Skip to main content
The Runlayer browser extension brings AI Watch prompt monitoring, scanner decisions, and Sessions telemetry to supported AI web chats in Google Chrome. It reports as the Browser extension client while Runlayer resolves the provider from the page URL.
Managed force installation is currently available for Chrome on macOS through Jamf Pro, Intune for macOS, Iru/Kandji, SimpleMDM, Mosyle, and the generic macOS MDM flow. The browser extension is not installed by the Windows or Linux AI Watch packages.

What it does

For a supported web chat, the extension can:
  • capture submitted prompts and assistant responses
  • record web conversations in Sessions
  • send prompt input through your configured security scanners
  • mask sensitive prompt input before it reaches the provider
  • block a denied prompt before it reaches the provider
Assistant responses are captured after they render. Response scanner outcomes are therefore audit-only: the extension cannot remove or rewrite content that the provider has already displayed.

Deploy the extension

1

Create a macOS deployment

Open Settings → MDM configuration and create a new deployment for a supported macOS MDM.
2

Enable the browser extension

Turn on Install browser extension. Runlayer adds the stable extension ID and Runlayer-hosted update manifest to the generated managed configuration.
3

Deploy the generated artifacts

Follow the guide for your MDM. The AI Watch package installs Chrome’s force-install policy and mirrors the tenant host, organization API key, browser mode, and browser Sessions setting into Chrome managed storage.
4

Enable browser hook processing

In Settings → Agent session monitoring, enable Full session scanning APIs and the Browser extension Hook client. Both are required for browser monitoring and prompt scanner decisions, including Mask and Block. The deployment’s Collect browser session data setting separately controls whether conversations are recorded in Sessions.
Browser extension installation is selected when a deployment is created. If an existing deployment was created without it, create and deploy a new configuration with Install browser extension enabled. Managed configuration is read-only inside the extension. Users cannot override the tenant host, organization API key, mode, or Sessions setting from the extension options page.

Configure browser mode and Sessions

Open Settings → AI Watch (/settings/ai-watch). Under Configurations, select Manage settings for the deployment, then choose the Browser extension tab. By default, the browser extension inherits the deployment’s AI Watch mode and Sessions setting. Turn on Use independent protection mode only when browser traffic needs a different mode or Sessions setting from local AI clients. Protect and Enforce are distinct endpoint modes for local client hooks, but they intentionally share the same scanner-driven prompt behavior in the browser. Endpoint MCP-source allowlists, denylists, and local file/shell policy do not apply to web-chat page requests. Turning off Collect browser session data suppresses browser lifecycle and transcript events. Prompt scanner checks remain active in Protect and Enforce as long as Full session scanning APIs and the Browser extension Hook client remain enabled.

Supported web pages

Status labels:
  • ✅ Supported — validated prompt, response, and Sessions behavior for the current release
  • Monitor only — capture is supported, but the page has no safe pre-send rewrite and cannot Mask or Block
  • — intentionally unsupported for that page

Prompt protection and Sessions

These pages have a precise provider adapter and support prompt-input Mask and Block before provider send.

Observation-only pages

These pages support monitoring and Sessions, but cannot safely rewrite or stop the provider request.
The extension may be present on other HTTPS pages, but that does not make those pages supported. Unknown pages do not capture conversations and cannot enforce prompt decisions.

Scanner outcomes

Scanner actions are configured under Settings → Security Scanners. Per-client overrides for Web Browser take precedence over the global scanner action. The provider UI may display its own generic network or retry error when a request is blocked. Use the corresponding security finding in Incidents or Audit Logs as the policy evidence. When browser Sessions is enabled, the session’s Blocked status provides additional evidence.

Verify a deployment

  1. Confirm the extension appears as managed in chrome://extensions.
  2. Open the extension popup and confirm the expected Monitor, Protect, or Enforce badge.
  3. Confirm Full session scanning APIs is enabled and Browser extension is enabled under Settings → Agent session monitoring → Hook clients.
  4. On a response-capable supported page, submit a harmless unique prompt and confirm its prompt and response appear in Sessions. For NotebookLM, verify the prompt and session lifecycle only because response capture is intentionally unsupported.
  5. Test Mask or Block only with a dedicated test organization and a pre-approved scanner test value. Confirm the provider receives the masked value or does not receive the blocked prompt.

Troubleshooting

Confirm Collect browser session data is enabled, Full session scanning APIs is on, and the Browser extension Hook client is enabled. Restart Chrome after the first managed deployment or a policy change.
Confirm the page is listed under Prompt protection and Sessions, the browser mode is Protect or Enforce, and the relevant scanner action or Web Browser override is Mask or Block. Observation-only pages never modify the provider request.
Some providers surface a generic network, retry, or send error when the extension stops their request. Confirm the security finding in Incidents or Audit Logs. When browser Sessions is enabled, also confirm the corresponding session is marked Blocked.

Deploy AI Watch

Create the MDM deployment that force-installs and configures the extension

Sessions

Review captured browser prompts, responses, and scanner outcomes

Endpoint modes

Understand Monitor, Protect, and Enforce across local clients

Security scanners

Configure scanner actions and per-client overrides