Pairing with native SSH access, Pomerium Enterprise can now record and play back SSH sessions. Every keystroke and terminal output for a privileged SSH connection can be captured, stored, and reviewed later from the Console — giving security and compliance teams a full audit trail of what actually happened on a host, not just who connected.
Highlights:
- Full session capture & playback – Record interactive SSH sessions and replay them later, terminal output and all, directly from the Enterprise Console.
- Flexible storage – Point recordings at a local on-disk directory or any S3-compatible bucket, configured per cluster. In Pomerium Zero, recordings are stored in your organization's managed cloud bucket.
- Guided storage setup in the Console – A new blob-URI builder in the Enterprise Console lets admins configure the recording storage location without hand-writing a connection string for each provider — it exposes the relevant Go CDK driver options, with a free-form field for advanced parameters.
- Recordings UI – Browse, sort, and filter recordings in the Console by metadata such as the Pomerium route, the SSH user, the target host, duration, and size — then open one to play it back.
- Open, portable format – Recordings are captured in an asciinema-style (.asciicast) format, so they're easy to store, parse, and replay.
- Enterprise-gated – Native SSH access remains available in open source, while session recording is an Enterprise/Zero capability enabled for licensed customers.
See the Session Recording and Native SSH Access docs to get started.
