For administrators of managed users signed in to Chrome browser for Windows, Mac, or Linux.
As an administrator, you can use the Gen AI & SaaS app usage report in your Google Admin console to monitor use of popular enterprise and Generative AI (Gen AI) apps and sites. When this setting is turned on, it creates a report that provides information about web visits, unique profile counts, unique managed browser counts, sensitive content transfers, protocols, and site information.
Before you begin
Ensure that Gen AI and SaaS app usage reporting is turned on:
-
Sign in with an administrator account to the Google Admin console.
If you aren’t using an administrator account, you can’t access the Admin console.
-
Go to Menu
Chrome browser > Settings. The User & browser settings page opens by default.
Requires having the Mobile Device Management administrator privilege.
- On the left, select your top-level organizational unit, so that all child organizations inherit the policy.
- Go to Browser reporting.
- Click Gen AI and SaaS app usage reporting.
- Select Enable SaaS usage reporting.
- Click Save.
View Gen AI and SaaS app usage information
-
Sign in with an administrator account to the Google Admin console.
If you aren’t using an administrator account, you can’t access the Admin console.
-
Go to Menu
Chrome browser > Reports > Gen AI & SaaS app.
Requires having the Chrome administrator privilege.
- (Optional) On the left, select an organizational unit.
- Search for the site you want:
- Click Add a filter and select the field to search.
- Enter your search criteria and click Apply.
- (Optional) To search multiple fields, add a filter for each field, enter search criteria, and click Apply.
- Click the heading of a column to sort by different criteria.
Review information about Gen AI and SaaS app usage in Chrome
On the Gen AI & SaaS app page that opens, you can see the following information for each site:
|
Report information |
Description |
|---|---|
|
Site name |
Name of the site |
|
Category |
Category of the site |
|
Total visits |
The number of visits from managed Chrome profiles or managed browsers in the selected period |
|
Unique profiles |
The number of unique managed Chrome profiles who have visited the site in the selected period. |
|
Unique browsers |
The number of unique managed Chrome browsers who have visited the site in the selected period. |
|
Sensitive content |
Number of sensitive content transfers in the selected period |
|
Organization name |
Organization name |
|
Encryption protocol |
Displays a list of encryption protocols used by the site. There can be multiple depending on the subdomain. |
|
Domains |
List of domains associated with the site |
Clicking a row opens a page where you can see additional details about the site.
|
Report information |
Description |
|
General |
General site information, including Category, Organization, and more. |
|
Unique profiles |
A list of users that have visited the site, including their Profile ID, Profile email, and Organization unit. |
|
Unique browser |
A list of browsers that have visited the site, including their Machine name and Organization unit. |
Create data protection rules
As an admin, you can create data protection rules to specify what sensitive content to scan for, and the actions to take when sensitive content is found.
-
Sign in with an administrator account to the Google Admin console.
If you aren’t using an administrator account, you can’t access the Admin console.
-
Go to Menu
Chrome browser > Reports > Gen AI & SaaS app.
Requires having the Chrome administrator privilege.
-
At the top, click Create a rule.
-
In the Name section, enter a name and (optionally) description for the rule.
-
In the Apps section, select the Chrome events that will trigger your rule.
-
Click Continue.
-
In the Actions section, select the action to occur if sensitive data is detected in the scan.
-
(Optional) In the Alerting section, select the security level—Low, Medium, or High.
-
(Optional) To report events in the alert center where you can view notifications about potential issues and take action to resolve them, check the Send to alert center box. If you want to receive email notifications, add recipients during this step.
-
Click Continue.
-
In the Scope section, choose an option:
-
To apply the rule to your whole organization, select All in domain.name.
-
To apply the rule to specific organizational units or groups, select Organizational units and/or groups and include or exclude organizational units and groups.
If there's a conflict between organizational units and groups in terms of inclusion or exclusion, the group takes precedence.
-
(Optional) In the Content conditions section, click Add Condition, set the content type to scan (for example, All content), and choose what to scan for (for example, Matches predefined data type).
-
(Optional) Add more conditions, using AND, OR, or NOT operators.
-
To add context-aware access conditions, select an access level from the list, or create a new access level.
-
Click Continue.
-
Review the rule details.
-
For Rule status, choose an option:
-
Active—Your rule runs immediately.
-
Inactive—Your rule exists, but is not in effect. This gives you time to review the rule and share it with team members before implementing. Activate the rule later by going to Security > Access and data control > Data Protection > Manage Rules. Click the Inactive status for the rule and select Active. The rule runs after you activate it, and DLP scans for sensitive content.
-
Click Create.
For details about using data protection rules to monitor user actions on Chrome browser and on Windows, Mac, Linux, and ChromeOS devices, go to Use Chrome Enterprise Premium to integrate DLP with Chrome
Report details
The following SaaS apps and Gen AI sites are reported on the report.
List of SaaS sites
- 1password.com
- acrobat.adobe.com
- airfocus.com
- airtable.com
- anthropic.com
- anydesk.com
- anyword.com
- asana.com
- atlassian.com
- atlassian.net
- atlassian.net/wiki
- aws.amazon.com
- awsapps.com
- bamboohr.com
- behance.net
- bill.com
- bing.com
- bitbucket.org
- box.com
- canva.com
- canva.me
- canva.site
- character.ai
- chatgpt.com
- claude.ai
- clickup.com
- cloudflare.com
- cohere.com
- copilot.microsoft.com
- copy.ai
- coupa.com
- crowdstrike.com
- cursor.com
- datadoghq.com
- deepai.org
- deepdreamgenerator.com
- deepseek.com
- docs.google.com
- docusign.com
- doubao.com
- drive.google.com
- dropbox.com
- elevenlabs.io
- express.adobe.com
- figma.com
- filmora.wondershare.com
- firefly.adobe.com
- five9.com
- flux1.org,
- freshworks.com
- g.co
- gbin.me
- gemini.google.com
- gist.github.com
- github.com
- github.io
- gmail.com
- gmail.com
- grammarly.com
- greenhouse.io
- grok.ai
- gusto.com
- hubspot.com
- ideogram.ai
- illustrator.adobe.com
- intercom.com
- jamf.com
- jasper.ai
- jira.com
- knowbe4.com
- leonardo.ai
- localtunnel.me
- logmein.com
- lucid.co
- lucid.co/lucidspark
- lucidchart.com
- lucidspark.com
- mail.google.com
- meet.google.com
- meraki.cisco.com
- meraki.com
- meta.ai
- microsoft.com
- midjourney.com
- miro.com
- monday.com
- mychart.org
- netsuite.com
- ngrok.com
- nightcafe.studio
- notebooklm.google.com
- notion.so
- office.com
- okta.com
- onelogin.com
- openai.com,
- openai.com/dall-e-3
- oracle.com
- pagerduty.com
- paloaltonetworks.com
- pastebin.com
- perplexity.ai
- photoshop.adobe.com
- picsart.com
- quillbot.com
- recraft.ai
- replit.com
- runwayml.com
- rytr.me
- salesforce.com
- send-anywhere.com
- sentry.io
- servicenow.com
- slack.com
- snowflake.com
- splunk.com
- stability.ai
- stripe.com
- suno.ai
- synthesia.io
- teamviewer.com
- twilio.com
- vanta.com
- wetransfer.com
- workday.com
- writer.com
- zendesk.com
- zoom.com
- zoom.us
- zoominfo.com
- zscaler.com