Browser Extension

See and control AI-site usage right in your users' browsers — monitor, warn, block, or redirect any AI site.

The Airia browser extension, installed in your users' browsers, sees which AI websites and apps they use and reports it to Airia. It can also enforce a Shadow AI policy for each AI site: for any site, you decide whether to monitor, warn, block, or redirect.

"Shadow AI" just means AI tools people use without IT knowing. The extension brings those into the light.

This page covers the Discover → Connect side: getting the extension to your fleet and setting Shadow AI policy. For the extension's configuration schema, managed-storage keys, and the full per-MDM deployment matrix, see the Browser Extension MDM Deployment Guide. For the extension as a chat surface, see Browser Extension.

At a glance

SurfaceBrowser
What it doesSees which AI sites people use, and can monitor / warn / block / redirect them
How Airia connectsThe Airia extension is installed in users' browsers and tied to your Airia tenant
Who sets it upSomeone who can distribute browser extensions, usually IT
Time~20 min, plus rollout time

How it gets to your users

MethodBest for
Centrally (recommended)IT pushes it via browser or enterprise management — for example a Chrome/Edge force-install policy — so it lands on every user's browser automatically
Manual installYou share an install link and users add it themselves

Before you start

  • Decide which browsers you need to cover: Chrome, Edge, Firefox.
  • Access to your browser or enterprise management tool if you want to push the extension centrally (recommended) — for example Google Admin Console for Chrome, Intune or GPO for Edge.
  • A rough idea of which AI sites you want to monitor versus warn, block, or redirect. You can change this at any time.

The Airia Browser Extension is published on the public extension stores — the Chrome Web Store (Chrome and other Chromium browsers, including Edge) and Firefox Add-ons. Search for "Airia". No special build or download from Airia is needed.

Setup

Part A — Deploy the extension

Get the Airia browser extension

  1. Chrome and Chromium browsers, including Edge: open the Chrome Web Store and search for "Airia" to find the Airia Browser Extension listing.
  2. Firefox: open Firefox Add-ons (addons.mozilla.org) and search for "Airia".
  3. Note the extension ID from the store listing's URL — you need it for force-install in the next step. For Chrome it's the 32-character string at the end of the listing URL.

After install, the user signs in to the extension with an Airia account and selects the correct region and tenant. That sign-in is what ties reported usage to your Airia account.

Distribute it to users

The recommended path is force-install via your browser management policy. Worked example for Chrome via Google Admin Console:

  1. In admin.google.com, go to Devices → Chrome → Apps & extensions → Users & browsers.
  2. Select the organizational unit you want covered.
  3. Click + → Add Chrome app or extension by ID, and paste the extension ID.
  4. Set Installation policy to Force install (or Force install + pin), then Save.

The extension lands in every user's Chrome in that OU automatically on the next policy sync.

Equivalents for other setups:

  • Edge: push the extension ID through the ExtensionInstallForcelist policy via Intune (Settings Catalog) or Group Policy.
  • Chrome via GPO or MDM, without Google Admin: the same ExtensionInstallForcelist policy, delivered by your Windows GPO or macOS MDM.
  • Manual install: share the store link and have users add it and sign in themselves. Fine for a pilot, not reliable for full coverage.

Part B — Connect and set policy in Airia

Open the Browser Extension policies

  1. Go to Discover → Connect and click the Browser Extension tile. It opens the Browser Extension Policies page, also reachable under Security → Runtime Security → Browser Extension.
  2. Policies are per-group. Each policy has a name, who it applies to, its domain rules, and a status. A Default policy applies to everyone unless a more specific policy matches.
  3. Click Add policy, or open an existing one.

Set your Shadow AI policy

The policy editor has a few tabs. Work through them in order.

TabWhat you set
General SettingsPolicy name, enable browser-extension detection, optionally disable the floating chat panel and right-click context menus org-wide, and the polling interval (1–60 min — how often the extension refreshes its policy)
AssignmentApply the policy to specific users or groups. Leave both empty to make it the tenant-wide default
Domain RulesPer domain or URL pattern, pick the action — Monitor, Warn, Block, or Redirect — with an optional message shown to the user
Data Capture SettingsOptionally capture request bodies for analysis, with a maximum captured body size
Enterprise Identity (on builds where it appears)Require users to sign in to ChatGPT, Claude, and Gemini with an approved corporate email domain, and block access when the account can't be verified

What each action does:

ActionWhat it does
MonitorRecord the usage without interrupting the user
WarnShow the user a warning before they continue
BlockStop the user from using the AI site
RedirectSend the user somewhere else — for example to your approved Airia agent

Start with everything on Monitor to learn what's in use, then tighten up later. Nothing is permanent.

Verify it worked

The connection shows Connected. As people browse, the extension's reported events appear under Discover → Activity Feed → Browser events, with per-user detail.

Run an end-to-end test

Prove the data is flowing before you widen the rollout. From one machine with the extension installed and signed in:

  1. Test discovery. Visit an AI site covered by a Monitor rule and load a page or send a throwaway prompt.
  2. In Airia, open Discover → Activity Feed → Browser events and confirm the visit appears within a few minutes, attributed to the signed-in user.
  3. Test enforcement. Add a Block rule for a low-stakes AI domain, wait one policy-refresh interval (the polling interval from General Settings), then visit that domain. You should see the block page or warning in the browser.
  4. Back in Airia, confirm the block or warn event is logged against the same user.

Only after both the discovery event and the enforcement event show up in Airia should you assign the policy beyond the test group.

Troubleshooting

SymptomFix
No usage is reportedConfirm the extension actually installed (check your force-install policy rolled out) and that the user is signed in to the extension with an Airia account in the right region. An installed-but-signed-out extension reports nothing.
Only some users show upThe extension hasn't reached everyone yet, or some users haven't signed in. Force-install via your management policy and check sign-in state.
A block or warn isn't firingRe-check the Domain Rules — confirm the domain pattern and action. Then wait one policy-refresh interval; the extension only picks up rule changes when it polls.
Usage shows but no user namesThe extension reports anonymously until the user signs in. Confirm sign-in, or check the Assignment tab covers those users.

What you get

What Airia discovers

ObjectDiscovered?Source
AI apps (AI sites used in the browser)YesThe Airia extension running in users' browsers
AI data sourcesYesThe Airia extension running in users' browsers
Per-user attributionYesThe extension reports usage per user
Agents / models / MCP & toolsNot produced by this connector

Where it shows up

Discover → Activity Feed → Browser events shows every AI-site event the extension reports, per user and per site, including warn and block outcomes.

How often it syncs

Continuous. The extension reports as people browse, with no fixed schedule — usage shows up in near real time.

What you can do

Govern — every AI site used in the browser is inventoried, with per-user detail, so you can review and classify it.

Secure — set a Shadow AI policy per AI site or category: Monitor, Warn, Block, or Redirect. The extension enforces your choice right in the user's browser, and you can change any site's action at any time.

CapabilitySupported
DiscoverYes
GovernYes
SecureYes — monitor / warn / block / redirect per site
Was this page helpful?

On this page