Browser Agent kill switch
The Browser Extension can switch off its native Browser Agent on a device and switch it back on, without restarting any process. While disabled, the Browser Agent stops clipboard monitoring and file indexing and processes no clipboard or file DLP events. The disabled state survives reboots.
Which switch to use
This switch stops only the Browser Agent. It does not turn off the extension itself or the separately installed Endpoint Agent.
The Endpoint Agent kill switch page has the full matrix, required permissions and a canary recovery sequence.
Disable the Browser Agent
An admin toggles Disable Agent in the console.
The extension sends the signal to the Browser Agent over the Native Messaging pipe, and the Browser Agent applies it immediately.
Re-enable the Browser Agent
An admin toggles Enable Agent in the console. The Browser Agent clears the flag, restarts its services, and restores DLP processing without a process restart. Agent Status shows Active.
To verify on the device, copy a harmless test value that a clipboard rule would act on and check that the expected prompt or finding appears again.
How it works
- Re-enable stays available. While disabled, the Browser Agent ignores every event except re-enable signals. This channel is never removed, so the extension can always restore it.
- Startup enforcement. On every start, the Browser Agent reads the flag before it registers any service. If it is disabled, it skips service and DLP registration entirely and only listens for re-enable. Nothing is started and then torn down.
- Logging. Every disable and re-enable is logged with a timestamp and the trigger source.