team can reach these resources.

DevOps & Infrastructure

The DevOps VPN provides access to deployment pipelines, monitoring systems, and production infrastructure. Isolated from development to enforce a clean separation of environments.

Finance & Accounting

Finance teams connect through their own VPN with its own static IP - whitelisted in accounting platforms, payroll systems, and financial data sources. No other team shares this IP.

Customer Support

Support staff access CRM systems, helpdesk tools, and customer data through a dedicated VPN. Their traffic and access are fully isolated from engineering and finance.

HR & People

HR data is highly sensitive. A dedicated HR VPN restricts access to HR systems and personal data to only the people who need it - no other team has a path to these resources.

Contractors & Partners

Spin up a dedicated contractor VPN with access scoped to exactly what they need. When the engagement ends, revoke access on that VPN without touching any other team's configuration.

How Users Switch Between Team VPNs

Same credentials everywhere - the only difference between VPN profiles is the DNS endpoint

  1. Admin Grants Access

    The admin assigns the user to one or more VPNs from the dashboard. Each VPN the user has access to generates a profile they can configure on their device.

  2. User Adds VPN Profiles

    The user sets up a VPN profile for each team they belong to. Credentials are the same for every profile - only the DNS server address (the VPN endpoint) differs between them.

  3. Switch by Selecting a Profile

    To connect to a different team's network, the user simply selects the relevant VPN profile on their device. No new credentials, no re-authentication - just switch and connect.

A user with access to three VPNs - Engineering, DevOps, and Contractors - has three profiles on their device. Each profile connects to a different isolated node. Credentials are identical across all three. Switching takes seconds.

Why Isolation Matters - Least Privilege by Default

Segmenting your network by team is one of the most effective ways to contain the impact of a security incident

Least Privilege by Default

A user on the Finance VPN cannot route traffic to Engineering infrastructure - not because of a firewall rule, but because they are on an entirely different network node.

Per-Team Static IP

Each team VPN has its own static IP. Finance systems can whitelist the Finance VPN IP only. Engineering tools whitelist the Engineering VPN IP only. Clean, precise access control.

Isolated Access Logs

Access logs are scoped per VPN. Engineering connection records are kept separate from Finance - clean attribution with no cross-team contamination.

Contained Blast Radius

If a credential on one team's VPN is compromised, the attacker can only reach that team's resources. They cannot pivot to another team's node - the infrastructure stops them.

Frequently Asked Questions

Common questions about deploying multiple VPNs per team with PrivyNet

How many VPNs can one organisation deploy?

A tenant can deploy multiple VPNs - one per team, department, or use case. Each VPN gets its own dedicated node and static IP. Contact us to discuss the right configuration for your organisation's size and structure.

Do users need separate credentials for each team VPN?

No. A user's credentials are the same across every VPN they have been granted access to. The only difference between VPN profiles on their device is the DNS endpoint - the server address that identifies which team's node they are connecting to.

How does a user switch between team VPNs?

Users configure a VPN profile for each team they have access to on their device. Switching between teams is as simple as selecting a different profile - the same credentials work across all of them.

Can a user be on more than one team VPN?

Yes. An admin can grant a single user access to multiple VPNs. A developer who also does DevOps work can have profiles for both the Engineering VPN and the DevOps VPN, for example.

Is each team VPN genuinely isolated, or is it just a firewall rule?

Each VPN is a physically separate dedicated node with its own network path and its own static IP. It is not a VLAN or a firewall policy applied to shared infrastructure - the teams are on different machines entirely.

What happens when a contractor finishes their engagement?

Revoke their access to the contractor VPN from the admin dashboard. Their session is terminated immediately and their credential is invalidated for that VPN. Your other team VPNs are completely unaffected.

Give Every Team Their Own Network

Deploy a dedicated VPN for each department. Full isolation, one dashboard, and the same simple credentials your users already know.

One node per team
Full isolation
Switch profiles instantly