SafeToOpen Browser Security
AI Governance: Sanctioned AI, Shadow AI Warnings and the AI Usage Report
Approve the AI platforms your organisation sanctions, warn on or block the rest, and report who uses which AI tools
Most organisations now have a contracted AI platform (ChatGPT Enterprise, Microsoft 365 Copilot, Gemini for Google Workspace or Claude for Work) and a long tail of AI tools nobody approved. SafeToOpen Browser Security lets a Business Plus workspace name the approved editions, show its own message or a block page on the others, tell a work sign-in apart from a personal one on the same website, and report AI use per platform, workspace and person. Everything in this guide is workspace policy: there is nothing to install beyond the extension your fleet already runs.
1. Tiers and editions#
Every AI platform the extension recognises resolves to an edition key, and every edition sits in one of three tiers:
| Tier | What the person sees | Typical use |
|---|---|---|
| Sanctioned | Nothing. Visits are counted for the report. | Your contracted tools: ChatGPT Enterprise, Microsoft 365 Copilot, Gemini for Workspace, Claude Team or Enterprise, an internal portal. |
| Tolerated | A banner across the top of the page with your message, dismissible. | Tools you have not approved but do not want to fight yet; the long tail while you decide. |
| Unsanctioned | Warn (a notice that must be accepted, then the banner), Block (the page is covered and cannot be used) or Monitor (nothing shown, counted and recorded). | The personal editions of your contracted tools, and any tool your policy forbids. |
Editions that share an address#
Microsoft is easy: work Copilot lives on m365.cloud.microsoft and personal Copilot on copilot.microsoft.com, so the address decides. ChatGPT, Gemini and Claude serve work and personal accounts from the same address, so the extension looks at the account the person is signed in with:
- A signed-in email address on one of your work account domains marks the session as the work edition; any other address marks it personal. Gemini shows the address in the account button; ChatGPT and Claude show it in the profile menu, so the edition is confirmed the first time that menu opens and remembered for twelve hours.
- Vendor plan markers are the second signal: “ChatGPT Enterprise”, “Team workspace”, “Enterprise plan” and their personal counterparts (“ChatGPT Plus”, “Pro plan”, “Upgrade”).
- Until either signal has been seen, the tier under “When the edition cannot be told apart” applies. Leave it at Tolerated so a person on the work edition sees at most a banner for a moment; choose Unsanctioned only where the personal edition is banned and a short warning on the work edition is acceptable.
Work account domains default to the domain of each member’s SafeToOpen account. Set them explicitly when your organisation signs in to AI tools with a different domain, or with several.
2. Setting it up#
- Console → Configuration → Policies → choose the workspace → open the AI governance section.
- Set AI governance to yes.
- Platform tiers: put your contracted editions in Sanctioned, their personal editions in Unsanctioned, and leave Everything else on Tolerated for the first weeks. Use the “Set all to” buttons to start from one tier and adjust.
- Your own AI platforms: add internal portals or partner tools with a name, hostnames (wildcards allowed) and a tier. A custom entry wins over the catalogue.
- Work account domains: confirm or list the email domains that identify a work sign-in.
- On an unsanctioned platform: Warn is the usual start. Block covers the page with a notice and a Close button; Monitor shows nothing and only counts and records.
- Your message: a short HTML paragraph naming the approved tools and who to ask. It is the banner text on tolerated platforms and the notice text on unsanctioned ones.
- Keep AI usage report and Record incidents on. Save changes. Extensions pick the policy up on their next poll, within an hour; a browser restart applies it at once.
3. What people see#
- Sanctioned — Sanctioned platform: nothing changes.
- Tolerated (banner) — A slim strip in your workspace colour across the top of the page with your logo, the platform name and your message. Dismissible for that page load; it returns on the next visit.
- Unsanctioned, Warn — A notice covering the page with the platform name, “Not approved by your organisation”, your message and two buttons: Close page and Continue anyway. Continuing is remembered for 24 hours on that site, shows the banner, and records an incident.
