Modern development depends on distributed teams, external contributors, and fast access to the right tools. Organizations need a way to give developers, and AI agents secure, ready-to-use environments without adding infrastructure burden, endpoint risk, or unpredictable spend.

High-end laptops are costly to buy, ship, and secure. Virtual Desktop Infrastructure (VDI) is not aligned with the methods of modern development such as Infrastructure as code, DevOps and Platform Engineering. Meanwhile, source code, credentials, and access tokens still sit on endpoints that are hard to control.

The real issue is that development environments are not one-of-kind. Personas, projects, toolchains, and security needs rarely fit one standard model.

A successful developer and agentic platform must prove three things:

  1. Lighter IT burden: Infrastructure operations are drastically reduced.
  2. Great user experience with predictable spend: Costs remain transparent as teams and projects scale.
  3. Zero endpoint risk: Code, data, and secrets never live on the local machine.

Announcing a new approach that is purpose-built around these core pillars

Today, Citrix is announcing Citrix SecurSpaces Flex, a Citrix-managed service within Citrix Platform Flex.

Citrix SecurSpaces Flex delivers a platform for developers and AI agents that integrates with internal portals and the broader DevOps and Platform Engineering ecosystem these teams already use. They can then access these environments through the interface that best fits their workflow, whether a Progressive Web App-based IDE or terminal, via SSH from their local tools, or a customer’s own web application experience built on top of Citrix SecurSpaces.

Citrix SecurSpaces Flex is also aligned with Gartner’s emerging category of Agentic Development Sandbox Platforms and is cited as a vendor in the latest Gartner Market Guide for this category. These platforms provide secure, isolated environments where organizations can run AI coding agents with controlled access to code, tools, credentials, and networks. This matters because agentic development requires more than productivity; it requires a safe execution boundary in which AI agents can operate without exposing secrets, bypassing policies, or accessing unauthorized systems.

Operational management: reduce the infrastructure work

Most teams are not looking for a new platform to run. They want to stop spending engineering cycles on infrastructure that does not directly advance software delivery.

With Citrix SecurSpaces Flex, Citrix operates the layers that consume time and carry availability risk, including the control plane, hosting infrastructure, databases, developer workspaces, as well as patching, scaling, and monitoring. Updates are delivered as a managed service, and workspaces continue to operate normally during the underlying platform upgrade.

All while customers keep control of identity, source code repositories, images, applications, policies, and data.

That boundary lets IT focus on the work that adds direct value: defining Linux environment for different needs, maintaining the right tooling, designing policies, and improving onboarding rather than building and maintaining the platform.

In Citrix SecurSpaces Flex, operational efficiency comes down to a simple, complementary pairing:

  • Workspace size (Capacity): Sets the compute profile (light, medium, or heavy) to match the task at hand.
  • Workspace templates (Consistency): Defines the environment itself, including the container image, preinstalled tools, and attached resources.

Because these layers are decoupled, a team can reuse a single template across dozens of workspaces, pairing it dynamically with whatever compute size the current workload demands.

Great user experience: match the workspace to the work

User experience problems for developers usually show up at scale, when environments drift, setup takes days, and every persona is handed the same configuration whether they need it or not.

Citrix SecurSpaces Flex lets organizations deliver right-sized workspaces by persona rather than treating all developers as having the same requirements. The same applies to AI agents: each coding or non-coding agent runs sandboxed inside the workspace, isolating and auditing its activity.

Developers and AI agents start in minutes with a ready-to-use environment and work from day one, rather than spending days setting up and maintaining a local machine.

Teams can scale compute up or down depending on the task. Because usage is counted daily, a developer can run a light workspace for a few days and switch to a heavy profile when the work requires more CPU, memory, or GPU resources. That maintains a good user experience while aligning spend to actual use instead of peak capacity. AI agents follow the same model: each one runs in a sandbox inside the workspace under a single control plane, with controlled ingress and egress and native data loss prevention, so its activity stays isolated and contained rather than running unmanaged on the endpoint.

Security: keep the control boundary clear

Security teams rarely object to cloud development in theory. They object when it is not clear who owns what, what can be enforced, and what can be audited once developers are working.

With Citrix SecurSpaces Flex, active development occurs within secure workspaces rather than on endpoints, keeping source code, credentials, and access tokens entirely off local machines. Sensitive assets remain confined to the workspace boundary, encrypted at rest and in transit within the customer’s chosen region.

By defining a clear line between platform operations (managed by Citrix) and asset governance (managed by the customer), security teams get a clear, defensible posture. Access is strictly enforced through a zero-trust model with role-based controls and comprehensive audit logging, aligning perfectly with enterprise compliance expectations even as teams shift.

Predictable spend without a procurement cycle

Cloud spend for developer and AI agent tooling is under scrutiny, and rigid models make it hard to adjust. Citrix SecurSpaces Flex consumption is based on clearly defined workspace sizes mapped to compute profiles, each with a published rate. FinOps specialists can estimate costs in advance, while engineering teams have the flexibility to choose the workspace size that best fits their needs. As requirements change, teams can scale workspaces up or down without re-architecting or a new procurement cycle.

Because Citrix SecurSpaces Flex is part of Citrix Platform Flex, the same credit model applies to other Platform Flex services. For example, developers can use a lightweight desktop for email, documentation, and collaboration, and connect to a SecurSpaces workspace for coding, builds, and testing, with usage tracked through the unified Platform Flex model.

Modernization without the cutover risk

The goal is not simply to move development to the cloud. The goal is to modernize the delivery of working environments for developers and AI agents without creating new infrastructure, operations, or security problems for EUC and platform engineering teams to absorb.

Citrix SecurSpaces Flex gives organizations a practical path forward: start with the teams or use cases that are ready, such as contractor access or high-end laptop replacement, validate security and cost, keep control over the decisions that matter, and expand without forcing a single high-stakes rollout.

That gives IT fewer layers to operate, platform and EUC teams a more practical way to phase adoption, security teams clearer control boundaries, and the organization a developer and agentic sandbox development platform that can adapt as teams and workloads change.

For a more technical view, read the companion Tech Zone article that explores how Citrix SecurSpaces Flex optimizes security, resiliency, and costs.

To gain further insights, please visit the Citrix® SecurSpaces Flex and Citrix® Platform Flex documentation.