Skip to content
English

File and clipboard control

Once the connection is managed, whether data can be carried in and out is a separate question. The system collects the clipboard and file movement into five global policy keys and enforces them in four places. A stopped action is a record in itself.

The workspace toolbar of an SSH asset carries File management. The panel browses directories, uploads, downloads, creates directories, and deletes, showing size and modification time, with a second confirmation before a deletion.

The file endpoints run their gates in this order: the authorization check, the asset existence and enabled check, the access policy gate, and the data transfer gate. Paths have to be absolute, and escaping upward is not accepted.

In the “data transfer control” section of the Access Control page, all five ship as allowed:

Policy key What it governs
Paste the clipboard into the asset Sending local clipboard content to the remote
Copy the clipboard out of the asset Fetching remote clipboard content back
Upload files to the asset Uploads, and creating directories
Download files from the asset Downloads, query console result exports included
Delete files on the asset Deleting remote files

The two clipboard keys are enforced on graphical connections and apply to new connections, which the interface notes. The three file keys apply immediately to SFTP file management, the graphics channel, and container file movement.

Listing a directory falls outside these keys, so after the policy is tightened the file list is still visible and the actions become unavailable.

  1. The connection parameters of a graphical connection.
  2. The SFTP file endpoints.
  3. The instruction stream of the graphics channel, where the actual send and fetch actions are caught.
  4. The container file copy endpoints, and the query console result export endpoint.

Administrators are not exempt from these policies, and a break-glass ticket does not let them through either. When the policy cannot be resolved, the enforcement points refuse everything.

A disabled action appears as unavailable with a reason, rather than failing after you press it. The top of the panel says which actions the security policy has turned off, and notes that browsing and listing are unaffected. The text terminal offers no fake controls: an SSH terminal never shows a “paste is disabled” notice, because that layer was never one of these keys’ enforcement points.

The access control page has an expandable section that lists the boundaries of this control one by one.

When the policy for sensitive-original access alerts is enabled, viewing clipboard plaintext requires a reason and generates a medium-severity alert. The access itself is also audited.

  • Every successful file operation records the operator, asset, operation type, and remote path; uploads and downloads add the size and a content hash.
  • Every stopped action leaves the same action type with its status marked as refused, and notes which gate stopped it.
  • Creating a directory is decided on the upload key, while the audit action is still recorded as creating a directory; the two are not conflated.
  • When the connection is made, the five capabilities in effect for that session are written into the session record.
  • A change to a policy key leaves a record with the person, the key, and the old and new values.