Manage Interactions - Chats

The Chats page focuses on interactions that take place within chat-based AI services, including web and desktop versions of conversational tools. It provides summaries of chat sessions, along with indicators that highlight prompt activity and potential risk. For each interaction, the view shows the results of applied policies, making it easier to understand how enforcement is being carried out across conversational AI usage.

Administrators use this area to apply DLP policies that prevent sensitive information from being included in prompts, to block or limit interactions that are considered risky, and to monitor overall compliance for chat-based AI tools. To learn examples of the Chats policies, see Control Policy Framework.

To add a new rule:

  1. From the left menu, select Workforce AI > Manage Interactions > Chats.

  2. On the toolbar, click Create new.

  3. On the right pane, edit the new rule. Enter the rule name.

  4. Set the Active slider to ON (green).

  5. Configure Settings:

    1. Select the event type:

      • Prompt

      • File Upload (supported only for browser-based GenAI and ChatGPT, Claude Desktop)

      • Paste (supported only for browser-based GenAI)

      • or any combination of them

      Note - For traffic monitored through the Claude Compliance API integration, only File Upload events are supported. Prompt and Paste events are not supported. In addition, only the Detect action is currently available for file scanning through this integration.

    2. Select Entire organization to apply the rule for all users.

    3. Select Selected users and groups to set the rule granularity:

      • Select the relevant groups from the list. The groups appear based on the selected Identity Provider.

      • Select the relevant users from the list. The users appear based on the selected Identity Provider.

    4. Set the destination:

      • Any platform - For all applications.

      • Selected platforms - Select one or more standalone discovered AI tools.

      • Managed platforms - Select one or more application platforms managed by your organization. To set up a platform as managed, see Managed Applications.

    5. From the Data Types list, select the sensitive data types you want the rule to monitor. If you need help choosing the appropriate categories, use the DLP details button to refine your selection. For more information about Data Types, see Data Types Classification.

      Note -

      Data Type selection is limited to a maximum of 100 Data Types across all policies in an account.

      To ensure effective enforcement, select the Data Types that are most relevant to your organization’s data protection needs.

    6. Select the Action to perform when the rule is triggered:

      • Allow

      • Ask

      • Block

      • Prevent

      • Detect

      • Redact (not supported for files)

    7. Select to enable or disable Logging.

    8. Optionally, add a comment.

  6. For Ask actions only, configure Customization:

    1. Below Blocking messages, select:

      • Default to use global blocking messages configured in Settings > User Interactions.

      • Custom to edit a rule-specific message:

        • Edit Title.

        • Edit Description.

        • Click Preview page to see the message.

  7. Click Save.

Policy

Short Description

Behavior

Data Flow Data Control

Allow

Always allow the action

Accepts the entered data without restrictions. Action proceeds normally.

Allowed

Not restricted

Ask

User must confirm

Prompts the user to approve or cancel the action before proceeding.

Conditional

Conditional

Block

Do not allow the action

Rejects the entered data and stops the action.

Not allowed

Attempt blocked

Detect

Log the event only

Identifies and records the data event without changing or interrupting the action.

Allowed

Not restricted

Prevent

Strictly block the action

Actively stops the action and may disable the ability to submit data.

Not allowed

Action disabled

Redact

Remove sensitive data

Allows the action but removes or masks sensitive information before processing.

Sanitized only

Sensitive data