Browser controls
A browser control tells the extension what to watch for and what to do when it happens, for example "a user shares sensitive data with an AI application". Controls live on the Browser Extension tab of the Policy Engine. For how the Policy Engine works across all surfaces, see Policy Engine.
Controls table
Use Search, the Posture filter (AI Risks, Data Risks, Device Risks, IT Support, MFA Risks, Password Hygiene, and more), and the Type filter to narrow the list. Sort by Recently modified. Export downloads the list. Each row menu has Edit and Duplicate.
Add or edit a control
Select Add control, or Edit on a row. The form has these parts:
- Control details: name, description, Criticality (Very Low to Very High), and Mode (Monitor or Action).
- When this happens: the use case the control watches for (for example "A user is uploading data"). The use case, posture, and behavior are fixed once the control is created; to change them, duplicate the control.
- Mandatory conditions: conditions that come with the use case. For a sensitive-data use case, these are typically that the application category is Generative AI and the data is sensitive.
- Additional conditions (Add condition): optional conditions to narrow scope, for example to a user or smart group, an application, or a data type.
- Perform action: what happens in Action mode. Depending on the use case, this can include just-in-time choices for the user (remove sensitive data and continue, continue with no, optional, or mandatory justification, or redact sensitive data), remediation such as sending an alert to syslog, or activating an AI agent for follow-up.
Then finish the form:
To stage a control without running it, save it with Enabled off, review it, then turn it on from the Status toggle.
Start new or changed controls in Monitor mode, scoped to a pilot group. Review the findings for a week or two (true and false positives, affected users and apps) before you switch the control to Action.
What users see
In Action mode, the extension shows a popup that explains the decision. Word and brand these popups in End-user popups. When a user justifies a blocked action, the request appears in Action requests for an admin to approve or reject.