SafeToOpenEmail Security Docs

SafeToOpen Browser Security

Workspace policies and branding

The five enforced behaviours, the deferred verdict, the URL scan service, logo, names, colours and the branded add-in, report inboxes, alert recipients and analysts, and what applies in Outlook versus Gmail

Guide 4 of 7 · April 2026

Everything here is set in Console → Workspaces. The organisation default applies to every member without a workspace-level setting; a workspace overrides only the fields you fill in. Changes reach the add-in at its next check-in, within a minute; the branded add-in identity (name, button, icon) is the one exception and needs a manifest re-upload (guide 2).

1. Behaviour policies#

PolicyWhen onWhat the user sees
Automatic Deeper AnalysisEvery opened message on an Executive seat runs Deeper Analysis without a click. The quick score is shown as “Still analysing…” until the final verdict; a verdict can only get stricter.The toggle is shown on but greyed out with “managed by your organisation”.
Auto-forward unsafe emailsMessages with a final verdict of Dangerous are forwarded to the workspace report inbox automatically and recorded as an “auto-forwarded by policy” incident.Nothing; a note in the panel says the message was forwarded.
Tag resultsThe verdict is written to the message as a category (Outlook) or label (Gmail).Category or label on the message.
Auto-scan linksLinks in the message are checked without the user clicking Scan.Link results appear with the score.
Security tipsContextual tips are shown with each verdict.Tips block in the panel.

A policy left blank in both the workspace and the organisation default leaves the choice with the user.

PolicyOutlookGmail
Automatic Deeper AnalysisYes, with the “Still analysing…” hold until the final verdictYes; the analysis runs right after the scan and updates the panel
Auto-forward unsafe emailsYesYes
Tag resultsOutlook categoryGmail label; the personal labels toggle is greyed out
Auto-scan linksYesNot applicable; the Gmail panel always checks links with the scan
Security tipsYesNot applicable; the Gmail panel has no tips block
Branding (name, logo, tagline, colours)YesYes
Add-in name and button labelYes, via the branded manifestNot applicable; the Marketplace listing name is fixed
URL scan serviceYesYes

2. URL scan service#

Every link the add-in checks, and every link preview it shows, goes to a scan service. By default that is SafeToOpen’s scanner. A workspace (or the organisation default) can name another https address, for example a regional scanner or one you host, and both add-ins send that workspace’s link checks there. The console shows the current default as the placeholder, so leaving the field blank always means the SafeToOpen scanner (or, for a workspace, the organisation default).

3. Branding#

FieldWhere it appears
Display namePanel header, “<name> Email Security”, and the default add-in name
LogoPanel header and the scanning animation; also resized into the add-in icons of the branded manifest
TaglineUnder the display name in the panel
Accent and secondary coloursButtons, score bar and highlights in the panel
Add-in name and button labelThe Outlook ribbon and app list, via the branded manifest (guide 2, section 2b); not applicable to Gmail
URL scan serviceWhere link checks and previews are sent (section 2)
  1. Console → Workspaces → the workspace (or Organisation default) → Policies & branding.
  2. Upload a PNG or SVG logo, set names and colours, Save. For Outlook, download the manifest and deploy it to that workspace’s group.

4. Report inbox, alerts and analysts#