Overview
Enforcement activity
Events per day over the last 14 days, by severity.
Device compliance
Posture reported at each device's last check-in.
Top event sources
Devices generating the most events in the window.
Event breakdown
What the fleet is actually reporting, by type.
Blocked categories
Categories enforced on every endpoint. Applied at the next agent poll.
Blocked sites
One per line — domain, IP or CIDR range. Learn more
Temporary site access
Grant a user access to a specific site that is normally blocked by category filtering (adult, gambling, messaging apps like WhatsApp/Telegram, etc.) for a limited time — on demand, without changing the category rule for everyone else.
| Site(s) allowed | Expires | Granted |
|---|
Data Loss Prevention
Rules that block or log sensitive content leaving the company. Learn more
| Name | Channels | Classifications | Action |
|---|
Advanced: detectors & classifications (JSON)
Threat intelligence
Indicators the agent blocks on: malicious destinations and known-malware file hashes. EICAR + Windows Defender (AMSI) are always on.
USB device control
Default for removable drives. Exceptions apply to a person or a machine, never to an individual USB device. Learn more
Leave Expires blank for a permanent exception, or pick a date to grant access on demand and have it lapse automatically.
| Name | Grant to | User ID / Asset serial | Action | Expires |
|---|
Upload policies
Controls where files may be uploaded from a browser. Learn more
Allows the domain and its subdomains; unlisted destinations are blocked. Paste a full URL and it's trimmed down to the domain automatically. Learn more
| Domain |
|---|
Devices
Endpoints running the agent. Compliance is from each device’s last check-in. Click a row for detail.
| Host | Authenticated as | Windows user | OS | IP | Agent | Last heartbeat | Policy | Compliance | Actions |
|---|
Assets
Who has which endpoint — assigned manually, one asset tag per device. Not auto-populated from a heartbeat; add a record here when a device is issued. Learn more
| Employee | Employee ID | Asset tag | Serial | Device | Flags | Actions |
|---|
Logs
Audit and enforcement events for your scope, newest first.
| Time | Type | Severity | Actor | Device | Message |
|---|
Console users
Who can sign in, and what they may do. New users set their own password by email code. Learn more
| Role | Password |
|---|
Directory groups — Microsoft Entra ID / Active Directory
Group membership grants the role automatically. Learn more
| Group | Role |
|---|
Local admin account lockdown — endpoint security
gsecure provisions two admin accounts on every laptop (one you name, plus the built-in Administrator as a recovery account), verifies both actually work, then removes local-admin rights from every other account after a grace period — closing the gap on endpoints with no Active Directory to manage this. Off by default. Learn more
| Account | Password |
|---|
Password history — last 5 per account, for a device that missed a rotation
| Account | Password | Rotated |
|---|
Role reference
Your role is —. You can assign roles at or below your own.
| Role | Can do |
|---|
API tokens
Programmatic access, scoped to your organization. Delete a token to revoke it. Learn more
Quick reference — reporting & bulk changes (curl)
Send as Authorization: Bearer gsk_…. Learn more
| Label | Role | Scope | Prefix | Last used | Status | Actions |
|---|
Agent logout code
A shared code your users must enter to sign out of the gsecure agent. Rotating it invalidates the old code immediately, for everyone. Leave it unconfigured to keep today's one-click logout.
Organizations
Only approved organizations can sign in. Self-service registrations arrive pending. Learn more
| GSecure ID | Organization | Domains | Admin email | Plan | Country | Created | Status | Actions |
|---|
Agent builds
Upload an agent.msi built on another machine (this server has no build toolchain), then publish it as the live update - a separate step on purpose, so you can check the size/hash before every already-installed agent silently updates to it.
| File | Size | Uploaded |
|---|
Access request link
Where the block page’s request button sends users. Learn more
Leave empty to hide the button.
Email delivery
Loading…
Verification codes and password-reset emails for your users are sent from here. Leave this empty to use the gsecure platform mail server.
The test sends a real message to your own address using the settings above — including unsaved changes. Nothing is stored until you press Save.
gsecure