SafeToOpen Browser Security
Workspace policies and branding
The five enforced behaviours, the deferred verdict, the URL scan service, logo, names, colours and the branded add-in, report inboxes, alert recipients and analysts, and what applies in Outlook versus Gmail
Everything here is set in Console → Workspaces. The organisation default applies to every member without a workspace-level setting; a workspace overrides only the fields you fill in. Changes reach the add-in at its next check-in, within a minute; the branded add-in identity (name, button, icon) is the one exception and needs a manifest re-upload (guide 2).
1. Behaviour policies#
| Policy | When on | What the user sees |
|---|---|---|
| Automatic Deeper Analysis | Every opened message on an Executive seat runs Deeper Analysis without a click. The quick score is shown as “Still analysing…” until the final verdict; a verdict can only get stricter. | The toggle is shown on but greyed out with “managed by your organisation”. |
| Auto-forward unsafe emails | Messages with a final verdict of Dangerous are forwarded to the workspace report inbox automatically and recorded as an “auto-forwarded by policy” incident. | Nothing; a note in the panel says the message was forwarded. |
| Tag results | The verdict is written to the message as a category (Outlook) or label (Gmail). | Category or label on the message. |
| Auto-scan links | Links in the message are checked without the user clicking Scan. | Link results appear with the score. |
| Security tips | Contextual tips are shown with each verdict. | Tips block in the panel. |
A policy left blank in both the workspace and the organisation default leaves the choice with the user.
| Policy | Outlook | Gmail |
|---|---|---|
| Automatic Deeper Analysis | Yes, with the “Still analysing…” hold until the final verdict | Yes; the analysis runs right after the scan and updates the panel |
| Auto-forward unsafe emails | Yes | Yes |
| Tag results | Outlook category | Gmail label; the personal labels toggle is greyed out |
| Auto-scan links | Yes | Not applicable; the Gmail panel always checks links with the scan |
| Security tips | Yes | Not applicable; the Gmail panel has no tips block |
| Branding (name, logo, tagline, colours) | Yes | Yes |
| Add-in name and button label | Yes, via the branded manifest | Not applicable; the Marketplace listing name is fixed |
| URL scan service | Yes | Yes |
2. URL scan service#
Every link the add-in checks, and every link preview it shows, goes to a scan service. By default that is SafeToOpen’s scanner. A workspace (or the organisation default) can name another https address, for example a regional scanner or one you host, and both add-ins send that workspace’s link checks there. The console shows the current default as the placeholder, so leaving the field blank always means the SafeToOpen scanner (or, for a workspace, the organisation default).
- The alternative service must answer the same request and response contract as the default; the add-ins do not adapt to a different one.
- A blank or invalid value is ignored by the add-in, which falls back to the default, so a wrong policy cannot stop link checks.
- Changes reach members at their next check-in, within a minute; no manifest change is needed.
3. Branding#
| Field | Where it appears |
|---|---|
| Display name | Panel header, “<name> Email Security”, and the default add-in name |
| Logo | Panel header and the scanning animation; also resized into the add-in icons of the branded manifest |
| Tagline | Under the display name in the panel |
| Accent and secondary colours | Buttons, score bar and highlights in the panel |
| Add-in name and button label | The Outlook ribbon and app list, via the branded manifest (guide 2, section 2b); not applicable to Gmail |
| URL scan service | Where link checks and previews are sent (section 2) |
- Console → Workspaces → the workspace (or Organisation default) → Policies & branding.
- Upload a PNG or SVG logo, set names and colours, Save. For Outlook, download the manifest and deploy it to that workspace’s group.
4. Report inbox, alerts and analysts#
- Report inbox — Report inbox: where user reports and auto-forwards for the workspace are sent, for example a SOC or MSP mailbox. Blank uses the organisation default from Settings; blank there sends reports to SafeToOpen’s analysts.
- Alerts — Alert recipients: who receives incident alerts for the workspace, in real time or as a daily or weekly digest, above a minimum severity. Set on the Workspaces page; the organisation default lives in Settings.
- Analysts — Analysts: people who may see and triage the workspace’s incidents in the console, and nothing else. Grant and revoke on the Workspaces page; they are emailed on both.