AI Agent Allowlist
Home Page-Types Database Agent Guardrails 2026 Incidents API Docs Pricing
Resources
Use Cases (15) Industries & Buyers (12) Learn: Core Concepts (12) Implementation Guides (15) Comparisons (8) Agent Security Guides (22) Market & Frameworks (9) Schema & Data Reference (6) FAQ Glossary
Why It Matters
2026 Agent Incidents Category Targeting Database Refreshes Contact Customer Login
Download Free Sample
the chat window now has hands, so the admin console needs rules

Agent Mode Allowlisting Guide

Chat assistants now offer an agent mode that browses sites, fills forms and connects to company apps. Admins need to decide what it may reach.

This guide covers the five settings to get right, where your own proxy helps and where it cannot, and how an AI agent allow list shapes the site list.

5Settings to decide
2Places it can run
8Action page types
40M+Domains classified
What it is

What agent mode does

In agent mode, a chat assistant stops only answering and starts doing. It plans steps, opens web pages, clicks, types and uses connected apps.

That makes it far more useful, and it moves the risk from what it says to what it does.

The user sees a summary. The actions happen on real sites and in real accounts.

Browses

Opens and reads web pages, often in a browser the vendor runs.

Acts

Fills forms, clicks buttons and can reach signup or checkout pages.

Connects

Uses company apps such as mail, files and calendars through connectors.

Where it runs

The question that decides your options

Before setting anything, find out where the agent's browser runs. It changes which controls you can use.

Ask the vendor in writing. Product pages rarely say it clearly.

Many agent modes run the browser in the vendor's cloud. That traffic never passes your network.

Browser in the vendor's cloud

  • Your proxy does not see the pages it opens
  • Control comes from the vendor's admin settings
  • Site lists are usually by domain
  • Confirmation prompts are set by the vendor

Browser on your device or network

  • Your egress proxy sees every page
  • Page-type checks work on every URL
  • Per-agent policy files apply
  • Admin settings still matter for connectors
Five settings

The five agent mode settings to decide

Names differ between products, but most admin consoles offer these five controls in some form.

If your product lacks one of them, record the gap and raise it at renewal.

Try the switches below to see what each one changes.

Agent mode settings (illustration)

1. Who may use agent mode

Everyone, selected groups, or nobody.

2. Which apps it may connect to

Mail, files, calendars, code and business apps.

3. Which sites it may open

An allowed or blocked list of domains.

4. What needs confirmation

Purchases, signups, sending and posting.

5. Logging and export

Records of actions for compliance tools.

All five controls are on. Click a switch to see what it changes.
The site list

Building a site list when you only get domains

Most admin consoles only accept domains. Nearly every domain has action pages as well as reading pages.

Page-type data tells you which of those domains carry the action pages to watch.

So a domain list decides where the agent may go. Confirmation settings must decide what it may do there.

28Page types
8Action page types
40M+Domains
2Controls working together
# using page-type data to shape a domain list step 1 list the domains your teams really need # from proxy logs or a survey step 2 look up which page types each domain has # reading pages, action pages step 3 allow domains that are mainly reading pages # docs, help centres, news step 4 for domains with checkout or signup pages # keep confirmation on, always step 5 review the list each quarter
By team

Suggested settings by team

Not every team needs the same agent mode. Start narrow, and widen where a real task needs it.

Adjust the table after the pilot, based on what teams really used.

Confirmation stays on for everyone.

TeamAgent modeConnectorsSites
Research and strategyOnFiles, read-onlyBroad reading list
MarketingOnFiles, calendarReading list plus own sites
SalesOnCalendar, CRM read-onlyReading list, no signups
Finance and procurementPilot onlyNone at firstNamed suppliers only
IT administratorsOff for admin accountsNoneNot applicable
ExecutivesPilot onlyMail and calendar, read-onlyReading list
Connectors

Allowlisting connectors safely

Connectors let agent mode read and write inside company apps. They often matter more than the website list.

Treat each connector as a separate risk decision, not a feature switch.

A page on the open web can steer an agent that also holds a mail connector.

1

Start with none

Turn connectors on one at a time, per group.

2

Prefer read-only

Reading mail is less risky than sending it.

