Documentation

Groups of Controls

What it does: Defines named groups of domains/URLs and the content-protection actions enforced on them. Rules only take effect once applied to a group.

How to set up:

  1. Click + new group β€” the Content protection for SaaS Apps dialog opens.
  2. Enter a DLP group name.
  3. Domain/URLs tab: pick a Working mode (Protect all URLs / Protect specific URLs / Protect by category), then add URLs (+ Add URL) or toggle the built-in SaaS apps (+ Add application) the group applies to.
  4. Protected Actions tab: enable the actions to enforce (see list below).
  5. Protected PII data tab: choose the mask style and enable the PII/secret detectors (see list below).
  6. Click Save. Back in the list, use the per-row ENABLE toggle, ✏️ to edit, or βœ• to delete the group.
Groups of Controls β€” list of groups (Group name Β· Domains/URLs Β· Protected Actions Β· Enable Β· Action)

Creation form β€” Domain/URLs tab

Choose the working mode and select which sites/apps the group covers. Built-in SaaS apps (GitHub, GitLab, Gmail, O365, Salesforce, Notion, Workday, Zendesk, …) can be toggled individually, or add your own with + Add URL / + Add application.

New group β†’ Domain/URLs tab

Creation form β€” Protected Actions tab (the actions you can block on the group's sites):

  • Copy β€” protect from copying content.
  • Paste β€” protect from pasting content.
  • Print β€” protect from printing content.
  • View Source Code β€” protect from viewing the page source code.
  • Screen Capture β€” protect from screen capturing.
  • Watermark β€” overlay a watermark on the user's view (deters/traces screenshots).
  • Database Injection β€” block database-injection strings in input fields.
  • Cross Browser Redirect β€” redirect users to the SURF browser to access content with policies unsupported on Chrome.
New group β†’ Protected Actions tab (Copy, Paste, Print, View Source Code, Screen Capture, Watermark, Database Injection, Cross Browser Redirect)

Creation form β€” Protected PII data tab (detect & mask sensitive data before it leaves):

  • Mask display style β€” *Legacy* (replace characters with X) or *Redacted* (replace matches with [REDACTED]).
  • Built-in detection rules β€” toggle the PII/secret detectors to enforce: SSN, Credit Card Number, Currency/Financial, IBAN, SWIFT/BIC, Email Address, PEM/SSH Key, AWS Key, JWT, Bearer Token, OpenAI/API Key (sk-), High-entropy Secrets.
  • Custom rules β€” add your own regex-based patterns for organization-specific data.
  • Spreadsheets β€” run PII checks inside Google Sheets and Excel Online.
  • View masked data β€” optionally require a password to reveal masked PII.
New group β†’ Protected PII data tab (mask style + built-in detectors + custom rules)