1️⃣ What the Sonar browser extension does
Your teams use AI tools in their browser, including tools that aren't approved by your organization. The Sonar browser extension automatically anonymizes sensitive data before it's entered into these tools.
The goal: keep control of your data without slowing your employees down. The extension doesn't block tools — it anonymizes what needs to be anonymized and points employees toward approved tools.
2️⃣ What the extension covers
👉 Browsers
Google Chrome and Microsoft Edge (more browsers to come).
The employee must be signed into the browser with their work account.
👉 Tools concerned
AI tools accessed in the browser (such as ChatGPT, Claude, Perplexity…).
Desktop apps aren't covered, since they run outside the browser.
👉 Action detected
For now, the extension only intercepts sensitive copy-paste actions. Manual typing and file uploads will follow soon.
💡 Pre-requisites:
Use Google Chrome or Microsoft Edge.
Be signed into the browser with your work account.
3️⃣ What the extension intercepts exactly
Redaction only applies within a specific scope. Knowing it saves you from promising your teams broader coverage than there actually is.
👉 Browsers
Google Chrome and Microsoft Edge, provided the employee is signed into the browser with their work account. Other browsers will follow.
👉 Actions
copy-pasting sensitive content;
uploading files, in
.txt,.csv,.pdf,.docxand.xlsxformats.
Typing on the keyboard and other file formats aren't covered yet.
⚠️ Important: for .pdf, .docx and .xlsx formats, on-the-fly redaction isn't possible: the upload is blocked rather than redacted. So employees see different behaviour depending on the file type — expect questions about it.
👉 Sites
AI tools accessible in the browser. Desktop applications are not covered, since they run outside the browser.
👍 Good to know: redaction also triggers on an AI tool that is approved at your company, if the employee isn't signed into it with their work account. That is deliberate: on a personal account, your contractual guarantees don't apply.
4️⃣ The employee experience
When an employee pastes sensitive data into an unapproved AI tool:
Albert pops up and anonymizes the data on the fly, before it reaches the AI tool.
Albert tells them what was anonymized and which approved AI tool to use instead.
If the employee disagrees, they can override the redaction in one click (if you allow it — see step 2 below).
5️⃣ What you configure, and what you see
👉 Your three settings
which AI tools are approved at your company;
which types of sensitive data Albert should redact;
whether your employees can override redaction or not.
👉 What you see in the analytics
You never see your employees' prompts, nor individual events. You get aggregated statistics on how often redaction happens, broken down by employee, by data type and by unapproved AI tool.
👍 Good to know: sensitive data doesn't leave the browser. Analysis is performed locally, on the employee's machine. That is the key argument when addressing concerns from your employee representative bodies, and a notable difference from the content analysis of files stored in the Drive.
6️⃣ Deploying and configuring the extension
The extension is included in your Sonar subscription, at no extra cost.
Step 1: Deploy the extension. From your Sonar settings, enable the extension in just a few clicks, then follow our installation guide for Chrome or Edge.
Step 2: Configure the policy. Everything else happens in Sonar's Sensitive data redaction in AI tools policy. There you define:
the tools concerned (those that aren't approved at your organization);
the sensitive data types Albert should anonymize;
whether employees can or cannot override Albert's decision.
Step 3: Track the events. Once the extension is enabled, the first events appear in Sonar's Insights tab (top-right of your screen).
7️⃣ The three deployment routes
The Hub guides you step by step. Which route applies depends on your directory.
The extension is force-installed on managed Chrome browsers, from the Google Admin console. Only employees signed into Chrome with their work account receive it.
👉 Microsoft in the cloud
The extension is force-installed on managed Edge browsers, with no additional tooling. For managed Chrome browsers, deployment goes through Microsoft Intune.
👉 Microsoft on-premise
Several methods exist depending on your setup; we provide guides for the most common ones. Two steps are specific to this case:
a secret must be added to the extension to identify your workspace;
the employee must sign in to the Riot portal once after installation, so they can be identified.
⚠️ Important: if your environment is entirely on-premise, enabling Sonar can't be done through the usual journey, which is designed for cloud environments. Contact us via the chat: our team will handle it.
💡 Restricting the rollout to a few employees: this is possible on the Microsoft side, for the Edge deployment only, by selecting a group during the procedure
8️⃣ Try the extension
A demo interface lets you try the extension live, with no setup required: demo interface. Just follow the steps to see in real time what Albert can anonymize before data reaches AI tools.
👍 Good to know: Sensitive data doesn't leave the browser: anonymization happens locally, which addresses data privacy concerns.
Key takeaways
The Sonar browser extension anonymizes sensitive data before it reaches unapproved AI tools.
Available on Chrome and Edge, included in Sonar at no extra cost.
For now: copy-paste only (manual typing and file uploads coming soon).
You stay in control: approved tools, data types to anonymize, override permission.

