How to monitor and secure AI usage with dope.security
18:53 · Published December 2, 2025
See how dope.security discovers employee AI use, restricts personal ChatGPT accounts, and monitors or blocks sensitive files and prompts with Dopamine DLP.
This recording shows the product as demonstrated at the time. The current interface and available features may differ.
In this demo
- 00:00 AI governance and Shadow IT monitoring
- 01:41 Allow, warn, or block AI applications
- 05:45 Restrict ChatGPT to approved enterprise workspaces
- 09:36 Configure Dopamine DLP
- 11:10 Block sensitive file uploads
- 13:15 Block sensitive prompts
- 15:04 Monitor mode versus block mode
- 17:19 Recap and next steps
Read the full transcript
00:01Hey everyone, today's dope.security demo is gonna focus on a common request we've been receiving and that is around AI governance.
00:09More specifically, how can I monitor and secure AI usage within my organization? So let's tackle that first part, which is monitoring.
00:20So here's our dope.security dashboard. We're gonna go ahead and click on Shadow IT and here you're gonna get a list
00:29of the most commonly used applications within your organization. So on the right hand panel here, I can see ChatGPT is actually at the top.
00:39So I'm gonna go ahead and click that and now I can see all of the users that are actually using ChatGPT.
00:48Not only that, but I can also see with what domain are they using it. So for myself here at the top, I could see
00:55that I'm accessing ChatGPT with my dope.security domain as well as my personal domain. Uh, if we jump down to my colleague Ashley,
01:04she has the same setup where she has her, uh, corporate domain as well as her personal domain. So this means that both myself
01:12and Ashley are using ChatGPT, uh, both our enterprise account and our personal account. So by knowing that information, you know
01:23that there could be a level of risk associated with accessing ChatGPT, right? So one is that you know that you have employees
01:31that are using AI tools. Two, you can also see with what account are they accessing that tool with. So now that we've identified, um,
01:41is there any AI usage going on and if so, what and how are they accessing it? Now we can address the security guardrails
01:50that we can put in place, uh, around AI usage. So the first type of guardrail that we can put in place is the URL uh, policy.
02:02So we'll go ahead and click SWG and we'll click my policy. And you can see here within my SWG policy, I can
02:14toggle and allow block or warn, um, setting for AI application. So this means that any URL, any domain that's specific
02:24to an AI application, I can um, put either an allow block or warning access permission on it. So let's say I want to be the most restrictive
02:33and I want to completely block AI usage, I'll toggle that to block, I'll click save policies, update it. So now when I try to access ChatGPT,
02:53I'm blocked. If I try to access Claude un blocked. So this is the most restrictive level of, uh, enforcement that you can have.
03:15So the other thing you can do is you can have a warning. So with this warning you can also create a custom warning
03:25page so that it's not generic, right? What you can do is you can say, Hey, like here are the parameters
03:31of which you can access AI applications and here's our company policy around, you know, the types of information you should upload to it
03:38and you should refrain from uploading to it. So I'll show you what that custom page will look like. So we'll toggle that to warning, we will click save.
03:52Let's go ahead and click AI again. And right now it has just a generic warning, but let's go ahead and do a ChatGPT
03:59warning and we'll click save. Okay, so now when I access ChatGPT get a custom warning. It says, Hey, are you sure you wanna use ChatGPT?
04:17Do not upload any corporate documents here. So now I can choose if I want to continue or if I wanna go back and go and click continue
04:28and say, okay, yep, I wanna upload anything and I'm in ChatGPT, I'm gonna close that out and then we'll toggle this back to allow click save.
04:45And now I should be able to access ChatGPT freely. Yep, perfect. So that is one type of a guardrail that you can put in place.
04:55It is a URL filtering guardrail where you can either block, allow or warn for the AI category. So the next type of policy
05:07or guardrail that we can put in place is let's say, uh, you're a your your company and you have an enterprise account with ChatGPT
05:18and you only want your employees to be able to access ChatGPT using those enterprise licenses, which is pretty common.
05:25If you recall, I'll jump back to our Shadow IT page here, ChatGPT. So even here at dope.security we have users
05:34who are using their corporate domain as well as their personal domain to access ChatGPT. So again, let's say that you have enterprise licenses
05:45and you only want your employees to be, to be able to access ChatGPT with that enterprise account. We actually have a cloud application control
05:57that can address just that. So we'll go ahead and click cloud app. And before I show you how this configuration works,
06:05I just wanna show you that right now I am able to log into ChatGPT using my personal account.
06:13So we'll go ahead and log in here, put my email in password
06:39and it should be logging me in. Great. So I am logged in to ChatGPT
06:57with my personal account. So now I can input anything I want here. Now if we think back to that use case, so
07:06I'm an organization, I have enterprise licenses, I wanna make sure that my employees are only accessing ChatGPT, uh, using those enterprise licenses.
07:14So we'll go ahead and configure ChatGPT in our cloud application controls here. So we'll click ChatGPT, enable control,
07:24and when you sign up for an enterprise account, you're going to get a workspace id. Now what you're gonna do is you're gonna take
07:32that workspace ID and you're gonna paste it in here and enter and say, okay, so now with this configuration, I should only be able
07:49to access ChatGPT with my enterprise account, not my personal account. So let's go and see if I can still log into ChatGPT with
07:58that personal account. Gonna click log in, continue with Google, enter my personal email
08:35password. There you go, here we go. So now it's gonna try and log me in, but remember we only wanna make,
08:53we only wanna have access through our enterprise account. Okay, perfect. So this basically tells me that, hey, my access is denied.
08:59My IT administrator has blocked access to this workspace. So what that means is that the only workspace that I can access ChatGPT with is
09:07with my enterprise account, not my personal account. No matter where I click, what I try to do, I can't get out of this.