- Unsanctioned, Block — The page is covered with “Blocked by your organisation”, your message and a Close page button. Typing, scrolling and pasting underneath are stopped while the notice stands.
- Unsanctioned, Monitor — Nothing on screen. The visit is counted and, when Record incidents is on, an incident is recorded.
“Pause analysis on this site” does not switch AI governance off: it is an organisation policy, not a personal preference.
4. The AI usage report#
Console → Security → AI usage. Choose 7, 30 or 90 days and, where you have several, a workspace.
| Section | Shows |
|---|---|
| Headline figures | People using AI and the share of active members that is; sanctioned share of visits; unsanctioned visits and people; time spent in AI tools and how much of it on unsanctioned ones; prompts sent and files uploaded; warnings shown and how many continued anyway; platforms blocked; distinct platforms seen. |
| AI visits over time | Visits per day, with days that carry unsanctioned visits highlighted. |
| Visits by tier and by platform | Where AI use sits: sanctioned, tolerated, unsanctioned, or unknown edition. |
| Platforms | Every platform edition seen, its tier, people, workspaces, visits, time spent, prompts, uploads, warnings, continued-anyway and blocks. |
| By workspace and People | The same counts per workspace and per member (top 50 by visits, addresses partly masked). |
| Incidents recorded | How many unsanctioned visits and accepted warnings became incidents in the period. |
Export CSV downloads the platform table for the period, which is the evidence most ISO 42001, EU AI Act and cyber-insurance questionnaires ask for: which AI tools are in use, which are sanctioned, and what control is applied to the rest. MSPs see every organisation’s figures by switching organisation in the console.
Time spent counts a second while the AI tab is visible and the person typed, clicked, scrolled or pasted within the last minute, so an open tab left idle does not count. Prompts are counted when a message is actually sent; files when an upload actually goes through. All three are durations and counts per platform, never content.
Figures arrive with the extension heartbeat, sent within about two minutes of AI activity. Usage is stored per member, day and platform for the retention period of your other analytics, and holds no page addresses.
5. Paste Guard by tier#
The Privacy tab configures Paste Guard for every website. On AI platforms the AI governance section adds a matrix that decides, per tier, what happens at the three moments data leaves the browser: pasted text, the prompt box at the moment it is sent, and file uploads (file pickers and drag-and-drop). Each cell takes one of five actions.
| Action | Pasted text | Prompt box | File upload |
|---|---|---|---|
| Allow | No check; nothing is sent to the PII engine. | No check. | No check; the generic upload check on the Privacy tab is skipped too. |
| Check and count only | Checked after it lands; a hit is counted and, when the Privacy tab says so, reported to your SOC. Nothing shown. | Checked when sent; the message goes out either way. | Checked alongside the upload. |
| Warn when PII is found | The ordinary Paste Guard flow: the text lands, a notice lists the categories found. | Held until the engine answers; on a hit a notice appears and the message is not sent until the person presses I understand and sends again. | The upload proceeds; a notice appears if the file carries PII. |
| Refuse when PII is found | Held until the engine answers (usually under a second); on a hit the paste is refused and nothing lands. | Held; on a hit the message is not sent and cannot be sent unchanged. | Held; on a hit the file is removed from the picker and the site never sees it. Files over 8 MB are refused unchecked. |
| Refuse always | Every paste is refused. | Nothing can be sent. | Every upload is refused. |
Defaults: sanctioned allows everything (the contract covers it), tolerated warns, unsanctioned refuses pastes and prompts that carry PII and refuses uploads outright. Refusals are counted per platform on the AI usage page and recorded as incidents (kinds AI_PASTE_BLOCKED, AI_PROMPT_BLOCKED, AI_UPLOAD_BLOCKED, severity low) when Record incidents is on; a paste that Paste Guard warned about is counted as “pastes with PII warned”.
