Browser extension
The browser is where most workforce AI use happens: an employee opens ChatGPT, pastes a customer record, and asks for a summary. The browser collector makes that interaction visible and governable from inside the browser, where the page content is already plaintext, so it does not depend on opening TLS at the host.
It is a WebExtension (Manifest V3) for Chrome and Edge 120 or newer (supported browsers), published on the Chrome Web Store. For the governed control it is force-installed by browser policy, so an ordinary user cannot remove or disable it (how it is deployed). It talks to the endpoint agent over Native Messaging, so every verdict comes from the same local engine and policy as every other collector on the machine.
The collector captures ChatGPT, Claude, Perplexity and Gemini today; Gemini is new and in preview until a run through the endpoint agent on a live account confirms it end to end (see Known limits). Other AI sites (Microsoft Copilot, Poe and the rest) are only discovered: the endpoint's inventory records that they were used, and nothing typed into them is captured or enforced. Every one of these sites, captured or not, appears in the endpoint's AI inventory as Seen in browser once it is opened. Pre-send Block and Redact are available on all four, wherever the policy promotes a rule to them; the built-in Local default only logs. Response capture and response-side enforcement are best-effort, as described below, and on Gemini replies are recorded only, never blocked or redacted.
Supported browsers
| Browser | Status |
|---|---|
| Google Chrome 120 or newer | Supported |
| Microsoft Edge 120 or newer | Supported |
| Chromium 120 or newer | Same engine and build as Chrome |
| Brave | Not supported yet. No native-messaging host is registered for Brave, so the extension cannot reach the agent there |
| Firefox | Later track. No signed build ships yet |
| Safari | Not planned. Its extensions ship inside a notarized app through the App Store |
Version 120 is the minimum_chrome_version in the extension's manifest; an
older browser refuses to install it.
What it captures
On the AI-provider sites it covers, per interaction:
- The prompt: the full message the user sends, including pasted and typed
text. On Claude, long pasted text and text files the site reads in the page
are sent as attachments rather than in the message, and they are inspected
with it, even when the message itself is empty. The inspected text marks
each attachment with a separator line (
--- attachment 1: server.log ---), so a logged or redacted interaction's stored text shows which attachment a match is in; a blocked interaction stores no text. Files uploaded to the provider, such as documents and images, are not inspected: their content is not in the request. - The response: the model's reply, reconstructed from the streamed feed. This is best-effort today: a provider can change how it streams without notice, and a reply that is not reassembled is simply not recorded. Capture of replies has not been confirmed on every provider yet; see Known limits.
- Metadata: the provider, the API address the page called (on Gemini without its session query string), the conversation id and the model when the request names them, and the machine and operating-system user the agent supplies. Gemini's request names neither a conversation nor a model; the conversation id is taken from its reply and recorded on the response only.
It does not identify which provider account is signed in, so it cannot tell a personal ChatGPT account from a corporate one today.
Capture is allowlist-only: the extension runs only on the AI-provider domains it is configured for. It has no visibility into general browsing (banking, webmail, internal apps) by construction.
What it enforces
Every interaction is evaluated against your policy, and the applied action is recorded with it:
- Log: record the interaction, change nothing.
- Redact: mask the matched text (a credential, a customer record) before the request leaves the browser, so the raw value never reaches the provider.
- Block: stop the request before it is sent and show the user an in-page notice explaining why, with a reference they can quote to your security team.
Blocking and redacting a prompt before it is sent is authoritative: the request never reaches the AI provider. Acting on the model's reply as it streams is best-effort by nature, because text already on screen cannot be recalled, so it holds a short tail of the answer back to cut a developing leak before it paints.
Gemini sends its prompt a different way from the other three sites (an
XMLHttpRequest rather than fetch), and the extension holds it for the same
verdict, within the same time limits. A blocked Gemini prompt is not sent: the
page sees its request refused, and behind the notice Gemini removes the
unanswered turn and puts the prompt back into the input box, so the person
can edit it and send again. A redacted prompt reaches Gemini with the matched
text masked, and Gemini answers the masked text. Both were checked on the live
gemini.google.com page, with the capture code loaded into the page directly;
the same run through the installed extension and the endpoint agent is still
pending (see Known limits). Gemini's reply cannot be rewritten
in the page, so it is recorded but never blocked or redacted, whatever the
settings below say.
