
Tehama’s deployment begins with onboarding administrators and progresses seamlessly through configuration to full operation. Here's the step-by-step process:
Invitation & Account Setup
Administrators receive an invite to create or join a Tehama organization. They register using email, Tehama credentials with MFA, Google credentials, or via corporate SSO, then accept terms and configure MFA—typically completed within a few hours.
Organization & Room Creation
Admins choose whether to create or join an organization and then set up a “Room” (virtual workspace). They select the Room type—Standard, Domain‑Join, or Service‑provider—and configure network access method: Internet‑Only, Tehama Gateway, or Multi‑Path VPN.
Network Integration
Based on the selected mode, admins either deploy the Tehama Gateway on-premises or configure IPSec VPN tunnels. Network testing and validation follow. This integration phase takes anywhere from a few hours to a couple of days, depending on network complexity.
User & Role Configuration
Administrators add users, third-party organizations, and define roles and permissions. They configure policies, firewall rules, file/app vaults, and desktop templates. Most organizations complete this within one business day, though extensive policies may extend it slightly.
Desktop Provisioning & Client Setup
Desktop templates are created and instantiated on demand. End users install the Tehama Client, authenticate, and connect. Provisioning typically happens within minutes per desktop instance.
Estimated Total Time: A basic implementation—comprising admin setup, network integration, and initial desktop deployment—usually takes 1 to 3 business days. More complex environments involving VPNs, domain‑join configurations, or extensive customization can extend the process to 1–2 weeks.
Tehama’s platform supports extensive customization across the configuration, connectivity, security, and automation layers:
Room Types & Connectivity Modes
Organizations can choose from Standard, Domain‑Join, or Service‑provider Rooms. Network access can be tailored using Internet‑Only, Tehama Gateway, or Multi‑Path VPN, allowing flexible integration with on-premise or cloud networks.
Role-Based Access & Permissions
Admins create custom roles, assign users, and enforce granular firewall and DNS policies on a Room-level basis, supporting least-privilege security.
Vaults & Secret Management
File Vaults and App Vaults can be enabled or disabled per Room to control secure file and application sharing among users.
Desktop Template Customization
Depending on project needs, VM templates can be configured with different OS types, CPU/RAM/storage profiles. GPU-backed or high-memory instances are available for specialized workloads.
Security Policy & Audit Automation
Admins define firewall rules, DNS filtering, encryption settings, and privileged access policies within each Room. The platform automatically logs activity, providing audit trails tailored to compliance frameworks like HIPAA, PCI-DSS, and CMMC.
Networking & Domain Integration
Domain‑Join Rooms enable integration with existing Active Directory environments. VPN/IPSec configurations support connectivity to multiple private networks simultaneously.
Scalability & Lifecycle Automation
The UI facilitates elastic scaling and lifecycle management—automated provisioning, monitoring, patching, or decommissioning—tailored via API scripting or scheduled operations.
Tehama operates on a transparent, per-user, pay-as-you-go model with no setup, maintenance, or hidden support fees. All enterprise-level capabilities—such as cloud compute, virtual desktops, gateways, privileged access management, identity tools, MFA, secure networking, audit logging, and compliance—are included in the standard pricing. According to their Pricing page, users are charged only for the number of desktops deployed and their computing resources, with no separate line items for onboarding, infrastructure setup, or ongoing maintenance.
Tehama provides a comprehensive support ecosystem:
Tehama delivers a robust, Zero Trust-based cybersecurity architecture:
Secure, isolated virtual enclaves for each workspace, ensuring strong segregation of user data and applications.
Tehama regularly issues platform updates every few weeks to months, ranging from new features and enhancements to critical security patches. For example, in June 2025 Tehama introduced support for customer-managed Azure Rooms, firewall management, and scripted maintenance windows, while in September 2025 they rolled out a major UI update, renaming “Rooms” to “Enclaves” and added Azure domain-join support.
Updates are published in the Release Notes section of the Help Center, detailing version numbers, release dates, and changes. Admins are notified in-app and via email, and the Tehama Client auto-updates to ensure workspaces and gateways seamlessly receive the latest features and fixes with minimal disruption.
Tehama features elastic scaling designed to align directly with client requirements. You can add or remove virtual desktops instantly through the admin console without upfront commitments or infrastructure costs. This flexibility allows organizations to respond to fluctuating workforce sizes—such as onboarding temporary contractors or scaling capacity during peak demand—while paying only for actual usage.
Desktops come in multiple configurations (entry-level to GPU/memory-optimized), and customers can switch between tiers, resize instances, or terminate environments on demand. Billing is strictly usage-based, with no minimum seat count or hidden commitments—allowing full control over scaling costs and resource allocation.
Tehama is engineered to meet a wide range of regulatory and cybersecurity standards, ensuring it is suitable for highly-regulated sectors like finance, healthcare, government, and energy. The platform includes built-in controls and certifications that simplify compliance adherence: