Skip to main content
The Runlayer browser extension brings AI Watch prompt monitoring, scanner decisions, and Sessions telemetry to supported AI web chats in Google Chrome and Mozilla Firefox. Both browsers report as the Browser extension client while Runlayer resolves the provider from the page URL.
Managed force installation is available for Chrome 120+ and Firefox 140+ on macOS through Jamf Pro, Intune for macOS, Iru/Kandji, SimpleMDM, Mosyle, Workspace ONE, and the generic macOS MDM flow. The browser extension is not installed by the Windows or Linux AI Watch packages.

What it does

For a supported web chat, the extension can:
  • capture submitted prompts and assistant responses
  • record web conversations in Sessions
  • send prompt input through your configured security scanners
  • mask sensitive prompt input before it reaches the provider
  • block a denied prompt before it reaches the provider
Assistant responses are captured after they render. Response scanner outcomes are therefore audit-only: the extension cannot remove or rewrite content that the provider has already displayed.

Deploy the extension

1

Confirm AI Watch 0.29.6 or newer

Open Settings → AI Watch and confirm the target devices run AI Watch 0.29.6 or newer. If they do not, update the AI Watch policy under Settings → Client updates and allow the managed updater to install the selected version before continuing.
2

Enable the browser extension

In Settings → AI Watch, find the existing deployment under Configurations, select Manage settings, and open the Browser extension tab. Turn on Install browser extension, then select Save changes.
3

Let AI Watch reconcile the browsers

The macOS bootstrap daemon reads the setting and installs the managed Chrome and Firefox policies during its next hourly reconcile. Restart each browser after the policy is applied. No change or redeployment of the existing MDM profile is required.
4

Enable browser hook processing

In Settings → Agent session monitoring, enable Full session scanning APIs and the Browser extension Hook client. Both are required for browser monitoring and prompt scanner decisions, including Mask and Block. The deployment’s Collect browser session data setting separately controls whether conversations are recorded in Sessions.
AI Watch uses the deployment’s existing tenant host and organization API key to configure both browsers. It force-installs Runlayer’s stable Chrome CRX and Mozilla-signed Firefox XPI, then keeps their managed settings synchronized with the deployment. Users do not need a Chrome or Firefox account. If AI Watch is not yet deployed, complete the macOS MDM deployment first. Existing deployments already running AI Watch 0.29.6 or newer only need the Runlayer setting above; do not edit or re-deploy com.runlayer.aiwatch.config.mobileconfig to enable the browsers. Managed configuration is read-only inside the extension. Users cannot override the tenant host, organization API key, mode, or Sessions setting from the extension options page.

Set up one browser manually

Use this flow for a test browser profile or one-off validation. For a fleet rollout, use the managed deployment above so installation, configuration, and updates remain enforced.
Manual configuration stores a personal API key in the browser profile, and Runlayer attributes its activity to that key’s owner. Use a dedicated test profile on a trusted device, not a shared browser profile.
1

Download the selected browser package

In Settings → Client updates, open Browser extension, select and save the version policy you want to test, then download the package for the browser:
  • Chrome: runlayer-aiwatch-browser-extension-<version>.crx
  • Firefox: runlayer-aiwatch-browser-extension-firefox-<version>.xpi
2

Install the package

Chrome supports direct installation of a self-hosted CRX only on Linux. Open chrome://extensions, turn on Developer mode, drag the downloaded .crx onto the page, and approve the installation.Chrome on macOS and Windows requires an enterprise policy for a self-hosted CRX. Use the managed deployment instead of attempting to sideload the downloaded file on those platforms.
3

Configure the extension

Open Runlayer AI Watch → Manage extension → Extension options. Enter your Runlayer tenant URL as Backend host. In Settings → Personal API keys, create a personal API key for the user running the test, then enter it as API key. Leave prompt-input scanner actions off for Monitor, or enable them for Enforce. Select Save, then Test connection.A personal API key attributes activity directly to its owner, so a manual installation does not need the AI Watch native identity host. If the connection test reports Device identity unresolved, replace the organization API key with a personal API key and retry.
4

Enable browser hook processing

In Settings → Agent session monitoring, enable Full session scanning APIs and the Browser extension Hook client. Both are required for browser monitoring and prompt scanner decisions.

