Endpoint Controls

Access granted is not the end of the story.

What happens inside the session — copying, downloading, wandering — is policy too.

the six controls_

enforced per app, per user group — every event is one of 202 logged types.

A live remote session to SAP ERP, showing the Q3 vendor payment schedule. It runs from a managed laptop, and the tunnel out of it reaches that one application and nothing else on the network — the file server, the internal range and the database are all off the map. A copy of two invoice rows has been attempted and refused, so the local clipboard is stamped BLOCKED; a watermark carrying the user, the session ID and the time is rendered over the screen; downloads and printing are switched off; a personal file-sharing domain is denied while a support domain is allowed; and the session closes on its own after fifteen minutes idle. Each of those decisions is written to the audit log.

What are endpoint controls?

Endpoint Controls

Not who gets in — what happens once they are.

Traditional security ends at the login: once in, the user's actions are their own. Endpoint controls extend policy into the live session — because most data loss isn't a hack, it's an allowed user doing an unallowed thing.

  • The risk is a permitted personPasting a customer table into personal email, downloading the price list before resigning, screensharing a console with credentials visible. None of those trip an intrusion alarm, because none of them are an intrusion.
  • Enforced on the device, not requested of the userInstaSafe's endpoint controls are enforced by the agent and portal on the device itself, which is why they hold on a laptop nobody in IT has ever touched.
  • Set per application and per user groupSo the sales tool can allow exporting while the HR system forbids even copy — same person, same session, different answer.
  • And every refusal is written downClipboard, watermark, network filter, app filter, chrome control, inactivity timeout. Each enforcement is one of 202 logged event types, so a block is evidence rather than a dead end.
Access grantedthe point where traditional security stops lookinglogin passedInside the sessionsix controls, set per application and per user groupsix controlsClipboard controlsClipboardWatermark protectionWatermarkNetwork filterNetworkApp filterAppsChrome controlChromeInactivity timeoutIdleCopy outCopyrefusedDownload fileDownloadrefusedPersonal drivePersonalrefusedWork in the appIn appallowed10:42:11 CLIP direction=out action=blocked · one of 202 logged typesCLIP action=blocked
6session controls
per-appand per-group
202logged event types
The six controls

Six things a session will not do for you.

Each control is a policy on an application and a user group, not a switch on a laptop. Hover any card to watch it enforce. Nothing here needs an agent rebuild, a proxy in front of the app, or a ticket queue.

Clipboard controls —
the copy that never leaves

Block copy/paste and clipboard access for designated applications; block screen-capture and screen-recording actions initiated through the governed session context.

Watermark protection —
the screen names its viewer

A logo and text overlay is rendered over on-screen content, carrying the user, the session ID and the time — so a photograph of the screen identifies who took it.

Network filter —
where the session may reach

Specified domains and IP ranges are blocked per user group for the life of the session. The support domain still resolves; the personal drive does not.

App filter —
the tool that will not start

Named local applications are blocked from launching while a sensitive session is open, and released the moment it closes.

Chrome control —
the browser, minus the exits

Downloads, developer tools and printing are switched off in governed browsing. The application itself stays entirely usable.

Inactivity timeout —
the unattended desk, closed

Idle or low-transfer sessions disconnect on their own, and the disconnect is logged like every other decision.

The controls, live

Try them yourself.

This is a real desktop, not a video. Turn a control on in the admin console and then attempt the thing it governs — the session answers the way it would on a laptop nobody in IT has ever touched.

The session ends. The evidence stays.

ARMED CONTROLSDownloadBlockedClipboardBlockedScreenshotBlockedUSB accessDisabledLive enforcementContext awareAutomatic loggingINSIDE THE SESSIONFinance dashboardapp.company.com/financeQuarterly revenue$ 8,542,316+12.6% vs last quarterDrop to downloadCONFIDENTIALalex@company.com10:24 AMActivity logTODAY · 14410:24:31Download blockedQ4_Forecast.xlsxHigh10:24:12Clipboard blocked32 charactersMed10:23:58Screenshot blockedfinance dashboardMed10:23:41USB access blockedSanDisk 32GBHigh10:23:10Print blockedQuarterly_Report.pdfMedView all logs
Endpoint outcomes

Nothing usableleavesthe session.

The controls are not a fence around the person — they are a boundary around the data. The work carries on; the copy of it does not.

Insider risk gets guardrails

The allowed user's unallowed action is blocked at the moment of attempt, and logged.

Third parties leave empty-handed

Vendors work in your systems; nothing usable leaves the session.

Compliance evidence by default

Every enforcement event is one of the 202 logged types — the audit trail writes itself.

FAQ

Endpoint controls, answered.

Tap a question — or open them all and read straight through.

Talk to us

//Ready when you are//

Ditch the VPN. Keep your apps invisible.

Runs alongside the VPN you have, app by app, until there is nothing left to switch off. Nothing to rack, no network to re-architect.

Regulated, air-gapped, or on-premise? See deployment options