Browser Extension
See and control AI-site usage right in your users' browsers — monitor, warn, block, or redirect any AI site.
The Airia browser extension, installed in your users' browsers, sees which AI websites and apps they use and reports it to Airia. It can also enforce a Shadow AI policy for each AI site: for any site, you decide whether to monitor, warn, block, or redirect.
"Shadow AI" just means AI tools people use without IT knowing. The extension brings those into the light.
This page covers the Discover → Connect side: getting the extension to your fleet and setting Shadow AI policy. For the extension's configuration schema, managed-storage keys, and the full per-MDM deployment matrix, see the Browser Extension MDM Deployment Guide. For the extension as a chat surface, see Browser Extension.
At a glance
| Surface | Browser |
| What it does | Sees which AI sites people use, and can monitor / warn / block / redirect them |
| How Airia connects | The Airia extension is installed in users' browsers and tied to your Airia tenant |
| Who sets it up | Someone who can distribute browser extensions, usually IT |
| Time | ~20 min, plus rollout time |
How it gets to your users
| Method | Best for |
|---|---|
| Centrally (recommended) | IT pushes it via browser or enterprise management — for example a Chrome/Edge force-install policy — so it lands on every user's browser automatically |
| Manual install | You share an install link and users add it themselves |
Before you start
- Decide which browsers you need to cover: Chrome, Edge, Firefox.
- Access to your browser or enterprise management tool if you want to push the extension centrally (recommended) — for example Google Admin Console for Chrome, Intune or GPO for Edge.
- A rough idea of which AI sites you want to monitor versus warn, block, or redirect. You can change this at any time.
The Airia Browser Extension is published on the public extension stores — the Chrome Web Store (Chrome and other Chromium browsers, including Edge) and Firefox Add-ons. Search for "Airia". No special build or download from Airia is needed.
Setup
Part A — Deploy the extension
Get the Airia browser extension
- Chrome and Chromium browsers, including Edge: open the Chrome Web Store and search for "Airia" to find the Airia Browser Extension listing.
- Firefox: open Firefox Add-ons (addons.mozilla.org) and search for "Airia".
- Note the extension ID from the store listing's URL — you need it for force-install in the next step. For Chrome it's the 32-character string at the end of the listing URL.
After install, the user signs in to the extension with an Airia account and selects the correct region and tenant. That sign-in is what ties reported usage to your Airia account.
Distribute it to users
The recommended path is force-install via your browser management policy. Worked example for Chrome via Google Admin Console:
- In admin.google.com, go to Devices → Chrome → Apps & extensions → Users & browsers.
- Select the organizational unit you want covered.
- Click + → Add Chrome app or extension by ID, and paste the extension ID.
- Set Installation policy to Force install (or Force install + pin), then Save.
The extension lands in every user's Chrome in that OU automatically on the next policy sync.
Equivalents for other setups:
- Edge: push the extension ID through the
ExtensionInstallForcelistpolicy via Intune (Settings Catalog) or Group Policy. - Chrome via GPO or MDM, without Google Admin: the same
ExtensionInstallForcelistpolicy, delivered by your Windows GPO or macOS MDM. - Manual install: share the store link and have users add it and sign in themselves. Fine for a pilot, not reliable for full coverage.
Part B — Connect and set policy in Airia
Open the Browser Extension policies
- Go to Discover → Connect and click the Browser Extension tile. It opens the Browser Extension Policies page, also reachable under Security → Runtime Security → Browser Extension.
- Policies are per-group. Each policy has a name, who it applies to, its domain rules, and a status. A Default policy applies to everyone unless a more specific policy matches.
- Click Add policy, or open an existing one.
Set your Shadow AI policy
The policy editor has a few tabs. Work through them in order.
| Tab | What you set |
|---|---|
| General Settings | Policy name, enable browser-extension detection, optionally disable the floating chat panel and right-click context menus org-wide, and the polling interval (1–60 min — how often the extension refreshes its policy) |
| Assignment | Apply the policy to specific users or groups. Leave both empty to make it the tenant-wide default |
| Domain Rules | Per domain or URL pattern, pick the action — Monitor, Warn, Block, or Redirect — with an optional message shown to the user |
| Data Capture Settings | Optionally capture request bodies for analysis, with a maximum captured body size |
| Enterprise Identity (on builds where it appears) | Require users to sign in to ChatGPT, Claude, and Gemini with an approved corporate email domain, and block access when the account can't be verified |
What each action does:
| Action | What it does |
|---|---|
| Monitor | Record the usage without interrupting the user |
| Warn | Show the user a warning before they continue |
| Block | Stop the user from using the AI site |
| Redirect | Send the user somewhere else — for example to your approved Airia agent |
Start with everything on Monitor to learn what's in use, then tighten up later. Nothing is permanent.
Verify it worked
The connection shows Connected. As people browse, the extension's reported events appear under Discover → Activity Feed → Browser events, with per-user detail.
Run an end-to-end test
Prove the data is flowing before you widen the rollout. From one machine with the extension installed and signed in:
- Test discovery. Visit an AI site covered by a Monitor rule and load a page or send a throwaway prompt.
- In Airia, open Discover → Activity Feed → Browser events and confirm the visit appears within a few minutes, attributed to the signed-in user.
- Test enforcement. Add a Block rule for a low-stakes AI domain, wait one policy-refresh interval (the polling interval from General Settings), then visit that domain. You should see the block page or warning in the browser.
- Back in Airia, confirm the block or warn event is logged against the same user.
Only after both the discovery event and the enforcement event show up in Airia should you assign the policy beyond the test group.
Troubleshooting
| Symptom | Fix |
|---|---|
| No usage is reported | Confirm the extension actually installed (check your force-install policy rolled out) and that the user is signed in to the extension with an Airia account in the right region. An installed-but-signed-out extension reports nothing. |
| Only some users show up | The extension hasn't reached everyone yet, or some users haven't signed in. Force-install via your management policy and check sign-in state. |
| A block or warn isn't firing | Re-check the Domain Rules — confirm the domain pattern and action. Then wait one policy-refresh interval; the extension only picks up rule changes when it polls. |
| Usage shows but no user names | The extension reports anonymously until the user signs in. Confirm sign-in, or check the Assignment tab covers those users. |
What you get
What Airia discovers
| Object | Discovered? | Source |
|---|---|---|
| AI apps (AI sites used in the browser) | Yes | The Airia extension running in users' browsers |
| AI data sources | Yes | The Airia extension running in users' browsers |
| Per-user attribution | Yes | The extension reports usage per user |
| Agents / models / MCP & tools | — | Not produced by this connector |
Where it shows up
Discover → Activity Feed → Browser events shows every AI-site event the extension reports, per user and per site, including warn and block outcomes.
How often it syncs
Continuous. The extension reports as people browse, with no fixed schedule — usage shows up in near real time.
What you can do
Govern — every AI site used in the browser is inventoried, with per-user detail, so you can review and classify it.
Secure — set a Shadow AI policy per AI site or category: Monitor, Warn, Block, or Redirect. The extension enforces your choice right in the user's browser, and you can change any site's action at any time.
| Capability | Supported |
|---|---|
| Discover | Yes |
| Govern | Yes |
| Secure | Yes — monitor / warn / block / redirect per site |
Related
- Browser Extension MDM Deployment Guide — configuration schema and per-MDM deployment.
- Microsoft SCCM — force-installing and locking the extension on Windows fleets.