DOCS
Merak operating manual
Merak governs who may talk to which service, through which route. This manual is task-oriented: find the page you need by naming the job you are trying to do, rather than by guessing a menu label.
Instead of scattering that decision across firewalls, VPN concentrators and API gateways, Merak keeps it in one place where it can be reviewed, approved and audited.
Every chapter opens with the user stories it covers ("As a …, I want …"), so you can match a chapter to the work in front of you without first learning the whole product.
Not covered here: the Agent — the Windows desktop client installed on managed personnel’s machines — is a separate product with its own documentation. This manual describes only what an administrator sees in the Console about an Agent-registered device.
The two applications this manual covers
Console
Administrators, IT operations, network and security staff
Manage members, applications, organizations, routing nodes, roles, approvals and audit trails.
Agentless Portal
Members (managed personnel)
A browser page listing the services a member may reach, and opening each one without installing anything.
Reading paths
Pick the path that matches your situation rather than reading front to back:
I am a new administrator, it is my first day
- Getting Started Sign in, set up MFA, learn the console layout.
- My Account Change your password, set your language, theme and timezone.
- Logs Read the day’s security posture at a glance.
I need to onboard people and give them access
- Members Create the accounts, send the activation mail.
- Organizations Group people so access can be granted by team, not one by one.
- Applications Publish the service and attach the members or organizations that may reach it.
- Bulk Operations Do all of the above for hundreds of rows from a spreadsheet.
I need to publish a new internal service
- Merak Nodes Make sure a routing node covers the network the service lives on.
- Applications Register the service endpoint and its virtual domain.
- Agentless Portal Optionally let people reach it from a browser with no Agent.
I am responsible for security and compliance
- Approvals Decide on pending device and token requests.
- Logs Audit log (who did what) and connection log (who reached what).
- Administrators & Roles Least-privilege role design and the anti-escalation rules.
- Permission Reference Permission keys and the page access matrix.
I am a member and I just want to reach my applications
- Agentless Portal The whole browser-based flow, end to end.
Chapter map
Eleven task chapters and three appendices. The appendices are for looking things up, not for reading.
Getting Started
Signing in, activating an account, recovering a password, setting up MFA, and finding your way around the Console.
Members
Managing the people who consume access — their accounts, their devices, and what they are allowed to reach.
Applications
Publishing a service through Merak: where the traffic really goes, what name members address it by, and who may reach it.
Organizations
Grouping members and applications so access can be granted by team rather than one person at a time.
Merak Nodes
The edge routing nodes that actually carry traffic between members and services.
Approvals
Reviewing and deciding the requests that are waiting on a human.
Logs
Two read-only records: who did what in the system, and who reached what across the network.
Administrators & Roles
Who may operate the Console, and exactly how much of it they may operate.
Bulk Operations
Doing the same thing to hundreds of records: exporting a list, acting on a selection, and importing from a spreadsheet.
My Account
Your own profile, your password, your second factor, and how the Console looks and behaves for you.
Agentless Portal
The browser page a member uses to reach their services without installing anything.
Appendices
Permission Reference
Every permission key, which page it opens, and which button it reveals.
Status Reference
Every status value in the product, what it means, and what it lets you do.
Troubleshooting
What went wrong, why, and what to do next.
Updated
Conventions
- Bold marks a button, menu item or field label as it appears on screen.
Code stylemarks a path, a permission key or a literal value.- Permissions are written as
resource:action, where the action is one letter:Ccreate,Rread,Uupdate,Ddelete. For examplemember:Ris "may view members". - Every procedure lists the permission it requires. If you do not hold it, the button is not disabled — it is not rendered at all. A missing button is almost always a missing permission, not a bug.
- Routes are written relative to the Console origin, e.g.
/member/create. - Some capabilities are behind a feature flag (agentless, images). If a section says "flag-gated" and you cannot see it, the flag is off for your deployment.
Vocabulary
- Tenant
- One customer organisation. Everything you manage lives inside your tenant.
- User
- A Console administrator account. Managed under Admin › Users.
- Member
- A managed person who consumes access (via the Agent or the Agentless Portal). Managed under Members.
- Application
- A service endpoint Merak publishes: a real backend target plus the virtual domain members address it by.
- Organization
- A group that bundles members and applications so access can be granted collectively.
- Merak Node
- An edge routing node that carries traffic. On-premises or cloud.
- Device
- A machine registered to a member by the Agent.
- Role
- A named bundle of permissions granted to Console users.
- Agentless
- Browser-based access to an application, with no Agent installed.
Need help with a deployment, or a manual tailored to your environment?
If you are evaluating Merak, planning a PoC, or need deployment instructions written against your own network, tell us what you need.