The prompt check works on the chat editors of ChatGPT, Claude, Gemini and Copilot and on ordinary forms with a text box and a Send button. Drag-and-drop refusal is reliable; letting a clean dropped file through depends on the site accepting a re-dispatched drop, which the major platforms do. Where a site does not, the file picker still works.
6. Incidents, response rules and SIEM#
With Record incidents on, these incident kinds are recorded, once per site and kind per hour per person. Every incident names the member, so an analyst sees who, what categories, on which platform:
| Kind | When | Carries |
|---|---|---|
| AI_UNSANCTIONED_VISIT | A person reaches a platform in the Unsanctioned tier (Warn, Block or Monitor). | Site address, platform edition, the action taken. |
| AI_WARNING_ACCEPTED | A person presses Continue anyway on the warning. | Site address and platform edition. |
| AI_PII_DETECTED | Personal information is found in a paste, a message or an upload on an AI platform and the matrix warned or only counted (severity medium). | Site address, platform and tier, the categories, what happened (never the text). On every other website the same detection is recorded as PII_DETECTED. |
| AI_PASTE_BLOCKED | A paste is refused by the Paste Guard matrix. | Site address, platform, the PII categories found (never the text). |
| AI_PROMPT_BLOCKED | A message is refused at send time. | Site address, platform, the PII categories found (never the prompt). |
| AI_UPLOAD_BLOCKED | A file upload is refused. | Site address, platform, the categories found or “too large to check” (never the file). |
They flow through every channel your other incidents use: alert emails (when your alert severity includes low), webhooks, the SIEM pull (/api/integrations/events, also as OCSF, ECS or CEF), and response rules. To be told in Teams or Slack each time someone continues past the warning:
- Console → Configuration → Response actions → Rules → Add rule.
- Kinds:
ai_warning_accepted(kinds match case-insensitively; list several with commas). Minimum severity: Low. - Action: the Teams or Slack connector’s message action, or a ticket in ServiceNow or Jira. Dry-run first, then enable.
{
"event_kind": "AI_WARNING_ACCEPTED",
"severity": "low",
"url_host": "chatgpt.com",
"finding_reason": "User continued to unsanctioned AI platform after the warning: ChatGPT",
"workspace": "acme.com"
}Uncomfortable with incidents for AI use? Set Record incidents to no. The usage report keeps counting; nothing reaches incidents, webhooks or rules.
7. Microsoft and Google tenant restrictions#
Where the personal edition of a Microsoft product is the problem (Copilot, but also Outlook.com and personal OneDrive), the extension can enforce Microsoft’s own tenant restrictions on managed browsers without a proxy. Microsoft honours two headers on its sign-in hosts: Restrict-Access-To-Tenants, the tenants a sign-in may go to, and Restrict-Access-Context, your directory ID. With the headers present, a sign-in to any other tenant, personal accounts included, is refused by Microsoft with its own explanation page.
- Console → Configuration → Policies → AI governance → Microsoft tenant restrictions.
- Allowed tenants: your tenant ID or verified domains (for example
acme.com, acme.onmicrosoft.com), plus every partner tenant your people sign in to as guests. Directory ID: from the Entra admin centre overview. - Save. Extensions apply the rule on their next policy refresh; a browser restart applies it at once. Leave the tenant list empty to switch it off.
Google Workspace#
Google honours X-GoogApps-Allowed-Domains on requests to google.com: list your primary and secondary Workspace domains in the same policy section and every Google sign-in in a managed browser must belong to one of them. Personal Gmail, personal Gemini, NotebookLM and any other Google account outside the list are refused with Google’s own “blocked by your administrator” page. Same reach and the same advice as the Microsoft control: it is whole-account, so announce it and start with one workspace. Google’s documentation calls this “block access to consumer accounts” and describes it for proxies; the extension adds the header in the browser instead.
