Halo
Halo
Admin Console

Sign in

Enter your email address and password to access your organisation console.

Incorrect email or password. Please try again.
Forgot password? Need access? support@halolayer.ai
First time signing in? No password has been set yet for this account. Enter your email and admin token (from your welcome email) in the fields above, then set a permanent password via Forgot password.

Reset password

Enter your email address and we'll send you a link to reset your password.

✉
Check your inbox

We've sent a password reset link to . The link expires in 1 hour.

Didn't receive it? Check your spam folder or try again.

Set new password

Choose a new password for your Admin Console account.

Halo
Halo Admin Console
Connecting…
— —
—

Activity Dashboard

Real-time DLP analytics across all monitored users — AI tools, CRM, social, and developer platforms.

16
AI tools open
0
CRM / Business
2
Social / Comms
0
Developer
2
Clipboard events
2
Print intercepts
Block
Enforcement mode
↑ first session
17
Prompts scanned
Across all enrolled users
↑ first session
17
Sensitive detected
17 contained sensitive data
↑ first session
688
Blocked / intercepted
Prompts · clipboard · print · download
first session
16
AI tool events
Events across AI tools

Risk level breakdown

Critical
12
High
183
Medium
506
Low
273

7-day risk trend

New activity today

Detection source

Where sensitive data was caught
Prompt scan
13
Clipboard copy/paste
2
File upload
0
Print interception
2
Download monitor
0

Top sites by risk

Ranked by sensitive event count

Sensitive activity by AI tool

6 AI tools with sensitive prompt activity.

Top risk categories

Risk heatmap

Detection intensity by hour across the last 7 days
Low
High

Org event log

All users · detection events across the organisation
TimeUserSiteSourcePackScoreLevelAction
1 / 1

Business exports Enforce

SIEM integration and compliance evidence exports
⚙
SIEM export
Structured JSON for Splunk, Datadog, Microsoft Sentinel. All events with full metadata.
🏥
HIPAA snapshot
Pre-formatted evidence of health data detection events across all enrolled users.
🇪🇺
GDPR snapshot
EU personal data events including special category data patterns.
💳
PCI-DSS snapshot
Card numbers, CVV, bank details and routing numbers detection evidence.
Halo Admin Console does not collect or transmit any user prompt content. Event metadata only. All detection runs locally in each user's browser.

Features & Enforcement

Configure the feature set enforced across all enrolled users. Admin policy overrides all local user settings.

🔒 Enterprise Admin Controls
These settings are Enforce-tier only. They control the extension itself, not just its detection behaviour.
Stealth mode is ON. The Halo widget will not appear on users' screens. Detection still runs silently in the background. Events are logged and reported to this console. Users will not know the extension is monitoring — suitable for regulated industries where background monitoring is permitted under policy.
📤 Push extension to users
Chrome Web Store link
Share this link with users to install Halo. Opens directly to the extension page.
Pre-filled activation URL
Send this URL to users — it opens the extension options page with the license key pre-filled.
Send onboarding email to a user
Sends an email with the Chrome Store link, activation URL, and license key. Same as the invite email from the Users tab.
🖥 Deploy via Chrome Enterprise / MDM
For IT-managed devices, force-install the extension and pre-configure the license key using Chrome Policy.
▸ View Chrome Policy JSON

        
      

Org-wide feature enforcement

Pushed to all enrolled users. Admin policy overrides individual user settings.

🧠 Advanced Context LLM — Configuration

When enabled, detections above the medium threshold are passed to a secondary LLM for intent analysis. The LLM determines whether the content represents a genuine data risk in context — a developer sharing an example API key vs a real credential, internal jargon vs actual PII. No prompt text is stored by Halo. The LLM call is made directly from the user's browser.

Select LLM provider
🔮
Claude (Anthropic)
claude-haiku-4-5 — fast, accurate, cheap
⚡
GPT-4o mini (OpenAI)
gpt-4o-mini — low latency
♊
Gemini Flash (Google)
gemini-2.0-flash — generous free tier
🔒
Local / On-prem
Ollama, LM Studio, or custom endpoint
⚠ Privacy note: The text of flagged prompts is sent to your chosen LLM provider for analysis. Ensure your LLM provider's data processing terms are compatible with your organisation's data policies and any applicable regulations (GDPR, HIPAA, POPIA). For maximum privacy, use a local/on-prem provider. Claude and GPT-4o have zero data retention options available.

Compliance & Detection

DLP rule packs, custom sensitive terms, and custom regex rules. All detection runs locally in each user's browser.

DLP detection packs

Toggle the compliance frameworks active for your organisation. Core packs are always on.

Core packs — always active
Regional packs — opt-in

Custom sensitive terms

Add organisation-specific keywords or internal project names, one per line.

Custom regex rules

Build patterns for structured data — customer IDs, internal identifiers, card formats.

No test run yet.

Saved rules

0 rules
No custom regex rules added yet.

Sites & Tools Coverage

Select which platforms Halo monitors across all enrolled users.

Policy Enforcement

Live view of active DLP controls, rule packs, platform coverage and enforcement actions.

Enforce
23
Active rule packs
45
Sites protected
Block
Enforcement mode
6
Active actions

Policy Builder

Rules push to all enrolled users within 5 minutes.

Detection rules

Mode: Enforce · 0 rules active
Policy JSON
DLP Rule Packs
PackCoverageFrameworkTierStatus
Platform Coverage

Integrations Enforce only

Forward detection events to your security stack. All data sent directly from each user's browser — Halo never relays events through its own servers.

0
Active integrations
0
Events forwarded
—
Last event sent
How BYOMCP works
1
Add an integration — paste your endpoint URL and API key or bearer token.
2
Choose your filters — set minimum risk score and event sources to include.
3
Pick your format — native JSON, CEF, LEEF, OCSF 1.1, or custom. Test before going live.

Quick-connect

Click a preset to pre-fill the form below.

Add integration

Example payload

    

Saved integrations

No integrations configured yet.
Halo never relays data through its own servers. Payloads assembled locally in each user's browser and sent directly to your endpoint.

Users

All users enrolled under your organisation license key.

✉ Invite users
Sends an email with the Chrome Store link, pre-filled activation URL, and license key.
50
Total seats
14
Active today
12
Blocks today
61
Avg risk score
UserLast activeEvents todayRisk scoreStatusActions

Compliance Reports

Organisation-wide compliance snapshot based on current policy and detection data.

Policy change audit trail

DateAdminChangePolicy version
No policy changes recorded yet.
HaloAdmin Console v3.0
← Back to sitePrivacyTermssupport@halolayer.ai
© 2026 Route19 (Pty) Ltd · Admin Console v3.0 · 100% local processing