App policies
App policies decide how the Endpoint Agent detects and acts on sensitive data in each AI application. They live on the Endpoint Agent tab of the Policy Engine. For how the Policy Engine works across surfaces, see Policy Engine.
The Endpoint Agent tab runs in Basic policies mode: you configure each application on its own card. The tab has two sub-tabs, Detection configurations and Application configuration.
Detection configurations
This sub-tab shows how the agent detects and acts on sensitive data in each application, with a count of active configurations. It lists the supported endpoint applications, for example ChatGPT, Claude, Cursor, GitHub Copilot, Microsoft Copilot, Gemini, DeepSeek, Grok, Slack, Ollama, and LM Studio.
Each application card shows:
Application configuration
Use this sub-tab to set what applications are allowed to do on endpoints. It works with process mapping, which enforces execution policies (allow, block, quarantine, justify) on discovered applications.
Example: coach on PII in ChatGPT
- Open Detection configurations and find the ChatGPT card.
- Open Guardrails. Set PII to Justify so users are coached and asked for a reason. Use Block for categories such as Auth & Secrets only after you have reviewed the findings, or start everything in Monitor.
- Open Group & user rules and scope the configuration to a pilot smart group.
- Check the results in Findings and interactions before widening the scope.
Policy changes reach agents without a restart. See Backend connectivity.
Convert to Policy Engine
The Convert to Policy Engine button moves the Endpoint Agent from Basic policies to the Policy Engine model used by the gateways. Your QuilrAI representative can help you plan the conversion.