Response-side enforcement is off by default, and a policy rule on responses
does not turn it on by itself. It is switched on per browser, by the
enforce_output key of the extension's managed configuration, which only an
administrator can set. See
Enforce on responses. With
it off, responses are still captured and logged where capture works.
How it is deployed
The extension is published on the Chrome Web Store as
Lumen Browser Collector,
extension ID pnbjfklmbahlondakkdjaffkmimofmni. There are three ways to put it
in a browser, listed from the one to try first. Whichever you use, the
endpoint agent must be installed on the same
machine and its native-messaging host must allow the extension's ID, or the
extension has nothing to ask for a verdict and captures nothing (see
The agent and the extension ID).
From the Chrome Web Store
Open the listing
and choose Add to Chrome. Edge installs it from the same page once
Allow extensions from other stores is turned on at edge://extensions. The
store keeps it updated. An agent put there by the one-line installer is already
registered for the store listing's ID, so the extension reaches it at once; an
agent installed any other way needs the step in
The agent and the extension ID, or the
extension captures nothing. A copy someone installs this way is theirs to disable or
remove, so it suits an evaluation or a personal machine; it is not the enforced
control.
Force-installed by policy
The enforced control: browser policy installs the extension and locks it in
place. The policy entry for the store listing, in ExtensionInstallForcelist, is:
pnbjfklmbahlondakkdjaffkmimofmni;https://clients2.google.com/service/update2/crx
Whether a browser honours a force-install depends on where the extension is hosted and on whether the machine is managed. For Chrome that means joined to a domain, enrolled in an MDM, or enrolled in Chrome Browser Cloud Management; for Edge, joined to an Active Directory domain on Windows, or MDM-managed on macOS.
| Force-install of | Managed machine | Unmanaged Windows or macOS machine |
|---|---|---|
| The Chrome Web Store listing, in Chrome | Yes | Yes. Chrome force-installs an extension from its own store on any machine. On macOS the policy still arrives as a configuration profile |
| The Chrome Web Store listing, in Edge | Yes | No. Outside an Active Directory domain on Windows, and without an MDM on macOS, Edge force-installs only from Microsoft's Edge Add-ons store |
The self-hosted package from dl.lumen.wazuh.com, in Chrome or Edge | Yes | No. Chrome rejects it: there it force-installs an extension from outside its store only on a managed machine |
The policy arrives two ways:
- Your MDM / GPO. Intune, Jamf, Group Policy or Chrome/Edge cloud management push the force-install list centrally. On macOS this is the only way: the policy must come from a configuration profile.
- The agent installer. On Windows and Linux, which are preview platforms today, the one-liner also writes the force-install policy for the store listing above. Chrome honours it on any machine, managed or not; Edge on Windows only on a machine joined to an Active Directory domain. On macOS the installer writes no policy, because Chrome and Edge read it there only from a configuration profile. A fleet that cannot reach the store can point the installer at the self-hosted package instead, which takes effect on managed browsers only (see Deploy on managed browsers). What else it does on each platform is in What the installer does, per platform.
The one-line installer also registers the agent for the store listing's ID, so a store copy installed by policy or by hand reaches the agent on a machine it set up (The agent and the extension ID).
Because the policy lives in an admin-only location, removing the collector takes the same privilege as removing the agent; a standard user can do neither. For the step-by-step force-install per browser and OS (GPO/registry, MDM configuration profile, Linux managed policy), see Deploy on managed browsers. Traffic from browsers you cannot reach at all is covered by the gateway collectors instead, which is an honest limit of any in-browser sensor.
