Browser extension

Browser extension capabilities

Explore the visibility, investigation, and deployment capabilities provided by the elba browser extension.

Reviewed Jul 22, 2026 · Product

Overview

The elba browser extension provides browser-level context that complements data from your connected SaaS applications. Administrators can use that context to understand application usage, investigate relevant browser events, and manage the extension rollout from one workspace.

Available capabilities depend on the browser, operating system, deployment method, and Browser Security configuration selected for your organization. The Deployment Center in elba is the source of truth for the options currently available to your workspace.

Chrome, Edge, Firefox, and Safari 26 or later support application visibility, sensitive-data signals, browser logs, and enrollment reporting. Safari requires macOS 26 or later.

Application visibility

The extension can surface browser application usage in the unified Third-Party Apps inventory to help administrators understand which tools are being used across the organization. This is particularly useful when reviewing applications that have not yet been formally approved or connected to elba.

Browser usage is labeled Observed in the browser and remains attributed to its Browser Security source. It can be combined with connector-confirmed accounts, OAuth grants, and supporting email activity under one application without being converted into an account. Browser evidence is current for 30 days after its last observation; older evidence remains visible as Not recently detected.

When a high-confidence application does not yet match elba's automatically assessed catalog, it can appear as an organization-private provisional identity marked Identification in progress. The assessment is performed by elba's automated enrichment pipeline, not a manual human reviewer. Ambiguous items and signals classified as devices, operating systems, platform components, or general websites are kept out of the default application inventory.

Use this visibility alongside your application inventory and Third-party apps review process to decide which tools should be assessed, approved, or investigated further.

Sensitive-data signals in AI applications

For supported AI application workflows, the extension can identify relevant sensitive-data signals and report them to elba. It can also classify the observed AI account status as Work account, Personal account, No account signed in, or Unknown. Administrators can review those findings with the surrounding application and user information in the dashboard.

Browser Security reports only those four account statuses, and Browser Logs filters only those statuses. Work and personal accounts is not a status sent by the extension: the canonical inventory computes this combined status only when current work and personal evidence coexist for the same user and application. Browser Logs therefore does not offer a filter for it.

AI account status is an observation made in the browser, not a verified account. The detected email address and domain remain in the browser; application inventory and Browser Logs do not expose them, page content, tenant-specific hostnames, or full URLs.

This capability complements the controls described in Data protection. Coverage depends on the applications and Browser Security settings configured for your workspace.

Installed extension inventory

The extension can report information about browser extensions installed in a user's browser, including the extension name, installed version, enabled state, install type, and installed or uninstalled state.

This inventory helps security teams:

  • Discover extensions that warrant review.
  • Confirm whether an extension is installed and enabled and how it was installed.
  • Investigate changes in a user's browser environment.
  • Add browser-extension context to a broader employee risk review.

Installed-extension inventory is available on Chrome, Edge, and Firefox. Safari does not expose the browser extension-management API needed to enumerate other installed extensions. This limitation does not affect Safari enrollment status or the other Browser Security capabilities described on this page.

An automatically assessed extension identifier can be linked to its related application; an unknown extension remains private to your organization while its identification is in progress. Installation evidence is labeled Observed in the browser. It does not contribute OAuth permissions, risky-access exposure, SSO adoption, or account-remediation actions.

elba does not expose raw browser-extension identifiers, permission lists, or host-permission domains in the application inventory, public API, or Browser Logs. Browser Logs show the privacy-safe installation metadata listed above, while the Users tab shows the installation evidence and its current state in Detected users and accounts.

Safari also does not expose searchable browser download history to WebExtensions. Any control that specifically relies on a browser-download-history lookup is unavailable on Safari; AI prompt and attachment data controls continue to operate.

Browser logs and investigation

Relevant browser events are available in elba's browser logs. Administrators can filter the log, inspect event details, and use the associated user, application, or extension information during an investigation. Application-usage and AI-account-status observations do not expose detected account identifiers, page content, tenant-specific hostnames, or full URLs.

Browser logs are most useful when combined with information from connected integrations and the Employee risk profile, rather than treated as an isolated source.

Deployment and enrollment visibility

The deployment view helps administrators follow rollout progress across users. From this view, you can:

  • Search users and groups.
  • Filter users by extension status.
  • Send setup instructions or reminders to selected users.
  • Confirm that a user has completed extension enrollment.

On Safari, elba confirms enrollment using an authenticated extension heartbeat because Safari does not expose its installed-extension list. The heartbeat contains the signed-in user, workspace, Safari source, extension version, and last-seen timestamp; it does not include browsing content.

Safari's all-website permission is required for application visibility and supported Browser Security controls. It does not continuously upload complete pages or raw browsing history. Relevant findings use sanitized URLs without credentials, query strings, or fragments. When a configured control requires classification, the relevant prompt or a bounded file or page excerpt is sent through elba's authenticated classification service. The stored finding contains the result and necessary metadata rather than the raw prompt or file content.

For centralized and manual rollout options, see Deploy the browser extension.

Operational requirements

The extension must be installed, signed in, and connected to elba for network-backed capabilities to operate as expected. Browser and device policies can also affect installation, updates, or extension permissions.

When evaluating coverage:

  1. Verify the deployment policy on a representative device.
  2. Confirm that the user can sign in.
  3. Check that the device's extension status is reflected in elba.
  4. Validate the specific browser signals your organization intends to use.

Start with Browser extension for the product overview or continue to Deploy the browser extension for rollout guidance.

On this page