A policy is set by an owner or admin under Organization → Policies and applies to every member. Members' clients pick it up automatically — at start and live when it changes — and show anything locked as “Managed by <your organization>”.
The settings
| Setting | Options | Effect |
|---|---|---|
| Locked setting packs | Choose one or more packs | The pack's settings are applied to every member and shown read-only in their dashboard and extension. Members can still change anything outside the pack. |
| Require browser extension | On / off | Members without the extension are counted as unprotected on the overview and see a nudge on their own dashboard. |
| Require mobile app | On / off | Same as above for the Android / iOS app. |
| Work mailbox | None / optional / required | None hides mailbox connection from members. Optional lets them connect a work Gmail or Outlook. Required counts unconnected members as unprotected. Mailbox access is always read-only and always with the member's own consent. |
| Allow work e-mail code as fallback | On / off (only when SSO is configured) | Keeps the code-by-e-mail sign-in available next to SSO — useful while rolling SSO out or as break-glass if your identity provider is down. Recommended: off once SSO is verified working. |
| Admins can see member threats | On (default) / off | When off, admins see only counts on the overview, not the per-member threat list. |
| Join policy | Invite only / auto-join by verified domain | Whether anyone on a verified domain becomes an employee on first sign-in. Needs at least one verified domain; see Inviting people. |
What a member sees
- An organization badge and the organization name in the header.
- Locked settings rendered disabled with the label “Managed by <organization>”.
- If a required client is missing: a clear notice with the install link.
- Under Settings → Connected accounts: the mailbox option hidden, offered or marked required, according to your policy.
Nothing else about the member's dashboard changes — their scans, history and personal preferences remain theirs.
How coverage is counted
The overview shows coverage as members meeting the policy ÷ seats in use, broken down by extension, mobile app and mailbox. A member is protected when every client you marked as required is present and signed in. Turning a requirement off removes it from the calculation immediately.
Versions and audit
Every policy save creates a new version; the audit log records who changed what and when. Clients switch to the new version within seconds when online, or the next time they start.
Recommended starting policy
- Require the browser extension. It is where most protection lands.
- Work mailbox optional during the pilot, required once people trust the verdicts.
- One locked pack that sets your baseline; leave the rest to the individual.
- Fallback sign-in on until SSO has passed Test login for two admins, then off.