to control access to a GenAI app for specific users.
For example, based on your investigation you discover that there are multiple
unsanctioned GenAI apps with a large volume of data usage. This poses a
security risk because there are users accessing an unapproved app on the
network and you don't know what data is being downloaded or uploaded. Until
you can perform proper due diligence to understand the GenAI app purpose and
who is permitted to use the GenAI app, you can Block
the GenAI app for all users.
Conversely, you notice there are some Unsanctioned
GenAI apps listed that but they are GenAI apps approved for use on your
network by specific users with a large volume of data usage. In this case,
you can change the tag to Sanctioned and write a
policy rule to Allow usage of the app but only for
users in specific roles or departments. In the policy rule you can associate
an Enterprise Data Loss Prevention (E-DLP) data profile to prevent exfiltration of
sensitive data and a Vulnerability profile to stop attempts to exploit
system flaws or gain unauthorized access to systems.