Weekly per-staffer summary and Tier 1 alerts — not a raw log viewer. Raw events are available below for active investigations only.
not yet loaded
Data retention
Events, alerts, and errors older than this many days are purged automatically once a
day. Change it here to override the default without editing config files or
restarting anything.
Tier 1 alerts
When
Staff
Reason
Related events
No Tier 1 alerts. Quiet week.
Weekly digest — per staffer, per module
Staff
Machine
Module
This week
Their own 4-week average
No activity in the last 7 days.
USB devices
To approve a device, plug it into the staff PC and run
Dlp.UsbGuard.Cli.exe list-devices there to read its Hardware ID and
Serial Number, then enter them below. Staff PCs pick up changes here automatically
within a couple of minutes (no need to touch the machine again).
Recently blocked (not yet approved)
When
Machine
Hardware ID
No recent blocked-device events.
Approve a device
All devices
Machine
Label
Hardware ID
Serial
Status
Updated
No devices approved yet.
Known client account names
ContentGuard matches clipboard copies against this list, in addition to email/phone
patterns. Add every client account name here — all staff PCs pick up the change
within a few minutes, no per-machine file editing needed.
Add multiple at once
Paste a list, one name per line (or separated by commas). Duplicates and blank
lines are skipped automatically.
All account names
Name
Added
No account names added yet.
Paste destination risk rules
Classifies where flagged content gets pasted (ContentGuard's paste tracking). WhatsApp
and webmail/browser compose windows are typically Risky; internal ticketing/approved
tools are Allowed. This is logging only for now — pastes are never blocked.
Label
Pattern
Risk
No destination risk rules configured yet.
Connected staff PCs
Each installed component checks in with the server about once a minute. Use this to
verify a fresh install is actually talking to the server — no need to wait for a
USB/content/screenshot event to happen first. "Offline" means that component hasn't
checked in for a few minutes (service stopped, PC off, or a network/firewall issue).
Machine
Staff name
USB Guard
Content Guard
Screenshot Guard
No staff PCs have checked in yet.
Machines & USB enforcement
USB blocking: turning this ON tells that machine's USB Guard service to actively
block non-whitelisted USB storage (within its next poll, a couple of minutes).
Turning it OFF removes the block.
OCR scanning: turning this ON runs OCR on that machine's image file attachments
(screenshots, photos of documents), fully offline, nothing sent to a third-party
service. Defaults to off, and is per-machine on purpose — turn it off for any one
machine whose hardware it turns out to bother, without affecting the rest of the
fleet.
Content Guard: the master switch for all clipboard/paste/file-attachment scanning
on that machine. Defaults ON (unlike OCR) — turning it OFF is a temporary,
dashboard-driven way to pause monitoring for a legitimate task (e.g. an admin
editing this server's own config, which contains real email addresses) instead of
killing the agent process by hand.
A machine that hasn't reported any event yet won't appear here — it needs to check
in at least once first.
Machine
Staff name
USB blocking enforced
OCR scanning
Content Guard
Last changed
No machines have reported in yet.
Audit log Every admin action taken from this dashboard
When
Action
Detail
No admin actions logged yet.
Error log Runtime errors from all components, in one place for debugging
Every component (USB Guard, Content Guard, Screenshot Guard, and this server itself)
reports unhandled runtime errors here — no more hunting through separate log files
on 15 different machines.
When
Component
Machine
Staff
Message
No runtime errors reported. Good sign.
Investigation lookup Tier 3 raw events — only pull this when actively investigating someone