Clipboard monitoring
Clipboard monitoring catches sensitive data at the copy step. The QuilrAI agent on the endpoint watches clipboard events, sends them to the Browser Extension for a DLP decision, and then allows the copy, clears the clipboard, or asks the user for a justification.
Set it up
The clipboard monitor is part of the QuilrAI agent that you deploy with the extension (see Prerequisites). It starts automatically after deployment.
Settings
Clipboard settings are managed with your QuilrAI representative and pushed to the agent. They take effect on the next agent restart.
Policy actions
The extension evaluates its DLP rules against the clipboard content (by content category, size, or custom regex). Clipboard rules are browser controls: open Govern › Policy Engine › Browser Extension and add or edit a control whose use case is A user is copying to clipboard (see Browser controls). The same rule set applies to text, files, and images.
How it works
- OS hook. The agent listens for clipboard changes: NSPasteboard change-count polling on macOS, WinAPI clipboard-change notifications on Windows.
- Filter. Events inside the debounce window, disabled content types, and oversized payloads are dropped or trimmed.
- Forward. Content metadata and a size-capped payload go to the Browser Extension over the Native Messaging pipe.
- Evaluate. The extension applies its DLP rules with the user's identity and returns Allow, Block, or Prompt.
- Enforce. The agent carries out the decision on the endpoint. The justification dialog is a native Cocoa dialog on macOS and a native dialog on Windows.
Monitor activity
Every clipboard event is logged with its content type, policy decision, and enforcement outcome. Clipboard events appear in Findings and interactions (Observe › Findings & Interactions). Check there that events are flowing and policies are enforced, including user justifications for prompted copies.
To pause clipboard monitoring together with the agent's other services, use the agent kill switch.