Skip to main content

AI Usage Control

Overview​

AI Usage Control helps your company see and govern how employees use AI tools in the browser. It discovers which AI apps your team touches (such as ChatGPT, Claude, Gemini, Copilot, Perplexity, and Cursor), lets you mark each app as approved or not, and lets Dralvia warn or block risky data movement based on your policy. Every decision is recorded with redacted evidence so your reviewers can see what happened without exposing the sensitive value itself.

You will find it in the platform under Web Access Protection, in the AI Usage Control tab.

Why this matters​

Employees increasingly paste source code, API keys, customer data, credentials, contracts, and internal documents into AI tools. Some of those tools are approved for company use and some are personal accounts that sit outside your control. Without visibility, sensitive data can leave your company through a browser tab. AI Usage Control gives you that visibility and a way to act on it, directly in the browser, without replacing the browser or deploying a proxy.

What you can use it for​

  • Discover the AI tools your team is actually using (approved and unapproved).
  • Separate approved company AI workspaces from personal AI accounts.
  • Warn or block when secrets, credentials, or source code are sent to AI tools, based on your policy.
  • Coach users toward an approved path instead of silently failing.
  • Give reviewers a redacted, evidence-backed record of each AI-related decision.

How it works​

When the Dralvia browser extension is installed, it observes browser actions such as paste, file upload, form submission, download, and print. When an action happens on a known AI tool, Dralvia tags the activity as AI usage, classifies the content (for example secrets, credentials, or source code), and applies your policy. Depending on configuration, the default may be to observe and warn, and you can tighten it to block as you gain confidence.

Dralvia keeps a built-in catalog of well-known AI tools so it can recognize them on sight. Tools that are part of a larger app (for example an AI feature inside a general productivity app) are handled by your app and workspace policy rather than labeling the whole app as AI.

How to use it​

  1. Open Web Access Protection and select the AI Usage Control tab.
  2. Review the overview cards: how many AI apps were discovered, how many are approved, how many are unapproved or unknown, and how much activity was seen.
  3. In the AI apps table, set each app's Sanctioned classification (Sanctioned, Unsanctioned, Monitor, or leave unassigned) and its Control (Allow, Monitor, or Block). Both save immediately and can be changed back.
  4. Use the Policy presets to apply a common starting point in one click. For example, "Observe AI usage" or "Monitor all AI tool usage" applies a control across the AI apps you have discovered. You can revert any app afterward.
  5. Watch the AI activity feed to see recent AI-related browser actions, the action type (such as code paste or file upload), the data classes involved, and the decision.

Everything here is available in both the UI and the API, and both use the same underlying settings, so a change made one way is visible the other way.

Approved AI workspaces vs personal accounts​

Dralvia supports approved account domains, approved workspace identifiers, and SSO-required and workspace-bound app settings. This lets you allow an approved company AI workspace while warning or blocking the same tool used from a personal account, where it is configured.

Policy presets​

Each preset explains what it does, its enforcement level, the data classes it covers, the actions it covers, and its limitations:

  • Observe AI usage: discover and log AI usage without blocking. A good first step.
  • Monitor all AI tool usage: keep every discovered AI app under monitor.
  • Block unknown AI tools: block AI apps that are not sanctioned for your company.
  • Block secrets into AI tools and Block source code to unapproved AI: these are data-class rules. You set them in Browser Protection, under Policy Controls, alongside the other content rules.

Rolling out safely: observe, then warn, then block​

Start in observe mode to learn your baseline without disrupting anyone. Move to warn so users get coached toward an approved path. Move to block once you are confident. You can step back at any time by changing the control on an app or by applying the "Observe AI usage" preset.

Evidence and privacy​

Dralvia records redacted evidence for AI-related decisions. It does not store the raw pasted text, raw source code, raw file contents, passwords, or full token values. Reviewers see the data class that was detected and a short redacted sample, which is enough to act on without exposing the secret itself.

What Dralvia does and does not claim​

Dralvia provides browser-native AI usage control. It can warn or block sensitive paste, upload, submission, print, and download actions based on your policy.

Dralvia does not:

  • Replace your browser or require a proxy deployment.
  • Provide endpoint-wide data loss prevention outside the browser.
  • Provide full AI model governance or complete model observability.
  • Rewrite prompts.
  • Discover every possible AI tool. Discovery is based on browser activity and the built-in AI catalog.

By default, policy may be set to observe or warn depending on your configuration, so not everything is blocked unless you choose to block it.

How to test it​

  1. Make sure the browser extension is installed and AI Usage Control is at least in observe mode.
  2. Paste a sample block of source code into an unapproved AI tool and confirm the event appears in the AI activity feed as a code paste.
  3. Paste a sample API key into an AI tool and confirm it is detected as a secret.
  4. Upload a file to an unknown AI tool and confirm the upload is recorded.
  5. Use an approved AI workspace and confirm it is treated as approved.

How to roll back​

To relax enforcement for a single app, change its Control back to Monitor or No control in the AI apps table. To relax everything, apply the "Observe AI usage" preset. Sanctioned classifications can also be cleared back to unassigned at any time.

FAQ​

Can Dralvia block employees from pasting secrets into ChatGPT? Dralvia can detect sensitive classes such as secrets and credentials in browser actions and warn or block based on your policy.

Can Dralvia block source-code uploads to AI tools? Dralvia can classify source-code-like content during browser uploads, pastes, and submissions and warn or block based on the destination and your policy.

Does Dralvia require replacing the browser? No. It works through the Dralvia browser extension on supported browsers.

Does Dralvia store the raw secret? No. Dralvia keeps redacted evidence and avoids storing raw sensitive values.

Is this full AI model governance? No. Dralvia focuses on browser-native AI usage control, data movement, destination governance, and agent-action safety on supported surfaces.

Can Dralvia tell an approved AI workspace from personal usage? Where configured, yes. It supports approved account domains, approved workspace identifiers, SSO-required workflows, and workspace binding.