09:15So we'll go ahead and click sign out. Okay, close that window. So as long as this is enabled, I will not be able
09:26to access my ChatGPT account with my uh, personal account. So now that that is done, we'll go ahead
09:36and disable this control just for the rest of the demo save. Perfect. So the last guardrail we're gonna look at is
09:54I'm gonna focus on the what, right? So, so far we've spent time on how, right? How are my users accessing ChatGPT
10:02and are they doing it with a personal account or a corporate account? Am I outright blocking ChatGPT and AI tools
10:09or am I prompting them with a warning page or am I completely allowing access? Right? So that's on the on the how.
10:18Now if we shift to the what, right? What are my users actually uploading to these AI tools? We're gonna go here to our SWG tab
10:30and we'll click on my policy and you're gonna see this section here called DLP. So we've recently launched um,
10:39our latest product which is called Dopamine DLP. It's an AI powered endpoint data loss prevention tool and it can scan AI tools like ChatGPT
10:50and let you know are users uploading sensitive content there or not. So you can see that I've already got this toggled on
10:57and I'm blocking sensitive uploads. So let's go ahead and test this out. So if you recall, I do allow ChatGPT access.
11:10So I am able to access this here you can see I'm logged with my dope.security account. Now let's say I asked ChatGPT to analyze this file for me
11:23and I'm gonna upload the salary test file and I get some type of an error. It says, you know, enter your network settings, allow access
11:37to the site or contact your network admin. So maybe it was like, maybe it was user error. So let me try again, analyze this file for me, chat,
11:50attach this here and I get the same block message. So as a user, I'm unable to attach this uh, sensitive file, right?
12:04And we know it's sensitive because it's called salary, right? It's got salary information in it. Now on the admin side we can come over here
12:13and let's see what the admin is seeing. We can see here in our latest activity that there is some type of A DLP block that's occurred.
12:21If we go to click detail, I can see here that exact uh, attempt that was made here at 1108.
12:34If I click this, so again, as the admin on this account, I can see that this user tried to upload this file but was blocked, right?
12:45And then I get a cool dopamine summary here that tells why it was blocked. It says, Hey, this includes social security numbers, uh,
12:52and a list of employees along with our dates of birth and records of salary information, right? So it detected PII sensitive content in this file.
13:03So Dopamine DLP did not even allow me as a user to upload that file to ChatGPT. So now the next question is, well
13:15what if I don't have a file? What if I'm just injecting some sensitive information directly into the prompt? So let's say, Hey chat, I found this number
13:28looks like credit card. Can you confirm, hit enter.
13:49Let's see what it says, something went wrong. If the issue persists, please contact us through our help center. So as a user, again, I am blocked from being able to,
14:02yes, I can type the prompt out, but it's not even gonna get processed and it's not even gonna go through.
14:08So as an admin, let's see what I'm seeing on this side. So we can see a ChatGPT block was just triggered, found the add,
14:20can click in and see what that was. And it says, I gave the user the URL path. It was a direct prompt input into chat
14:31GPT, I can see that here. And it says why it was blocked. It include the credit card number detects PCI.
14:40So what's really cool about this is again, not only can you control how users are accessing these AI tools,
14:47but the what is such a critical component right now, right? Whether you're trying to upload files that contain sensitive information
14:55or inject that sensitive information directly into the prompt, our Dopamine DLP is able to monitor for that type of activity.
15:04And then in this case, because my SWG DLP is set up to block, it's gonna block that transaction. The other thing that I can do is if I didn't want
15:15to outright block it and I just wanted to go into what's called monitor mode, I can keep my DLP inspection on toggle this to monitor.
15:25So this means that it's gonna allow the sensitive uploads, but it's still gonna log and track what is being uploaded.
15:32So if I monitor and I click save my DLP configuration's updated successfully, and if I come back here now to ChatGPT
15:48and let's start a new chat, Hey chat, analyze this file for me and I upload that same file,
16:10you're gonna see now that ChatGPT does take the upload and I can send it through. And now ChatGPT is in fact going in
16:22and analyzing this file that does contain sensitive content, right? And so with going through this analysis, so on the user side, I'm not seeing any blocks,
16:37but on the network admin side, if I come back here once that analysis is done, see now I'm gonna get a
16:45monitored alert here. It's a DLP trigger. Go in here to detail and here it is, right? So in monitor mode, this type
17:02of an upload would still be allowed even though the file contains sensitive information. But I'm gonna get a an alert that says, Hey,
17:11we're just letting you know that this user uploaded this file with this content, uh, to ChatGPT in this case, right?
17:19But it could be ChatGPT, um, or any other type of AI tool. So just to recap, with dope.security, you can monitor
17:34and secure AI usage within your organization. You can use Shadow IT to find those AI applications that your employees are using.
17:43And not only will you get a list of those AI applications, but you'll also get a list of the users
17:50and the domains that they're using to access things like ChatGPT with. You'll be able to see are they personal accounts
17:57that they're using or are they corporate accounts. Once you have that information, now you can start to go in
18:03and put those guardrails in place that we discussed, right? You can start with a URL filtering policy and you can allow block or warn the AI category as a whole.
18:14You can allow access to only your enterprise ChatGPT account using our cloud application control. And once you've put those guardrails in place,
18:23you can go a layer deeper with our Dopamine DLP and you can start to monitor, uh, or block sensitive uploads to these AI tools like ChatGPT.
18:35So that's it for this demo, but as always, if you want to give this a bid for yourself, you can go to our website, dope.security
18:43and sign up for an instant free trial completely on your own. Thanks.
Keep exploring
We made it dope.

