A policy is set by an owner or admin under Organization → Policies and applies to every member. Members' clients pick it up automatically — at start and live when it changes — and show anything locked as “Managed by <your organization>”.
The settings
| Setting | Options | Effect |
|---|---|---|
| Locked setting packs | Choose one or more packs | The pack's settings are applied to every member and shown read-only in their dashboard and extension. Members can still change anything outside the pack. |
| Require browser extension | On / off | Members without the extension are counted as unprotected on the overview and see a nudge on their own dashboard. |
| If a member removes OKY | Allowed / warn / block | Allowed does nothing beyond showing the member as uncovered. Warn (default) records the removal in your audit log, notifies admins and asks the member to reinstall. Block also withholds that member's OKY dashboard until an install reports back — owners and admins are never blocked, and it needs Require browser extension to be on. See Deployment for the part that actually prevents removal. |
| Work account on your devices | Any / ask / work only | A browser or phone becomes yours the first time a member signs in on it, or immediately when your IT pushes the enrollment from Deployment. This decides what happens when one of those devices is then used with a personal account — a private Gmail, say: it is protected, but you cannot see it. Any has no opinion. Ask (default) records it in your audit log, tells admins, and names the work account on the sign-in page and inside the extension. Work only also refuses the personal account on your devices: the extension signs it out and the sign-in page offers only the work account. |
| Members may sign out | Off (default) / on | On shows Sign out to members in the extension, the dashboard and the apps. Off does not stop a member uninstalling OKY — that is what If a member removes OKY notices. |
| Members may delete their account | Off (default) / on | Off hides Delete account and refuses the request for accounts your organization created. Members who joined with an account they already had keep the right to delete it. |
| Protection layers | Read-only | Which layers your plan includes — link protection, crypto detector, prompt-injection shield, attestation warning. Members are offered only the layers you have, and their extension counts them accordingly. Talk to us to change what's included. |
| Allow work e-mail code as fallback | On / off (only when SSO is configured) | Keeps the code-by-e-mail sign-in available next to SSO — useful while rolling SSO out or as break-glass if your identity provider is down. Recommended: off once SSO is verified working. |
| Admins can see member threats | On (default) / off | When off, admins see only counts on the overview, not the per-member threat list — and a threat's details drop everything that identifies the person: the page it was opened from, the browser, and their other threats that day. The threat itself (address, evidence, screenshot) stays. |
| Warn on remote-access tool installers | On (default) / off | Members see a caution page before downloading AnyDesk, TeamViewer, UltraViewer, RustDesk and similar installers — the tools scammers talk people into installing so they can drive the computer. It is a policy warning, not a threat verdict: the download still opens when the member continues, and the threat feed labels it “Organisation policy”. Switch it off if your IT team hands these tools out routinely. |
| Join policy | Invite only / auto-join by verified domain | Whether anyone on a verified domain becomes an employee on first sign-in. Needs at least one verified domain; see Inviting people. |
Trusted and blocked sites
Reputation services cannot know that yourcompany.atlassian.net is your Jira or that a supplier's portal is safe. Under Organization → Trusted & blocked sites you tell OKY yourself, and the rule applies to every member before any check runs:
- Trusted — members are never warned about the site. It also clears any record OKY's own scans had written for an address on it. A rule for
example.comcovers its subdomains; a shared hosting platform (github.io, bolt.host) cannot be trusted as a whole — add the specific site. - Blocked — members are stopped before the site opens, even if they had added it to their own trusted list.
You can also trust or block a site straight from a threat in the feed (“For your organisation” on the threat detail). Members see trusted sites in their own Trusted sites list as “Managed by your organization”. Every change is in the audit log.
What a member sees
- An organization badge and the organization name in the header.
- Locked settings rendered disabled with the label “Managed by <organization>”.
- If a required client is missing: a clear notice with the install link.
- Only the protection layers your plan includes — an organization without the crypto detector sees “3 of 3 layers”, never a layer it cannot switch on.
Nothing else about the member's dashboard changes — their scans, history and personal preferences remain theirs.
How coverage is counted
The overview shows coverage as members meeting the policy ÷ seats in use, broken down by extension and work-account sign-in. A member is protected when every client you marked as required is present and signed in. Turning a requirement off removes it from the calculation immediately.
Versions and audit
Every policy save creates a new version; the audit log records who changed what and when. Clients switch to the new version within seconds when online, or the next time they start.
Recommended starting policy
- Require the browser extension. It is where most protection lands.
- One locked pack that sets your baseline; leave the rest to the individual.
- Fallback sign-in on until SSO has passed Test login for two admins, then off.