2 · Integrate — build for production

Take the agreed Tailscale access model into production with control.

Integrate implements the approved target model: identities, devices, Grants policies, routing, tests, GitOps, rollback and operational handover.

  • Scoped or phased project
  • Allow and deny tests
  • Price on request

When to choose Integrate

When the target model has been approved and the production rollout needs an owner.

Integrate requires a Defense First Advice delivery or equivalent approved source material. Missing architecture and ownership decisions are first scoped into Advice.

First production access path

From pilot to approved service

Build one prioritised use case and its governance model.

Migration

Retire VPN or public ingress in parallel

The new route is tested before the old one is removed, and the rollback model is documented.

Integration

Bring IdP, posture, network and automation together

The implementation is adapted to the customer's systems and selected Tailscale plan.

Production configuration

Build a manageable lifecycle, not only connectivity.

The proposal names the use cases, connectors, integrations and customer tasks to be implemented. The standard delivery components are listed below.

Identity and devices

  • administrator roles and device approval
  • groups, tags and tagOwners
  • posture baseline and required IdP integrations

Policy and network

  • Grants policies and policy tests
  • DNS, subnet routers, exit nodes or connectors
  • Tailscale SSH/JIT according to the selected use case

Automation and operations

  • GitOps validation, OAuth/API and webhooks
  • baseline audit and logging settings
  • runbook, rollback and operational handover

Acceptance

The production rollout is complete only when incorrect access is also denied.

  1. Agreed users or workloads can connect from the correct source state to the correct resource.
  2. Named invalid users, devices, resources and ports are denied.
  3. Complete-policy tests, including named denied paths, and agreed failure and recovery tests pass.
  4. The customer accepts the implementation, ownership, runbook and rollback path.

Customer deliverables

  • production configuration in the customer's tailnet
  • version-controlled policy and tests
  • architecture and responsibility-boundary documentation
  • deployment, rollback and operations runbook
  • test record and open follow-up actions

Responsibilities and boundaries

Integrate implements the agreed Tailscale scope.

The customer owns the tailnet, Git repository and documentation and arranges the required IdP, MDM, EDR, SIEM, cloud and network decisions.

Included

Use cases, integrations, tests, rollback, documentation and agreed hypercare named in the proposal.

Not included

24/7 operations, full management of other platforms, approval of business permissions or a formal training product.

Training

Formal Tailscale training is provided separately through Learners First. Integrate includes operational handover only.

Pricing

A scoped project or phased production rollout.

Price is determined by the scope of use cases, tailnets, connectors, integrations, migration, testing and approvals.

Price on requestTailscale licences and cloud, IdP, MDM, EDR, SIEM, device and travel costs are not included in the service price.See how pricing is determined →

Next step

Shall we take the first use case into production?

Describe the use case and current stage at a high level. We will respond by the next Finnish business day.

Book a 30-minute Integrate scoping call