A policy is set by an owner or admin under Organization → Policies and applies to every member. Members' clients pick it up automatically — at start and live when it changes — and show anything locked as “Managed by <your organization>”.
The settings
| Setting | Options | Effect |
|---|---|---|
| Locked setting packs | Choose one or more packs | The pack's settings are applied to every member and shown read-only in their dashboard and extension. Members can still change anything outside the pack. |
| Require browser extension | On / off | Members without the extension are counted as unprotected on the overview and see a nudge on their own dashboard. |
| Require mobile app | On / off | Same as above for the Android / iOS app. |
| Work mailbox | None / optional / required | None hides mailbox connection from members. Optional lets them connect a work Gmail or Outlook. Required counts unconnected members as unprotected. Mailbox access is always read-only and always with the member's own consent. |
| If a member removes OKY | Allowed / warn / block | Allowed does nothing beyond showing the member as uncovered. Warn (default) records the removal in your audit log, notifies admins and asks the member to reinstall. Block also withholds that member's OKY dashboard until an install reports back — owners and admins are never blocked, and it needs Require browser extension to be on. See Deployment for the part that actually prevents removal. |
| Protection layers | Read-only | Which layers your plan includes — link protection, email scanning, crypto detector, prompt-injection shield, attestation warning. Members are offered only the layers you have, and their extension counts them accordingly. Talk to us to change what's included. |
| Allow work e-mail code as fallback | On / off (only when SSO is configured) | Keeps the code-by-e-mail sign-in available next to SSO — useful while rolling SSO out or as break-glass if your identity provider is down. Recommended: off once SSO is verified working. |
| Admins can see member threats | On (default) / off | When off, admins see only counts on the overview, not the per-member threat list. |
| Join policy | Invite only / auto-join by verified domain | Whether anyone on a verified domain becomes an employee on first sign-in. Needs at least one verified domain; see Inviting people. |
What a member sees
- An organization badge and the organization name in the header.
- Locked settings rendered disabled with the label “Managed by <organization>”.
- If a required client is missing: a clear notice with the install link.
- Under Settings → Connected accounts: the mailbox option hidden, offered or marked required, according to your policy.
- Only the protection layers your plan includes — an organization without email scanning sees “4 of 4 layers”, never a layer it cannot switch on.
Nothing else about the member's dashboard changes — their scans, history and personal preferences remain theirs.
How coverage is counted
The overview shows coverage as members meeting the policy ÷ seats in use, broken down by extension, mobile app and mailbox. A member is protected when every client you marked as required is present and signed in. Turning a requirement off removes it from the calculation immediately.
Versions and audit
Every policy save creates a new version; the audit log records who changed what and when. Clients switch to the new version within seconds when online, or the next time they start.
Recommended starting policy
- Require the browser extension. It is where most protection lands.
- Work mailbox optional during the pilot, required once people trust the verdicts.
- One locked pack that sets your baseline; leave the rest to the individual.
- Fallback sign-in on until SSO has passed Test login for two admins, then off.