SafeToOpenBrowser Security Docs

SafeToOpen Browser Security

AI Governance: Sanctioned AI, Shadow AI Warnings and the AI Usage Report

Approve the AI platforms your organisation sanctions, warn on or block the rest, and report who uses which AI tools

Guide 8 of 9 · April 2026

Most organisations now have a contracted AI platform (ChatGPT Enterprise, Microsoft 365 Copilot, Gemini for Google Workspace or Claude for Work) and a long tail of AI tools nobody approved. SafeToOpen Browser Security lets a Business Plus workspace name the approved editions, show its own message or a block page on the others, tell a work sign-in apart from a personal one on the same website, and report AI use per platform, workspace and person. Everything in this guide is workspace policy: there is nothing to install beyond the extension your fleet already runs.

Note Counts only. The extension never sends prompts, answers, pasted text or page addresses for this feature. Usage is counted per platform (visits, warnings shown, warnings accepted, blocks) and incidents carry the site address and the reason. Personal Plus accounts never take part.

1. Tiers and editions#

Every AI platform the extension recognises resolves to an edition key, and every edition sits in one of three tiers:

TierWhat the person seesTypical use
SanctionedNothing. Visits are counted for the report.Your contracted tools: ChatGPT Enterprise, Microsoft 365 Copilot, Gemini for Workspace, Claude Team or Enterprise, an internal portal.
ToleratedA banner across the top of the page with your message, dismissible.Tools you have not approved but do not want to fight yet; the long tail while you decide.
UnsanctionedWarn (a notice that must be accepted, then the banner), Block (the page is covered and cannot be used) or Monitor (nothing shown, counted and recorded).The personal editions of your contracted tools, and any tool your policy forbids.

Editions that share an address#

Microsoft is easy: work Copilot lives on m365.cloud.microsoft and personal Copilot on copilot.microsoft.com, so the address decides. ChatGPT, Gemini and Claude serve work and personal accounts from the same address, so the extension looks at the account the person is signed in with:

  1. A signed-in email address on one of your work account domains marks the session as the work edition; any other address marks it personal. Gemini shows the address in the account button; ChatGPT and Claude show it in the profile menu, so the edition is confirmed the first time that menu opens and remembered for twelve hours.
  2. Vendor plan markers are the second signal: “ChatGPT Enterprise”, “Team workspace”, “Enterprise plan” and their personal counterparts (“ChatGPT Plus”, “Pro plan”, “Upgrade”).
  3. Until either signal has been seen, the tier under “When the edition cannot be told apart” applies. Leave it at Tolerated so a person on the work edition sees at most a banner for a moment; choose Unsanctioned only where the personal edition is banned and a short warning on the work edition is acceptable.

Work account domains default to the domain of each member’s SafeToOpen account. Set them explicitly when your organisation signs in to AI tools with a different domain, or with several.

2. Setting it up#

  1. Console → Configuration → Policies → choose the workspace → open the AI governance section.
  2. Set AI governance to yes.
  3. Platform tiers: put your contracted editions in Sanctioned, their personal editions in Unsanctioned, and leave Everything else on Tolerated for the first weeks. Use the “Set all to” buttons to start from one tier and adjust.
  4. Your own AI platforms: add internal portals or partner tools with a name, hostnames (wildcards allowed) and a tier. A custom entry wins over the catalogue.
  5. Work account domains: confirm or list the email domains that identify a work sign-in.
  6. On an unsanctioned platform: Warn is the usual start. Block covers the page with a notice and a Close button; Monitor shows nothing and only counts and records.
  7. Your message: a short HTML paragraph naming the approved tools and who to ask. It is the banner text on tolerated platforms and the notice text on unsanctioned ones.
  8. Keep AI usage report and Record incidents on. Save changes. Extensions pick the policy up on their next poll, within an hour; a browser restart applies it at once.
Note Start with visibility. Run a workspace for two weeks with every tier on Tolerated or Monitor, read the AI usage report, then tighten. People react far better to a warning that names the approved alternative than to a block with no explanation.

3. What people see#

“Pause analysis on this site” does not switch AI governance off: it is an organisation policy, not a personal preference.

4. The AI usage report#

Console → Security → AI usage. Choose 7, 30 or 90 days and, where you have several, a workspace.

SectionShows
Headline figuresPeople using AI and the share of active members that is; sanctioned share of visits; unsanctioned visits and people; time spent in AI tools and how much of it on unsanctioned ones; prompts sent and files uploaded; warnings shown and how many continued anyway; platforms blocked; distinct platforms seen.
AI visits over timeVisits per day, with days that carry unsanctioned visits highlighted.
Visits by tier and by platformWhere AI use sits: sanctioned, tolerated, unsanctioned, or unknown edition.
PlatformsEvery platform edition seen, its tier, people, workspaces, visits, time spent, prompts, uploads, warnings, continued-anyway and blocks.
By workspace and PeopleThe same counts per workspace and per member (top 50 by visits, addresses partly masked).
Incidents recordedHow many unsanctioned visits and accepted warnings became incidents in the period.

