Browser extension

Browser extension

Learn how the elba browser extension adds browser-level security visibility to your workspace.

Reviewed Jul 22, 2026 · Product

Overview

The elba browser extension brings browser activity into the same workspace where your team manages SaaS security, employee risk, and automated security workflows. It gives administrators an additional source of context for understanding application usage, reviewing browser security signals, and following extension deployment across the organization.

The extension is designed for managed organizational use. After it is deployed, each user signs in to connect their browser session to the correct elba workspace.

elba supports Chrome, Edge, Firefox, and Safari. Safari support requires macOS 26 or later with Safari 26 or later. The signed Elba host app installs and registers the Safari extension; it does not own the user's authentication session. The user opens the extension in Safari and selects Sign in. Authentication then completes in a dedicated Safari tab using PKCE, and the extension becomes active after the secure callback succeeds.

Safari production deployments must be MDM-managed so every signed host-app update is deployed. Manual Safari installation is reserved for pilot validation because the host app does not auto-update.

What the extension adds to elba

Depending on the browser security features configured for your workspace, the extension can help you:

  • Add observed web-application usage to the unified Third-Party Apps inventory, including previously unknown applications.
  • Surface sensitive-data signals in supported AI application workflows.
  • Inventory installed browser extensions with installation metadata such as name, version, enabled state, install type, and installed or uninstalled state.
  • Review relevant browser activity in elba's browser logs.
  • Track extension enrollment and deployment status by user.
  • Notify selected users when they still need to install the extension or complete sign-in.

Safari provides the same application visibility, AI prompt and attachment data controls, browser logging, and enrollment reporting as the other supported browsers. Safari does not expose APIs for listing every installed extension or searching browser download history. Installed-extension inventory and download-history-based exfiltration checks are therefore not available on Safari.

Application usage, AI account status, and installed-extension evidence remain observations from the browser. They do not confirm an application account, OAuth permission exposure, SSO-adoption input, or revoke action. Browser evidence is considered current for 30 days after it was last observed; older observations remain visible as Not recently detected in Third-Party Apps.

Safari website access and data handling

Safari must allow the extension on all websites so it can identify the business applications in use and apply Browser Security controls when a supported workflow occurs. This permission does not cause elba to continuously upload complete pages or raw browsing history. The extension sends the authenticated enrollment heartbeat, privacy-safe application observations, and defined security findings needed by Browser Security. A relevant security finding can include application or domain context and a sanitized URL whose credentials, query string, and fragment have been removed. Application-inventory observations do not expose full URLs or tenant-specific hostnames. Account email addresses and domains observed inside supported AI tools remain in the browser; Browser Security reports only the classified AI account status: Work account, Personal account, No account signed in, or Unknown. The canonical inventory displays Work and personal accounts only when current work and personal observations coexist for the same user and application; Browser Logs does not report or filter by this combined status.

For installed extensions, elba exposes installation metadata rather than the extension's raw identifier, permission list, or host-permission domains. That installation facet is kept separate from OAuth permissions and access-exposure scoring.

For controls that require classification, the relevant prompt or a bounded file or page excerpt is sent through elba's authenticated classification service. The stored security finding contains the classification result, a cryptographic hash, and the necessary file, application, and user metadata rather than the raw prompt or file content. Administrators should validate the configured controls and explain this scope to their pilot group before broad deployment.

For a closer look at the available signals and administrative views, see Browser extension capabilities.

How it works

  1. An administrator activates and configures Browser Security in elba.
  2. The extension is distributed through an available enterprise deployment method or shared with users for manual installation.
  3. Users sign in to associate the extension with their elba account and workspace.
  4. The extension receives the workspace's browser security configuration and reports relevant security signals to elba.
  5. Administrators review activity, deployment status, and follow-up actions from the elba dashboard.

The extension needs a valid signed-in session and a working connection to elba for network-backed features. If that connection is temporarily unavailable, the extension displays its connection state so the user knows that attention may be required.

Plan your rollout

Before deploying broadly:

  1. Choose a small representative group of users and devices.
  2. Select the deployment method that matches how those browsers are managed.
  3. Confirm that users can install or receive the extension and sign in successfully.
  4. Check that extension status and expected browser activity appear in elba.
  5. Expand the assigned group after validating the pilot.

The elba Deployment Center provides the current values and downloadable artifacts for each supported method. Follow Deploy the browser extension rather than reusing values from an older rollout.

Next steps

On this page