Dlp Suite

Enter the admin password to view the dashboard.

DLP Central Dashboard

Weekly per-staffer summary and Tier 1 alerts — not a raw log viewer. Raw events are available below for active investigations only.
not yet loaded

Data retention

Events, alerts, and errors older than this many days are purged automatically once a day. Change it here to override the default without editing config files or restarting anything.

Tier 1 alerts

WhenStaffReasonRelated events

Weekly digest — per staffer, per module

StaffMachineModuleThis weekTheir own 4-week average

USB devices

To approve a device, plug it into the staff PC and run Dlp.UsbGuard.Cli.exe list-devices there to read its Hardware ID and Serial Number, then enter them below. Staff PCs pick up changes here automatically within a couple of minutes (no need to touch the machine again).

Recently blocked (not yet approved)

WhenMachineHardware ID

Approve a device

All devices

MachineLabelHardware IDSerialStatusUpdated

Known client account names

ContentGuard matches clipboard copies against this list, in addition to email/phone patterns. Add every client account name here — all staff PCs pick up the change within a few minutes, no per-machine file editing needed.

Add multiple at once

Paste a list, one name per line (or separated by commas). Duplicates and blank lines are skipped automatically.

All account names

NameAdded

Paste destination risk rules

Classifies where flagged content gets pasted (ContentGuard's paste tracking). WhatsApp and webmail/browser compose windows are typically Risky; internal ticketing/approved tools are Allowed. This is logging only for now — pastes are never blocked.

LabelPatternRisk

Connected staff PCs

Each installed component checks in with the server about once a minute. Use this to verify a fresh install is actually talking to the server — no need to wait for a USB/content/screenshot event to happen first. "Offline" means that component hasn't checked in for a few minutes (service stopped, PC off, or a network/firewall issue).

MachineStaff nameUSB GuardContent GuardScreenshot Guard

Machines & USB enforcement

USB blocking: turning this ON tells that machine's USB Guard service to actively block non-whitelisted USB storage (within its next poll, a couple of minutes). Turning it OFF removes the block.
OCR scanning: turning this ON runs OCR on that machine's image file attachments (screenshots, photos of documents), fully offline, nothing sent to a third-party service. Defaults to off, and is per-machine on purpose — turn it off for any one machine whose hardware it turns out to bother, without affecting the rest of the fleet.
Content Guard: the master switch for all clipboard/paste/file-attachment scanning on that machine. Defaults ON (unlike OCR) — turning it OFF is a temporary, dashboard-driven way to pause monitoring for a legitimate task (e.g. an admin editing this server's own config, which contains real email addresses) instead of killing the agent process by hand.
A machine that hasn't reported any event yet won't appear here — it needs to check in at least once first.

MachineStaff nameUSB blocking enforcedOCR scanningContent GuardLast changed
Audit log Every admin action taken from this dashboard
WhenActionDetail
Error log Runtime errors from all components, in one place for debugging

Every component (USB Guard, Content Guard, Screenshot Guard, and this server itself) reports unhandled runtime errors here — no more hunting through separate log files on 15 different machines.

WhenComponentMachineStaffMessage
Investigation lookup Tier 3 raw events — only pull this when actively investigating someone
TimeStaffMachineModuleTypeDetailWindow