Settings

General

Privacy and Data Retention

Retention period controls how long the system stores user data. The default retention period is 30 days.

Risk threshold defines which AI interactions are stored based on their risk level classification.

Available options:

  • Low risk and above

  • Medium risk and above

  • High risk and above

  • Critical risk only

  • Any risk (No risk and above)

Important - When you select Any risk (No risk and above), you enable broader visibility into user prompts and AI interactions and broader storage of this data. Make sure that you use this setting according to your organization’s policies and applicable requirements.

Note - Changes made in this section can take up to one hour to take effect.

Connection Restrictions

Connection Restrictions lets administrators control which source IP addresses can use the account's client tokens. This helps limit token usage to approved networks and reduces the risk of unauthorized connections.

When restrictions are enabled, only connections originating from configured IP ranges are allowed to authenticate with the account's client tokens.

Administrators can define allowed sources using one of these formats:

  • CIDR notation (for example, 10.0.0.0/8)

  • IP range (for example, 192.168.1.10 - 192.168.1.20)

To configure connection restrictions:

  1. Go to Settings > General > Connection restrictions.

  2. Click Add.

  3. Select the restriction type:

    • CIDR

    • IP range

  4. Enter the required IP address range.

  5. Optionally, set the entry to Enabled.

  6. Click Add.

  7. Repeat as necessary for additional ranges.

  8. Turn on Enable restrictions (only the added IPs are allowed).

User Interactions

You can configure blocking messages for different protection types.

To configure:

  • Logo - Click Upload to add your company logo and use it in the message.

  • Title and Description for Access rule notifications - Edit the default messages. To configure the message for a specific rule, see Manage Interactions - Access.

  • Title and Description for Chat notifications on Ask action triggered - Edit the default messages. To configure the message for a specific rule, see Manage Interactions - Chats.

After editing the message, click the Preview button to see how it is displayed to the users.

Managed Applications

This page allows administrators to define organization-approved app instances and manage organizational licenses. For example, if your company has an official subscription for ChatGPT, you can mark it as managed by entering the license details. This allows to apply different policies to approved organizational accounts and to personal accounts, reducing the risk of uncontrolled usage. This capability complements access policies (see Manage Interactions - Chats) by allowing you to enforce rules based on license ownership.

To add a new managed application instance:

  1. Go to Settings > Managed application.

  2. In the table, select the platform for which you want to register a license.

  3. In the side panel that opens, click Add.

  4. In the Add organization ID window, enter the details:

    1. Configuration Name - The name of the organization or department that owns the license.

    2. Organization ID - The license number.

  5. Click Add.

  6. Click Save.

After the managed application is used in a rule, the configuration shows the number of linked policy rules.

User & Device Sync

Use this page to configure how Workforce AI Security retrieves identity and device information.

You can:

  • Select the Identity Provider (IdP) that supplies users and groups for policy rules.

  • Configure User & Device Synchronization (MDM) to identify users on the Inventory and Risk Posture pages.

Note - Connecting an MDM identifies users for Inventory and Risk Posture only. It does not synchronize users for policy rules and does not automatically deploy the agent or the script.

These configurations are independent and serve different purposes. For more information about Workforce AI Security connection to external systems, see External System Connections and Deployment Methods.

Identity Provider Selection

The selected Identity Provider (IdP) defines the source of users and groups that you can use when configuring policy scope in Workforce AI Security.

IDP Selection states

The behavior of IDP Selection depends on how many Identity Providers are configured in your environment:

  • No Identity Provider configured - No IdP is available. You must configure an Identity Provider in the Check Point Portal before you can use identity-based policy rules.

  • One Identity Provider configured - The IdP is automatically used as the active Identity Provider (shown as Chosen IdP). No selection is required.

  • Multiple Identity Providers configured - You can select which IdP to use. The selected IdP becomes the active Identity Provider (shown as Chosen IdP).

    Note - You can select only one IdP.

The option to choose an Identity Provider is available only when multiple IdPs are configured.

Important - Changing the selected Identity Provider can affect existing policy assignments. Review your policies after making changes.

To select an Identity Provider:

  1. In the Workforce AI Security menu, go to Settings.

  2. Select User & Device Sync.

  3. In IDP Selection, select the required Identity Provider.

  4. Click Save.

For information about connecting Identity Providers, see Identity Providers.

User and Device Management

You can configure integration with your organization's Mobile Device Management (MDM) for user and device synchronization.

To connect your organization's MDM for automatic mapping of users and devices, see each integration in the Appendices.