Rolling out the Prism extension (for your IT team)
Prism’s browser extension checks what people paste, upload or send as a message in AI tools (ChatGPT, Claude, Gemini, Copilot, Perplexity and the other AI websites you choose under Destinations, about 90 in all) against your organisation’s policy. It can also tell work accounts from personal ones on the tools that support it, and shows which AI websites are used and for how long each day. This page is for whoever manages Chrome or Edge at your organisation: installing it for everyone, configuring it centrally, and closing the obvious gaps.
Quickest route: the Prism console’s Set up page generates everything below (Jamf files, Google Admin policy, Windows registry file) with your API URL and a new sensor key filled in, and has the same steps.
You’ll need two values (both on Set up):
- API URL:
https://api.prism-dlp.com - Sensor key, starting
pk_…. It can only send events to your organisation; it can’t read anything. Create, revoke and replace keys on Set up.
The extension’s Chrome Web Store ID is oblejifclpmcamglacjnhmfmdccpbnmk (unlisted listing: https://chromewebstore.google.com/detail/oblejifclpmcamglacjnhmfmdccpbnmk).
1. Force-install
Google Admin console (Chrome browser cloud management or managed ChromeOS/Chrome):
- Devices → Chrome → Apps & extensions → Users & browsers, then choose the organisational unit or group.
- + → Add Chrome app or extension by ID, enter
oblejifclpmcamglacjnhmfmdccpbnmk, source From the Chrome Web Store. - Set Installation policy to Force install + pin to browser toolbar.
Any other management tool (the ExtensionSettings policy, as JSON):
{
"oblejifclpmcamglacjnhmfmdccpbnmk": {
"installation_mode": "force_installed",
"update_url": "https://clients2.google.com/service/update2/crx",
"toolbar_pin": "force_pinned"
}
}
Users can’t disable or remove a force-installed extension.
2. Configure it centrally
The extension reads these settings from policy, and users can’t change them:
| Key | Value |
|---|---|
apiUrl |
the API URL from Prism |
apiKey |
the sensor key from Prism |
email |
recommended: the user’s work email (Jamf: $EMAIL). Without it, the signed-in Chrome profile’s email is used. An email the user types in on the extension’s settings page is recorded but never unlocks an exception |
name |
optional; used only to recognise the user’s own contact details |
Google Admin console: select the extension (step 1) and paste this into Policy for extensions:
{
"apiUrl": { "Value": "https://api.prism-dlp.com" },
"apiKey": { "Value": "pk_…" }
}
macOS (Jamf or any MDM). Chrome on a Mac reads two preference domains: com.google.Chrome for ExtensionSettings (step 1) and com.google.Chrome.extensions.oblejifclpmcamglacjnhmfmdccpbnmk for Prism’s own settings, as top-level keys:
<key>apiUrl</key><string>https://api.prism-dlp.com</string>
<key>apiKey</key><string>pk_…</string>
Ready-made files and Jamf Pro steps, for Chrome and Edge: jamf/.
Windows (Group Policy or registry) (verify at chrome://policy on a test machine):
HKLM\SOFTWARE\Policies\Google\Chrome
ExtensionSettings (REG_SZ) {"oblejifclpmcamglacjnhmfmdccpbnmk":{"installation_mode":"force_installed","update_url":"https://clients2.google.com/service/update2/crx","toolbar_pin":"force_pinned"}}
IncognitoModeAvailability (REG_DWORD) 1
HKLM\SOFTWARE\Policies\Google\Chrome\3rdparty\extensions\oblejifclpmcamglacjnhmfmdccpbnmk\policy
apiUrl (REG_SZ) https://api.prism-dlp.com
apiKey (REG_SZ) pk_…
3. Close the gaps
- Incognito: extensions don’t run in Incognito unless allowed. Disable Incognito with
IncognitoModeAvailability = 1(shown above), or accept that gap. - Other browsers and desktop apps: the extension covers Chrome and Edge (same extension, see
jamf/). Block or restrict other browsers if they’re in scope. Desktop AI apps (ChatGPT, Claude, Cursor), AI command-line tools and copies to USB or cloud folders are covered by the Prism agent for Macs (jamf/macos-agent.md). - Every website, not just AI tools: a separate “Prism DLP (all sites)” extension checks pastes and uploads everywhere except the sites you skip (Destinations → Browser coverage). Ask us for it; tell your staff if you use it.
- Unmanaged devices: policy only applies to managed Chrome. On a personal device the extension can be installed from the store link and configured by hand, but the user can turn it off.
4. Check it worked
- On a test machine, open
chrome://policyand click Reload policies.ExtensionSettingsand the extension’sapiUrl/apiKeyshould be listed with status OK. - Open
chrome://extensions. Prism is installed, shows “Installed by your administrator”, and can’t be removed. - Paste a harmless test secret such as
AKIAIOSFODNN7EXAMPLEinto ChatGPT, and type and send another message containing it. Both appear under Incidents within a few seconds. In observe mode they’re recorded, not blocked; start in observe mode for the first week, review what it finds, then switch to Coach or Block (Settings). - Within about 15 minutes, AI tools lists ChatGPT as a website in use.
What the extension sends
Only on the AI websites your organisation watches, and nothing at all until it’s configured:
- when someone pastes, uploads or sends a message (on send, never while typing): the text or a text file’s contents (other files: name, type and size), the site and page address without query strings, and the user’s work email
- which kind of account is signed in on the AI site (the email domain, never the full address, or the ChatGPT workspace or Claude organisation ID), so Prism can tell work accounts from personal ones
- how long each watched AI site was in use each day (no page addresses, titles or content), unless you turn AI tool reporting off (Settings)
Detected secrets and personal data are replaced with placeholders by Prism before anything is stored; the original values are never kept. Full details: https://prism-dlp.com/privacy.
Versions
The store keeps managed browsers up to date automatically. 0.1.1 adds typed messages, the ~90 AI sites, work vs personal accounts and AI tool use; 0.1.2 adds support for time-limited exceptions (which apply only to an email set by your organisation or the Chrome profile).
Updated 9 October 2026