Export CSV downloads the platform table for the period, which is the evidence most ISO 42001, EU AI Act and cyber-insurance questionnaires ask for: which AI tools are in use, which are sanctioned, and what control is applied to the rest. MSPs see every organisation’s figures by switching organisation in the console.

Time spent counts a second while the AI tab is visible and the person typed, clicked, scrolled or pasted within the last minute, so an open tab left idle does not count. Prompts are counted when a message is actually sent; files when an upload actually goes through. All three are durations and counts per platform, never content.

Figures arrive with the extension heartbeat, sent within about two minutes of AI activity. Usage is stored per member, day and platform for the retention period of your other analytics, and holds no page addresses.

5. Paste Guard by tier#

The Privacy tab configures Paste Guard for every website. On AI platforms the AI governance section adds a matrix that decides, per tier, what happens at the three moments data leaves the browser: pasted text, the prompt box at the moment it is sent, and file uploads (file pickers and drag-and-drop). Each cell takes one of five actions.

ActionPasted textPrompt boxFile upload
AllowNo check; nothing is sent to the PII engine.No check.No check; the generic upload check on the Privacy tab is skipped too.
Check and count onlyChecked after it lands; a hit is counted and, when the Privacy tab says so, reported to your SOC. Nothing shown.Checked when sent; the message goes out either way.Checked alongside the upload.
Warn when PII is foundThe ordinary Paste Guard flow: the text lands, a notice lists the categories found.Held until the engine answers; on a hit a notice appears and the message is not sent until the person presses I understand and sends again.The upload proceeds; a notice appears if the file carries PII.
Refuse when PII is foundHeld until the engine answers (usually under a second); on a hit the paste is refused and nothing lands.Held; on a hit the message is not sent and cannot be sent unchanged.Held; on a hit the file is removed from the picker and the site never sees it. Files over 8 MB are refused unchecked.
Refuse alwaysEvery paste is refused.Nothing can be sent.Every upload is refused.

Defaults: sanctioned allows everything (the contract covers it), tolerated warns, unsanctioned refuses pastes and prompts that carry PII and refuses uploads outright. Refusals are counted per platform on the AI usage page and recorded as incidents (kinds AI_PASTE_BLOCKED, AI_PROMPT_BLOCKED, AI_UPLOAD_BLOCKED, severity low) when Record incidents is on; a paste that Paste Guard warned about is counted as “pastes with PII warned”.

Note Which text is checked. On AI platforms every paste of eight characters or more is checked, regardless of the word threshold on the Privacy tab, because a card number or an account number is one word. Prompts are checked from twenty characters. Shift+Enter is never intercepted. The matrix applies whether or not the personal Paste Guard toggle is on, and “Pause analysis on this site” does not switch it off.

The prompt check works on the chat editors of ChatGPT, Claude, Gemini and Copilot and on ordinary forms with a text box and a Send button. Drag-and-drop refusal is reliable; letting a clean dropped file through depends on the site accepting a re-dispatched drop, which the major platforms do. Where a site does not, the file picker still works.

6. Incidents, response rules and SIEM#

With Record incidents on, these incident kinds are recorded, once per site and kind per hour per person. Every incident names the member, so an analyst sees who, what categories, on which platform:

KindWhenCarries
AI_UNSANCTIONED_VISITA person reaches a platform in the Unsanctioned tier (Warn, Block or Monitor).Site address, platform edition, the action taken.
AI_WARNING_ACCEPTEDA person presses Continue anyway on the warning.Site address and platform edition.
AI_PII_DETECTEDPersonal information is found in a paste, a message or an upload on an AI platform and the matrix warned or only counted (severity medium).Site address, platform and tier, the categories, what happened (never the text). On every other website the same detection is recorded as PII_DETECTED.
AI_PASTE_BLOCKEDA paste is refused by the Paste Guard matrix.Site address, platform, the PII categories found (never the text).
AI_PROMPT_BLOCKEDA message is refused at send time.Site address, platform, the PII categories found (never the prompt).
AI_UPLOAD_BLOCKEDA file upload is refused.Site address, platform, the categories found or “too large to check” (never the file).

They flow through every channel your other incidents use: alert emails (when your alert severity includes low), webhooks, the SIEM pull (/api/integrations/events, also as OCSF, ECS or CEF), and response rules. To be told in Teams or Slack each time someone continues past the warning:

  1. Console → Configuration → Response actions → Rules → Add rule.
  2. Kinds: ai_warning_accepted (kinds match case-insensitively; list several with commas). Minimum severity: Low.
  3. Action: the Teams or Slack connector’s message action, or a ticket in ServiceNow or Jira. Dry-run first, then enable.
{
  "event_kind": "AI_WARNING_ACCEPTED",
  "severity": "low",
  "url_host": "chatgpt.com",
  "finding_reason": "User continued to unsanctioned AI platform after the warning: ChatGPT",
  "workspace": "acme.com"
}

Uncomfortable with incidents for AI use? Set Record incidents to no. The usage report keeps counting; nothing reaches incidents, webhooks or rules.

