# Granular Route Access Control for Cross-Organization Users

**URL:** <https://forum.pritunl.com/t/granular-route-access-control-for-cross-organization-users/3654>\
**Category:** Pritunl VPN\
**Tags:** pritunl\
**Created:** [December 10, 2025, 5:44am UTC](https://forum.pritunl.com/t/granular-route-access-control-for-cross-organization-users/3654 "2025-12-10T05:44:57Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![lucassalaroli](https://forum.pritunl.com/letter_avatar_proxy/v4/letter/l/7bcc69/32.png) [@lucassalaroli](https://forum.pritunl.com/u/lucassalaroli)\
**Post date:** [December 10, 2025, 5:44am UTC](https://forum.pritunl.com/t/granular-route-access-control-for-cross-organization-users/3654/1 "2025-12-10T05:44:57Z")

</div>

Hello guys,

My organization uses Pritunl to segment users by team (`Infra`, `Dev`, etc.). Each team is assigned a separate VPN server that routes **only** its specific subnets.

The challenge is granting granular, single-IP exceptions (e.g., User João from `Infra` needs one specific portal IP in the `Dev` network) **without forcing him to disconnect and reconnect to a different VPN server.**

This cross-access requirement is essential for daily operations. I am looking for the most efficient and scalable solution within the Pritunl ecosystem.

What is the **best and most correct practice** for implementing highly granular access control when a user requires routes that go beyond the standard scope of their primary VPN connection?

---

<div class="post-metadata">

**Author:** ![zach](https://forum.pritunl.com/user_avatar/forum.pritunl.com/zach/32/1105_2.png) [@zach](https://forum.pritunl.com/u/zach)\
**Post date:** [December 10, 2025, 6:21am UTC](https://forum.pritunl.com/t/granular-route-access-control-for-cross-organization-users/3654/2 "2025-12-10T06:21:43Z")

</div>

Routes can only be controlled at the server level. Users can connect to multiple servers or additional servers can be created with a different combination of routes.