3

Avoid browsing plus sending

An agent that reads the web and can send mail is an easy route for data to leave.

4

Review grants monthly

Remove connectors nobody used.

Your own network

Where your proxy still helps

Even when the agent's browser runs in the cloud, your network is not irrelevant. It still sees some important traffic.

It also shows how much agent use happens outside the approved workspace.

Where the browser runs on your side, it sees everything.

Access to the assistant

Allow only the approved workspace, not personal accounts.

Local browser agents

Agent modes that drive a browser on the device pass your proxy.

Page-type checks

On local traffic, action pages can be denied before they load.

Links users open

Pages the agent suggests and the user then opens are checked too.

Data loss rules

Uploads of company files to the assistant can be inspected.

Unapproved tools

Other agent tools show up in proxy logs.

Rollout

A six-week rollout

Agent mode is popular the day it appears. A short plan lets you say yes quickly without losing control.

A clear date for each team reduces pressure to switch it on early.

Tell users the plan on day one, so they wait for the approved route.

Week 1: decide

Find out where the browser runs, and which of the five settings your product offers.

Week 2: pilot group

Turn it on for one low-risk team with no connectors.

Weeks 3 to 4: site list and connectors

Build the domain list from pilot use, and add read-only connectors.

Weeks 5 to 6: widen

Add teams one at a time, with the settings from the table above.

Vendor questions

Questions to ask your assistant vendor

Ask before turning agent mode on for anyone. Keep the written answers with your risk register.

Vague answers to any of these are a finding in themselves.

The first three decide whether you can control it at all.

Where does the agent's browser run?

Your side, or the vendor's cloud.

Can admins limit sites?

By domain, by URL, or by page type.

Which actions need confirmation?

Can admins make more actions require it?

Can it use our egress proxy?

So our page-type checks apply to cloud browsing too.

What is logged and exported?

Pages, actions and confirmations, per user.

Can we switch it off per group?

Quickly, without affecting chat.

Mistakes

Common agent mode mistakes

These show up in many first rollouts. Each is easy to avoid once named.

Check your own rollout against the list before widening to new teams.

On for everyone on day one

No pilot, no site list, no plan.

Assuming the proxy sees it

Cloud browsing bypasses your network.

Confirmation turned off

To "reduce friction" for power users.

Write connectors by default

Sending mail and editing files from day one.

Domain list as the only control

Allowed domains still have checkout pages.

No log review

Exports that nobody reads.

Data controls

Data settings that go with agent mode

Agent mode reads pages and apps, then writes summaries and takes actions. Data settings decide what it may carry between them.

Many of these are set once for the whole workspace, so decide them before the pilot.

Check these alongside the five main settings.

Training on your data

Confirm in writing that business content is not used to train models.

Retention

How long pages, screenshots and actions are kept, and where.

Memory

Whether the agent remembers across sessions. Off for high-risk groups.

File uploads

Which company files users may give the agent.

Sharing

Whether agent results can be shared outside the workspace.

Region

Where the agent's browsing and data processing happen.

For users

Six rules to publish for agent mode users

Settings do most of the work. Plain rules help users with the rest.

Keep the list short enough to read in a minute.

Put them in the welcome message when agent mode is switched on.

1

Give narrow tasks

"Compare these three suppliers" rather than "sort out our suppliers".

2

Read every confirmation

Check the site, the amount and the action before saying yes.

3

Never share passwords with the agent

If a site needs a login, do that step yourself.

4

Do not paste confidential data

Unless the task and the data rules allow it.

5

Watch the first run of a new task

Stay with the agent until you trust the pattern.

6

Report surprises

Unexpected sites, forms or emails go to security.

Roles

Who owns agent mode settings

Agent mode sits in a collaboration tool, but its risks belong to security. Split the work clearly.

Record the owners in the agent registry.

SettingOwner
Who may use agent modeWorkspace admin with security
Connectors and their scopesApp owners
Site listNetwork security
Confirmation settingsSecurity
Data and retention settingsData protection
Log reviewSecurity operations
Objections

What people say, and how to answer

Agent mode rollouts meet the same few objections. Short answers keep things moving.

Most come down to one idea: reading is cheap to allow, acting needs a check.

