Using two ZPA tenants - a customer and a partner - Sharing applications between them.
Customer tenant deploys App Connector in their DC advertising a server and SIEM. Customer deploys Cloud Connector in an AWS VPC.
Partner deploys their App Connector in the AWS VPC.
Customer Policy allows the Partner App Connector to access *just* the server from the Cloud Connector.
Partner policy allows user to access resource. Partner logs traffic to the customer SIEM, through the Cloud Connector.
Customer logs traffic to the SIEM also. Customer can then correlate their logs with the partner logs.
Demo walks through the setup, the policy, and the traffic flow.