The session is already open
A browser agent can operate inside an employee's signed-in session. The access granted to a person becomes access an agent can use.
Your employee signed in. An AI agent is now acting with their access. Identra detects agents driving the browser and can block them by policy.
What security teams run into with browser AI agents today, before a control is in place.
A browser agent can operate inside an employee's signed-in session. The access granted to a person becomes access an agent can use.
A request to summarize a report can lead an agent through pages, forms, and files. The employee may not review each action along the way.
An agent can carry work data into a personal AI account. Approving an AI app does not settle which account should receive that data.
Knowing which AI tools employees use does not decide whether those tools should drive signed-in browsers. Security teams need controls they can enforce.
Covered by Identra Guard in the browser, tied to one identity and one timeline.
The same moment, played twice. Once without Identra, once with it.
An employee opens an internal report in a signed-in browser.
They ask a computer-use agent to summarize it using an AI app.
The agent carries report text into a personal AI account without the employee reviewing the transfer.
Identra detects the AI agent driving the browser and blocks it under the organization's policy.
The employee opens ChatGPT themselves and is redirected from their personal account to the company AI workspace.
Before the employee sends report text, Identra checks the prompt on the device.
Sensitive content triggers the configured prompt policy, and the send is blocked.
Discover AI apps, the accounts people use, installed extensions, and AI agents driving the browser.
Set policies for browser agent blocking, account-aware AI access, sensitive prompts, and file uploads.
Block browser agents by policy, redirect supported AI access to company workspaces, and protect prompts before send.
Review browser activity alongside endpoint and provider activity in one identity timeline, where the person is known.
QUESTIONS
Prompt content stays on the device by default. Prompts are checked on the device before they are sent, and policy determines whether to allow, alert, mask or block.
Identra Guard is a browser extension for Chrome, Edge, Firefox and Safari. It provides browser agent detection and policy blocking, account-aware AI access, prompt protection, upload controls, and browser extension controls.
No. Policies can allow supported AI access or redirect employees to the company AI workspace. Prompt policies can allow, alert, mask sensitive content and send, or block. Browser agent activity can be blocked by policy.
Identra supports account-aware allow, redirect, and block controls for ChatGPT, Gemini, Claude, Perplexity, and Grok. These controls let you distinguish work accounts from personal accounts.
This solution focuses on AI agents driving the browser and the browser's account, prompt, upload, and extension controls. Identra's separate macOS and Windows endpoint agent covers coding agents, desktop AI apps, MCP servers, skills, and plugins. See secure coding agents for that use case.
Where the person is known, Identra ties browser, endpoint and provider activity to the person in one timeline and groups related activity into incidents. Reviewers get identity context across those surfaces.
KEEP READING
The terms, comparisons and essays behind this page.
A walkthrough with a security engineer.