"The vendor has already made it safe"

Vendor defaults are built for all customers. Your settings reflect your data, your teams and your risks.

"Confirmations annoy power users"

They only appear for purchases, signups, sending and posting. Those deserve a second look.

"A site list is too much work"

Start with the domains the pilot team really used. Page-type data speeds up the review.

"We will just block it"

Users then turn to personal accounts with no controls at all. A managed yes is safer.

Measuring it

Numbers to report each month

A few figures show whether agent mode is both useful and under control.

Watch the trend across months rather than any single figure.

Share them with the workspace owners as well as security.

Active agent mode users

By team, against the rollout plan.

Confirmations shown and declined

Declines show the control working.

Connectors in use

And how many are read-only.

Personal-account use

From proxy logs. It should fall as the approved route grows.

Terms

Words used in this guide

Short definitions for readers new to agent mode administration.

Product names for these settings differ, but the ideas are the same.

Agent mode

A chat assistant setting where it carries out tasks, not just answers.

Connector

A link that lets the agent read or write in a company app.

Confirmation

A prompt asking the user to approve an action before it happens.

Cloud browser

A browser the vendor runs for the agent, outside your network.

Page type

What a page is for, such as documentation, signup or checkout.

Action page

One of 8 page types where something happens, such as a purchase or post.

What the 2026 incidents mean for agent mode

  • Agents in the 2026 incidents reached paths nobody intended: login pages, plugin installs and dataset uploads.
  • In agent mode, confirmation settings and page-type checks are the controls for those paths.
  • In our replay, page data plus egress rules would have stopped almost all of the incidents.
Check which controls would have stopped each incident

The honest fine print — the same two assumptions we publish, plus two operational ones

  1. The policy engine must see every request — an agent with raw socket access or a second network path bypasses everything; enforcement belongs at the egress proxy/network layer, not only in an SDK hook.
  2. Default-deny must be on. In flag-only mode these become alerts within minutes rather than prevention — still a large improvement on a timeline measured in weeks (the DseWiki edits ran from late May to late June 2026, per the researchers), but not a block.
  3. For full URL+method matching on HTTPS you need to be the proxy or in-process hook — SNI alone shows only the host, which still catches the entire host-list layer.
  4. Policy can’t read intent inside a legitimately allowed action: an agent whose job is publishing packages keeps registry access. In our replay of the 2026 incidents, no crossing fits any plausible allowlist for the agents’ documented tasks.
Related

Keep reading

FAQ

Agent mode allowlisting questions

What is agent mode in a chat assistant?
A mode where the assistant plans steps and carries them out: opening web pages, filling forms, clicking and using connected apps.
Can my web proxy control agent mode?
Only if the agent's browser runs on your device or network. If it runs in the vendor's cloud, use the vendor's admin settings instead.
Which agent mode settings matter most?
Who may use it, which connectors it has, which sites it may open, which actions need confirmation, and logging.
Is a domain allowlist enough?
No. Most domains have checkout, signup or upload pages. Keep confirmation on for those actions, and use page-type checks where traffic passes your proxy.
Which teams should get agent mode first?
Low-risk teams such as research. Finance, procurement, admins and executives should come later, with narrower settings.
Should connectors be read-only?
At first, yes. Avoid giving one agent both web browsing and the ability to send mail or share files.
What should I ask the vendor?
Where the browser runs, how sites can be limited, which actions need confirmation, whether it can use your proxy, and what is logged.
Where does an AI agent allow list help with agent mode?
It shows which page types each domain has, to shape domain lists. Where traffic passes your proxy, it lets you deny action pages before they load.
What data settings go with agent mode?
Training on business data, retention, memory, file uploads, sharing outside the workspace and the processing region. Check each alongside the five main settings.
Who should own agent mode settings?
The workspace admin and security decide who may use it, app owners handle connectors, network security the site list, security the confirmations and data protection the retention settings.
What rules should users follow in agent mode?
Give narrow tasks, read every confirmation, never share passwords with the agent, avoid pasting confidential data, watch the first run and report surprises.
Should we block agent mode instead?
Blocking tends to push users to personal accounts with no controls. A managed rollout with confirmations on is usually safer.

Know what is behind every domain you allow

28 page types, including 8 action types, on 40M+ domains.

Download the sample