Policies

Decide once what every member must run and may change: locked setting packs, required extension or mobile app, work-mailbox policy, break-glass sign-in and admin visibility.

A policy is set by an owner or admin under Organization → Policies and applies to every member. Members' clients pick it up automatically — at start and live when it changes — and show anything locked as “Managed by <your organization>”.

The settings

SettingOptionsEffect
Locked setting packsChoose one or more packsThe pack's settings are applied to every member and shown read-only in their dashboard and extension. Members can still change anything outside the pack.
Require browser extensionOn / offMembers without the extension are counted as unprotected on the overview and see a nudge on their own dashboard.
Require mobile appOn / offSame as above for the Android / iOS app.
Work mailboxNone / optional / requiredNone hides mailbox connection from members. Optional lets them connect a work Gmail or Outlook. Required counts unconnected members as unprotected. Mailbox access is always read-only and always with the member's own consent.
Allow work e-mail code as fallbackOn / off (only when SSO is configured)Keeps the code-by-e-mail sign-in available next to SSO — useful while rolling SSO out or as break-glass if your identity provider is down. Recommended: off once SSO is verified working.
Admins can see member threatsOn (default) / offWhen off, admins see only counts on the overview, not the per-member threat list.
Join policyInvite only / auto-join by verified domainWhether anyone on a verified domain becomes an employee on first sign-in. Needs at least one verified domain; see Inviting people.

What a member sees

  • An organization badge and the organization name in the header.
  • Locked settings rendered disabled with the label “Managed by <organization>”.
  • If a required client is missing: a clear notice with the install link.
  • Under Settings → Connected accounts: the mailbox option hidden, offered or marked required, according to your policy.

Nothing else about the member's dashboard changes — their scans, history and personal preferences remain theirs.

How coverage is counted

The overview shows coverage as members meeting the policy ÷ seats in use, broken down by extension, mobile app and mailbox. A member is protected when every client you marked as required is present and signed in. Turning a requirement off removes it from the calculation immediately.

Versions and audit

Every policy save creates a new version; the audit log records who changed what and when. Clients switch to the new version within seconds when online, or the next time they start.

Recommended starting policy

  • Require the browser extension. It is where most protection lands.
  • Work mailbox optional during the pilot, required once people trust the verdicts.
  • One locked pack that sets your baseline; leave the rest to the individual.
  • Fallback sign-in on until SSO has passed Test login for two admins, then off.