FireTail Product Release: Sharper AI Attribution, Adaptive Governance, and Domain-Based Access Control

This is a broad release, and most of it is about precision. It sharpens who FireTail can attribute AI usage to, makes governance adaptive so it improves as your workforce uses AI, and adds harder access controls like restricting AI to corporate accounts.

FireTail Product Release: Sharper AI Attribution, Adaptive Governance, and Domain-Based Access Control

This is a broad release, and most of it is about precision. It sharpens who FireTail can attribute AI usage to, makes governance adaptive so it improves as your workforce uses AI, and adds harder access controls like restricting AI to corporate accounts. The throughline is the one we keep coming back to: see what AI is running across your organization, govern how it gets used, and be ready to show your posture when someone asks.

Here is everything that shipped, grouped by the job it does.

See it: discovery

Knowing that AI is in use is only half the picture. This release focuses discovery on who is behind it.

Workforce identity attribution. The endpoint agent now discovers AI provider account identities on devices and links them to the people behind them, including when someone signs in with more than one account. Instead of knowing that someone in the org used a given AI tool, you get the person, the device, and the accounts involved. That attribution is what makes the per-person governance later in this release possible.

Consistent ChatGPT detection. ChatGPT usage is now detected and logged whether the user is signed in or browsing anonymously, closing a gap where anonymous sessions could slip past.

Discovery in more places. In code, FireTail now detects AI usage in repositories built with crewAI and legacy LangChain versions, and repository analysis recognizes a wider range of usage patterns. In the cloud, another AI platform joins the catalogue of services FireTail discovers and monitors.

Also in discovery this release:

  • Device agent version tracking shows which agent version is running on each device, so keeping a fleet current is straightforward.
  • AI provider accounts are tracked per user even when a person uses several, giving you accurate attribution across multiple accounts.

See it: logging

Cleaner logs, with more of what matters and less of what does not.

Blocked-domain action logging. The browser extension now logs blocked-domain actions specifically, so you get granular visibility into exactly when domain-blocking policies are enforced rather than inferring it from surrounding activity.

Show Image

Also in logging this release:

  • A new debouncing mechanism de-duplicates repeated requests to the same website, so activity logs stay clean and accurate.
  • The endpoint agent redacts more sensitive tokens from request headers, strengthening data privacy in workforce logs.

Govern it

Governance is where this release put most of its weight, and the theme running through it is precision: rules that fit the person, the topic, and the way people actually prompt.

Adaptive topic guardrails. Topic guardrails now learn from real usage. When a prompt matches a topic, it is captured as a new example, so the guardrail sharpens over time, and sensitive content such as email addresses is masked before anything is stored. The result is a topic that FireTail surfaced from real activity, scored for risk, with the prompts that matched it in view.

Custom topics, with risk scores. You can define and manage custom topics for Prompt Intelligence, with automatic sub-topic generation and example embedding, so you control which conversation subjects are detected and governed. Each topic carries a risk score, so you can rank them and put governance attention where it matters most.

Restrict AI to corporate accounts. When you create or edit an AI Workforce Policy, you can now set the email domains allowed per platform. Requests from outside those domains are blocked, which gives you a clean way to keep people on corporate accounts and off personal ones. Availability varies by platform.

Enforcement that is harder to slip past. Blocking guardrails are now evaluated before informational ones, so an enforcement action is never skipped because an informational match came first. System topic policies are scheduled and enforced automatically alongside workforce log policies, so organizations on the workforce product get that enforcement without extra setup. And endpoint devices are notified in real time when topic data changes, so they always enforce against the latest definitions.

Also in governance this release:

  • Long prompts are split into overlapping windows for evaluation, so content past the model's input limit is no longer silently dropped.
  • The browser extension now supports proxies, domains, and guardrail annotations for more complex network environments.
  • Fixes to policy merging, device guardrail inheritance from groups and projects, and clearing optional policy fields tighten enforcement accuracy.

Prove it: posture

Google SecOps integration (preview). You can now set up a Google SecOps (Chronicle) integration from the integrations page to forward FireTail findings into your Chronicle instance, so AI findings land in the SecOps workflow your team already runs. This one is available as a preview.

Under the hood

A round of deployment and platform work that makes the agent easier to run at scale and the console easier to move through.

On deployment, Windows now offers transparent, TUN-based traffic interception alongside the existing proxy mode, in-place Windows upgrades preserve your configuration, certificates, and device identity so only fresh installs need a token, and the agent installs and trusts its CA inside WSL2 automatically, so FireTail works there with no extra configuration. The macOS installer gained better support for MDM and RMM fleet deployments, and the agent now recovers cleanly from crashes on both Windows and macOS.

In the console, panels stack with a breadcrumb trail and full back and forward support so you keep your place, resource names are clickable throughout, dashboards take custom date ranges down to ten-minute granularity, and filtering gained name search, suggestions across resource types, and color-coded quota bars. Rounding it out: distributor access management for EU and US regions, faster application startup, stricter SCIM email uniqueness, clearer loading and empty states, and a set of stability fixes.

See it against your own environment

The fastest way to know what this finds is to point it at your own setup. Book a call and we will walk it with you.
‍

October 2, 2026

Discover your AI exposure now

See how FireTail provides a single platform to discover, assess, and protect all AI usage across your organization.