Users, profiles, access rules and the certificate authority all belong to the installation on that Linux host. Scale it and a cluster keeps certificates and credentials in a central database you run. More capacity, same unit.
The control tower is a separate piece from the gateways, and it still runs on your own infrastructure, on premise, in a private cloud or air gapped. A device identity, a certificate, an algorithm choice and a policy are fleet level objects, not settings in one box.
Certificates show it best. Access Server renews its CA on startup once the one in use is over a year old, and then “a client gets the latest CA certificate whenever they download a new client profile”. The pull belongs to the user. In QS-WAN those are fleet settings, eight key exchange options, eight certificate authorities and three ciphers, applied fleet wide or per gateway, with the certificates re-signed and redistributed rather than fetched. Crypto agility is that screen, and rotating the CA is a scheduled operation rather than a button: it needs every gateway connected while it runs.