Skip to content

Allow authorized Generative AI apps with restrictions

You can allow users to access approved Generative AI (Gen AI) applications while preventing them from uploading files and copying data from those applications. To do this, create an application group for the approved Gen AI apps and apply a web policy that blocks uploads and restricts data transfer.

Create an application group for authorized Gen AI apps

To create an application group for authorized Gen AI apps, do as follows:

  1. Go to My Products > Protected Browser > Policy objects.
  2. Click Add object.
  3. Select Application group.
  4. Enter a name for the application group.
  5. Expand Generative AI and select the authorized Gen AI apps.
  6. Click Save.

Create a web policy with restrictions

Create a web policy that allows access to the authorized Gen AI applications and applies restrictions to prevent data loss.

To create a web policy, do as follows:

  1. Go to My Products > Protected Browser > Web policy.
  2. Click Add policy.
  3. Enter a name for the policy.
  4. Select Allow as the policy action.
  5. Click Edit.
  6. Under Available, select the user groups you want to apply the policy to.
  7. Move the user groups to Assigned.
  8. Click Save.
  9. In Application group, select the application group you created for the authorized Gen AI apps.
  10. Under Upload protection, select Block all uploads.
  11. Under Data boundaries, select Keep data within this policy's destinations.
  12. Click Save.

Web policy settings for authorized Gen AI apps.