Configure browser mode and Sessions

Open Settings → AI Watch (/settings/ai-watch). Under Configurations, select Manage settings for the deployment, then choose the Browser extension tab. By default, the browser extension inherits the deployment’s AI Watch mode and Sessions setting. Turn on Use independent protection mode only when browser traffic needs a different mode or Sessions setting from local AI clients. Protect and Enforce are distinct endpoint modes for local client hooks, but they intentionally share the same scanner-driven prompt behavior in the browser. Endpoint MCP-source allowlists, denylists, and local file/shell policy do not apply to web-chat page requests. Turning off Collect browser session data suppresses browser lifecycle and transcript events. Prompt scanner checks remain active in Protect and Enforce as long as Full session scanning APIs and the Browser extension Hook client remain enabled.

Supported web pages

Status labels:
  • ✅ Supported — validated prompt, response, and Sessions behavior for the current release
  • Monitor only — capture is supported, but the page has no safe pre-send rewrite and cannot Mask or Block
  • — intentionally unsupported for that page

Prompt protection and Sessions

These pages have a precise provider adapter and support prompt-input Mask and Block before provider send.

Observation-only pages

These pages support monitoring and Sessions, but cannot safely rewrite or stop the provider request.
The extension may be present on other HTTPS pages, but that does not make those pages supported. Unknown pages do not capture conversations and cannot enforce prompt decisions.

Scanner outcomes

Scanner actions are configured under Settings → Security Scanners. Per-client overrides for Web Browser take precedence over the global scanner action. The provider UI may display its own generic network or retry error when a request is blocked. Use the corresponding security finding in Incidents or Audit Logs as the policy evidence. When browser Sessions is enabled, the session’s Blocked status provides additional evidence.

Verify a deployment

  1. Confirm the device runs AI Watch 0.29.6 or newer.
  2. In Chrome, open chrome://extensions and confirm the Runlayer extension appears as managed.
  3. In Firefox, open about:policies, confirm the Runlayer extension policy is active, then open about:addons and confirm the extension is installed. A Firefox account is not required.
  4. Open the extension popup in either browser and confirm the expected Monitor, Protect, or Enforce badge.
  5. Confirm Full session scanning APIs is enabled and Browser extension is enabled under Settings → Agent session monitoring → Hook clients.
  6. On a response-capable supported page, submit a harmless unique prompt and confirm its prompt and response appear in Sessions. For NotebookLM, verify the prompt and session lifecycle only because response capture is intentionally unsupported.
  7. Test Mask or Block only with a dedicated test organization and a pre-approved scanner test value. Confirm the provider receives the masked value or does not receive the blocked prompt.

Troubleshooting

Confirm Collect browser session data is enabled, Full session scanning APIs is on, and the Browser extension Hook client is enabled. Restart Chrome or Firefox after the first managed deployment or a policy change.
Confirm the page is listed under Prompt protection and Sessions, the browser mode is Protect or Enforce, and the relevant scanner action or Web Browser override is Mask or Block. Observation-only pages never modify the provider request.
Some providers surface a generic network, retry, or send error when the extension stops their request. Confirm the security finding in Incidents or Audit Logs. When browser Sessions is enabled, also confirm the corresponding session is marked Blocked.

Deploy AI Watch

Create the MDM deployment that force-installs and configures the extension

Sessions

Review captured browser prompts, responses, and scanner outcomes

Endpoint modes

Understand Monitor, Protect, and Enforce across local clients

Security scanners

Configure scanner actions and per-client overrides