7. Microsoft and Google tenant restrictions#

Where the personal edition of a Microsoft product is the problem (Copilot, but also Outlook.com and personal OneDrive), the extension can enforce Microsoft’s own tenant restrictions on managed browsers without a proxy. Microsoft honours two headers on its sign-in hosts: Restrict-Access-To-Tenants, the tenants a sign-in may go to, and Restrict-Access-Context, your directory ID. With the headers present, a sign-in to any other tenant, personal accounts included, is refused by Microsoft with its own explanation page.

  1. Console → Configuration → Policies → AI governance → Microsoft tenant restrictions.
  2. Allowed tenants: your tenant ID or verified domains (for example acme.com, acme.onmicrosoft.com), plus every partner tenant your people sign in to as guests. Directory ID: from the Entra admin centre overview.
  3. Save. Extensions apply the rule on their next policy refresh; a browser restart applies it at once. Leave the tenant list empty to switch it off.
Important This is a whole-account control, not an AI control. Once on, no personal Microsoft account can be used in that browser at all, and guest access to a tenant you did not list fails. Tell people before switching it on, list partner tenants first, and start with one workspace. It covers Chrome and Edge running the extension; Safari, mobile and browsers without the extension are not affected, and Microsoft’s server-side tenant restrictions v2 remain the way to cover those.

Google Workspace#

Google honours X-GoogApps-Allowed-Domains on requests to google.com: list your primary and secondary Workspace domains in the same policy section and every Google sign-in in a managed browser must belong to one of them. Personal Gmail, personal Gemini, NotebookLM and any other Google account outside the list are refused with Google’s own “blocked by your administrator” page. Same reach and the same advice as the Microsoft control: it is whole-account, so announce it and start with one workspace. Google’s documentation calls this “block access to consumer accounts” and describes it for proxies; the extension adds the header in the browser instead.

8. Cloud, mail and messaging platforms#

The same tiers and the same Paste Guard matrix apply to the other places data leaves through: personal cloud storage, webmail, file transfer, messaging, paste sites and social networks. The section “Cloud, mail & messaging governance” in Policies has its own switch, tiers, message, unsanctioned action and matrix; work-account domains, the unknown-edition tier, usage reporting and incident recording are shared with AI governance.

GroupPlatformsEditions
Google WorkspaceGoogle Drive and Docs, GmailWork and personal told apart by the signed-in account, like Gemini
Microsoft personalOneDrive personal (onedrive.live.com), Outlook.comPersonal by address; your tenant’s OneDrive and Outlook are never governed
Storage and transferDropbox, Box, WeTransfer, MEGA, iCloud, pCloud, MediaFire, Smash, Send Anywhere, file.io, transfer.sh, gofileOne tier each
Personal mailYahoo Mail, Proton Mail, GMX, mail.comOne tier each
Messaging, paste, socialWhatsApp Web, Telegram Web, Messenger, Discord, Pastebin-style sites, Facebook, Instagram, LinkedIn, RedditOne tier each

Usage appears on the AI usage page with a “cloud” tag and its own filter, and incidents carry a SAAS_ prefix (SAAS_UNSANCTIONED_VISIT, SAAS_PII_DETECTED, SAAS_UPLOAD_BLOCKED and so on). A custom platform from the AI section applies to any hostname, so an internal file-share can be sanctioned there.

Note Uploads are the usual way data leaves through these sites. The recommended unsanctioned row is: pasted text and messages refused when they carry personal information, uploads refused always.

9. Privacy and what is not collected#

10. Coming next#

11. Troubleshooting#

SymptomCauseFix
Nothing shows on an AI siteAI governance is no, the member is not in a business workspace, or the extension has not polled since the changeCheck the policy, the member’s workspace under People, then restart the browser
The work edition of ChatGPT shows the bannerThe edition has not been confirmed yetOpen the profile menu once; with the work address on a work account domain the banner goes. Add the domain under Work account domains if it differs
A personal account was treated as workThe person is signed in with a work address on a personal plan, or the domain list is too broadTighten Work account domains; move the edition to Unsanctioned only if the vendor plan marker is reliable for you
The report is emptyAI usage report is no, or no heartbeat since the first AI visitSet it to yes; figures arrive within about an hour
No incidents for AI visitsRecord incidents is no, or the platform sits in ToleratedOnly Unsanctioned platforms record incidents
An internal tool is banner-edIt matched the catalogue or a custom patternAdd it under Your own AI platforms as Sanctioned; custom entries win
A paste on the work edition was held or refusedThe edition was still unknown, so the unknown-edition tier’s matrix row appliedKeep the unknown tier at Tolerated, or confirm the work account once by opening the profile menu
Enter in the prompt box inserted nothingThe check refused the message, or the site treats Enter as a newline and the replay could not restore itRead the notice; use Shift+Enter for a newline on sites where Enter sends
A dropped file was refused although cleanThe file is over 8 MB, or the check timed outUse the file picker, or reduce the file; refused uploads are listed under Incidents