8. Cloud, mail and messaging platforms#
The same tiers and the same Paste Guard matrix apply to the other places data leaves through: personal cloud storage, webmail, file transfer, messaging, paste sites and social networks. The section “Cloud, mail & messaging governance” in Policies has its own switch, tiers, message, unsanctioned action and matrix; work-account domains, the unknown-edition tier, usage reporting and incident recording are shared with AI governance.
| Group | Platforms | Editions |
|---|---|---|
| Google Workspace | Google Drive and Docs, Gmail | Work and personal told apart by the signed-in account, like Gemini |
| Microsoft personal | OneDrive personal (onedrive.live.com), Outlook.com | Personal by address; your tenant’s OneDrive and Outlook are never governed |
| Storage and transfer | Dropbox, Box, WeTransfer, MEGA, iCloud, pCloud, MediaFire, Smash, Send Anywhere, file.io, transfer.sh, gofile | One tier each |
| Personal mail | Yahoo Mail, Proton Mail, GMX, mail.com | One tier each |
| Messaging, paste, social | WhatsApp Web, Telegram Web, Messenger, Discord, Pastebin-style sites, Facebook, Instagram, LinkedIn, Reddit | One tier each |
Usage appears on the AI usage page with a “cloud” tag and its own filter, and incidents carry a SAAS_ prefix (SAAS_UNSANCTIONED_VISIT, SAAS_PII_DETECTED, SAAS_UPLOAD_BLOCKED and so on). A custom platform from the AI section applies to any hostname, so an internal file-share can be sanctioned there.
9. Privacy and what is not collected#
- Never — Prompts, answers, pasted text and file contents are never read for this feature and never leave the browser.
- Addresses — Page addresses are not part of usage counts. Incidents carry the site address (for example
chatgpt.com/c/…), the same exposure as any other Browser Security incident, and are subject to the same retention and analyst access rules. - Account signal — Edition detection reads the navigation and account areas of the page for a signed-in email address or a plan name, compares the address domain with your work account domains, and keeps only the verdict (work or personal) for twelve hours. The address itself is not stored or sent.
- Notify SOC — For SaaS workspaces the older “notify SOC” call to SafeToOpen’s central service is no longer made; the detection becomes an incident on plus instead, governed by the same Notify SOC switch on the Privacy tab.
- Paste Guard — Pasted text and prompts that are checked go to the same PII engine Paste Guard already uses, and only when the tier calls for a check; files go to the file engine the upload check already uses. Verdicts are kept in the browser for ten minutes so an unchanged prompt is not checked twice. Nothing is stored server-side.
10. Coming next#
- Live catalogue — The platform catalogue and edition signals refreshed from SafeToOpen without an extension update, the way brand matching is.
11. Troubleshooting#
| Symptom | Cause | Fix |
|---|---|---|
| Nothing shows on an AI site | AI governance is no, the member is not in a business workspace, or the extension has not polled since the change | Check the policy, the member’s workspace under People, then restart the browser |
| The work edition of ChatGPT shows the banner | The edition has not been confirmed yet | Open the profile menu once; with the work address on a work account domain the banner goes. Add the domain under Work account domains if it differs |
| A personal account was treated as work | The person is signed in with a work address on a personal plan, or the domain list is too broad | Tighten Work account domains; move the edition to Unsanctioned only if the vendor plan marker is reliable for you |
| The report is empty | AI usage report is no, or no heartbeat since the first AI visit | Set it to yes; figures arrive within about an hour |
| No incidents for AI visits | Record incidents is no, or the platform sits in Tolerated | Only Unsanctioned platforms record incidents |
| An internal tool is banner-ed | It matched the catalogue or a custom pattern | Add it under Your own AI platforms as Sanctioned; custom entries win |
| A paste on the work edition was held or refused | The edition was still unknown, so the unknown-edition tier’s matrix row applied | Keep the unknown tier at Tolerated, or confirm the work account once by opening the profile menu |
| Enter in the prompt box inserted nothing | The check refused the message, or the site treats Enter as a newline and the replay could not restore it | Read the notice; use Shift+Enter for a newline on sites where Enter sends |
| A dropped file was refused although clean | The file is over 8 MB, or the check timed out | Use the file picker, or reduce the file; refused uploads are listed under Incidents |