Loaded unpacked, for development
A build from source (npm run build in the repository's extension/
directory) carries the store listing's public key, so a copy loaded unpacked in
developer mode gets the same ID as the store listing,
pnbjfklmbahlondakkdjaffkmimofmni, on every machine. The packages Lumen
publishes, the store upload and the self-hosted package, never carry that key:
the store refuses an upload with one. A browser holds one extension per ID, so
remove a store copy before loading an unpacked build. Loading a copy yourself on
a browser you do not manage is covered in
Install on an unmanaged browser.
The agent and the extension ID
The agent's native-messaging host answers only the extension IDs it was
registered for. The one-line installer registers it machine-wide, for every
user of the machine, and for both builds Lumen publishes: the store listing's
ID, pnbjfklmbahlondakkdjaffkmimofmni, and the self-hosted package's,
ocnmngannfenghhgdobcgiohodgafmlo. On Windows it writes the registry keys
Chrome and Edge look up itself, under HKLM; there is no reg add to run.
Where the host lands on each platform is in
Install on an unmanaged browser.
An endpoint set up by an installer from v2.9.0 or earlier registered the self-hosted ID only (on Windows, nothing), and an agent self-upgrade does not change that: re-run the one-line installer on it. On an agent installed any other way, or for a build with another ID, register the host yourself, as the person who uses the browser:
lumen-agent browser dev-install
With no --id it registers the store listing's ID, and it always includes both
published IDs; pass --id to add another.
Where it shows up
Browser findings flow through the local agent to the console like every other collector's, tagged as coming from the browser. They appear under the machine's endpoint, because the browser rides the agent's device enrollment rather than being a separate endpoint, and in Interactions alongside the rest of that machine's AI activity.
Known limits
- Response capture is best-effort and not yet confirmed live on every provider. Treat a missing reply as unknown, not as clean.
- Gemini capture has not yet been confirmed end to end on a live account. It is built and tested against Gemini's request and reply formats as recorded from a signed-in account on 2026-09-25, and on 2026-09-26 its redact and block were verified against the live gemini.google.com page: a redacted prompt was accepted and answered with the masked text, the reply was captured, and a blocked prompt was never sent and returned to the input box. That check loaded the capture code into the page directly, with a stand-in for the agent's verdict. A run with the extension installed, through the endpoint agent and into the console, is still pending. Until it is, treat Gemini capture and enforcement as preview: a missing Gemini record is unknown, not clean.
- Gemini replies are log-only. Response-side Block and Redact do not apply to Gemini; its prompts are enforced before they are sent like everywhere else.
- An unreadable request fails open. If a provider sends a request body the adapter cannot parse, for example one compressed in a format the browser cannot decompress (Brotli, zstd), the prompt goes out uninspected and nothing is recorded. gzip and deflate bodies, which claude.ai sends on some accounts, are decompressed and inspected.
- A very large prompt is blocked, not redacted. The agent answers the browser in one message of at most 1 MB, and a redact answer carries the whole masked prompt. When a pasted text of around 1 MB or more matches a Redact rule, the agent blocks the prompt instead and records it as blocked, with Redact as the policy's intended action. Agents up to v2.7.0 let such a prompt go out unmasked while its finding still recorded the Redact verdict, so upgrade the agent along with the extension. A Block rule applies at any size.
- A verdict that arrives late is not applied, and the record says so. The extension holds a prompt while it waits for the agent's verdict: up to 5 seconds for a page's first prompt, while the agent's browser host may still be starting, and up to 1.5 seconds after that. Past the hold it sends the prompt unchanged rather than stall the page. A Block or Redact that reaches the page after that is reported back as not applied, and the console shows the record as Log with a Block not applied badge, never as blocked. The extension starts the agent's host as soon as the first AI site loads, before anything is typed there, so a late verdict should be rare. See A block the browser did not apply.
- Tabs opened before the extension was enabled or updated are not protected until they are reloaded.
- The signed-in provider account is not captured, so approved and unapproved accounts cannot be told apart yet.
Privacy
The extension holds no detection, persistence or transport logic of its own: it captures on the allowlisted sites, applies the verdict the agent returns, and lets the agent record and ship it. Redaction happens at source, before the data leaves the browser, and a blocked prompt's content is never stored. See data handling for the full boundary.