Operations
Remote access
When you need to get onto a host, you can use one-time Remote Desktop credentials, a browser terminal, SFTP, or the file manager in the studio app.
Who can open a session
Remote Desktop and the browser terminal are for people, not automation: they are opened from a signed-in member session, never with an API key. The member must be an Owner or an Admin and must have completed multi-factor authentication, even when your organization does not require it for everyone.
Each request asks for a short reason, which is kept with the session and in your audit log.
Remote Desktop
Request access to a host and you receive a one-time credential for your own Remote Desktop client: the host's address, your organization's service account, a generated password and a ready-made .rdp file (the password is not stored in the file).
- The host's firewall opens Remote Desktop only to the public IP address the request came from, and only until the credential expires.
- A host has at most one live credential at a time. Every new request sets a fresh password.
- A session ends after 15 minutes of inactivity or 4 hours in total, when you end it, or when GameGrid support ends it.
- Windows sign-in events are collected for your records. The screen itself is not recorded.
Browser terminal
Open a PowerShell session on a host from the studio app. It runs as your organization's service account and is never elevated to Administrator.
- It is line-based: you type a line and see its output. It is not a full interactive terminal, and Ctrl+C does not interrupt a running command.
- Every session is recorded, input and output. If recording cannot start, the session does not open. Owners and Admins can play recordings back.
- Every line you type is also written to your audit log with its full text, so never type a secret into the terminal.
- The session ends after 15 minutes without input or 4 hours in total, and you can extend it while you work.
SFTP
Create SFTP accounts per host, on port 2022. Each account signs in with a password or an SSH public key (password sign-in can be turned off), and is limited to your organization's files on that host or to a single server's folder.
The SFTP port on a host is open only while that host has at least one enabled account.
File manager
Each server's files can be managed from the studio app: browse, view and edit files, create folders, rename and delete, upload (large uploads are sent in chunks), extract zip archives, and download files or folders as a zip.
Every member can list files. Reading and changing them needs the Owner, Admin or Operator role, and downloading needs Owner or Admin.