Skip to main content

App Conditional Policy

The app conditional policy is a feature that allows for fine-grained management of access rights and isolation security policies for the created app. Access to the app can be controlled based on conditions such as members, location, and time, and various security policies can be applied.

Table of Contents​

Basic

Policy Settings

Management


Basic Screen Composition​

The conditional policy screen is composed as follows.

  • Conditional Policy Tab: A tab where you can apply conditional policies to apps created in Home
  • Priority: Display policy priorities (the smaller the number, the higher the priority)
  • Add Policy: Create a new policy using the [Add Policy] button in the top left corner.
  • Search: Policy name, members, target app, usage status, and various conditions can be searched.
  • Policy Application Status Inquiry: Policy list top button bar's [Policy Application Status Inquiry] button to check the application history by policy and the policies not applied.

You can search for policies based on various criteria, including not only the policy name but also members, target apps, conditions, enforcement policies, and usage.

Types of Search Filters​

FilterSearch MethodExplanation
Policy NameIncluded SearchSearch for policy names that include keywords
MembersInclude Search + Dropdown SelectionUser (Name·Email), Group, Department Search, Assignment/Exception Classification Selection, Multiple Selection Available
TargetDropdown SelectionSearch by app name or app representative URL, multiple selections allowed
UsageDropdown SelectionUse / Not Use Selection
conditionInclude Search + Dropdown SelectionSearch by location (IP), time, device conditions, multiple selections available
Execution PolicyDropdown SelectionAccess Allow/Deny, Isolation Security Policy (All Allowed/Restricted Use), Additional Authentication Method Selection, Multiple Selections Possible

Member Search Details​

  • When you enter a name or email in the search box, results will be displayed in real-time dropdown.
  • Allocation / ExceptionYou can search by distinguishing between cases where a tab is selected and assigned to a policy and cases that are handled as exceptions.
  • All membersis fixed at the bottom of the dropdown and is included in the search results only when selected directly.
  • Location : 위치 제한 없음or enter a registered location name to search. The results are위치명 | IP 범위It will be displayed in the format.
  • time : 시간 제한 없음You can search by entering the registered time name. The results are시간명 | 시간 범위It will be displayed in the format.
  • device : 모든 디바이스, Desktop, Tablet, MobileSelect 중.

Execution Policy Search Details​

  • Access Policy: Allow access / Block access selection
  • Isolation Security Policy: Allow all / Select restricted use
  • Additional authentication methods: Not used / Email verification / OTP verification / Passkey (WebAuthn) verification selection (applies only to access permission policy)

Search Condition Combination Rules​

  • Between filters (AND condition): If you set multiple different filters, only the policies that satisfy all conditions simultaneously will be displayed.
  • In Filter (OR condition): If you select multiple items within the same filter, any policy that matches at least one will be displayed.
  • The set conditions are displayed in the form of tags, and the tags'×You can remove individual conditions with the button.

⚠️ Priority changes are not possible when search filters are applied. To change the priority, please clear all search filters.

Policy Application Status Inquiry​

Clicking the [Policy Application Status Inquiry] button at the top of the policy list opens a modal, where you can view the application history of conditional policies and the non-applied policies by period.

  • Modal Title: Policy Application Status Inquiry
areaContent
Query Period[Start Date] ~ [End Date] Calendar Selection
tabApplied Policies / Unapplied Policies
DownloadDownload Excel of the search results using the button in the upper right [↓]

Applied Policies Tab​

For the specified period, to the user**Policies Actually Applied (Heating)**Displays the list.

Table Column Configuration

columnExplanation
PriorityCurrent priority number of the policy
Policy NamePolicy Name (Click to move to the edit details screen)
ExplanationPolicy Description
Policy Usage StatusCurrently in use / Not in use status
Application Count ↑↓Number of times the policy was applied during the inquiry period (comma separated in thousands, sortable)
Recent application date ↑↓Most Recent Date Policy Applied Within the Query Period (Sortable)

💡 The application count and the most recent application date columns can be sorted in ascending/descending order. When sorting the application count in ascending order, you can quickly identify policies with low usage frequency at the top.

How to use

  1. [Policy Application Status Inquiry] Click the button → Open modal
  2. Setting the Query Period (Start Date ~ End Date)
  3. Check the Applied Policies Tab
  4. Sort by clicking the header of the application count or the most recent application date column.
  5. You can move to the edit detail screen of the corresponding policy by clicking the policy name.
  6. Download Excel results by clicking the button [↓] in the upper right corner.

Unapplied Policy Tab​

during the specified period**Policy that has never been applied (heating)**Displays the list.

Table Column Configuration

columnExplanation
PriorityCurrent priority number of the policy
Policy NamePolicy Name (Click to move to the edit details screen)
ExplanationPolicy Description
Policy Usage StatusCurrently in use / Not in use status

How to use

  1. [Policy Application Status Inquiry] Click the button → Open modal
  2. Setting the Query Period (Start Date ~ End Date)
  3. Select the Unapplied Policies tab
  4. Check the list of policies that were not applied even once during the period
  5. You can move to the edit detail screen of the corresponding policy by clicking the policy name.
  6. Download Excel results by clicking the button [↓] in the upper right corner.

💡 By periodically checking for unimplemented policies and organizing unnecessary ones, you can reduce policy management complexity and optimize the security environment.

Get Policy​

You can import and register a JSON file (single policy) or a ZIP file (multiple policies) that contains the conditional policy backup.

How to use

  • Download: Check the item checkbox > Click the [Download Policy] button on the top button bar
    • When selecting 1: Download JSON file
    • When selecting 2 or more: Download as a ZIP file.
  • import: Click the [Get Policy] button to select and register the backed-up JSON file or ZIP file.

Add Policy​

Clicking on [Add Policy] will take you to the new conditional policy page, where you can set the following items.

  • Policy Basic Information
  • condition
  • Execution Policy
  • Settings

Policy Basic Information​

Policy Name​

  • name(Required): Up to 20 characters can be entered
  • Explanation(Optional): Up to 200 characters can be entered.

The conditional policy name is a required value, and you must enter a unique name to identify the policy.

Members​

Set users or groups to include or exclude in this conditional policy.

allocation

  • All users: Apply policies to all users
  • Select User or Group: Search and select a specific user or group
    • Search by entering the username or group name in the search box.
    • The selected user or group can be confirmed in the box below.

Exclusion

  • Specify users or groups to exclude from the policy
  • Excluded members are not subject to the policy regardless of allocation.
  • The 'All Users' option cannot be used in the exclusion items.
  • If you select members to exclude, you can check the list of excluded members in the box below.

Target App​

  • Select the app or app group to which this conditional policy will be applied.
  • Only the selected app or group is subject to the policy.
  • You can select multiple apps, and you can also select them by app group.

Setting Conditions​

Set conditions such as location and time to be used for policy judgment. Based on the assigned conditions, determine the user's access environment and decide whether to apply the policy.

Location Conditions​

You can choose from the following two items for the location (IP) condition.

  • All Locations(Default): Apply policy at all locations without specific location conditions
    • Exception selection: To exclude only specific locations among all locations, specify the locations to be excluded through 'exception selection'.
  • Select Registered Location: Select from the locations registered in the conditions section of the Security365 Management Center.
    • Click 'Select a Location' to view the list of registered locations.
    • [+Register Location] : Click to add a new location condition
    • Exception Selection: Use 'Exception Selection' to exclude specific locations from the selected locations.

Time Condition​

You can choose from the following two time conditions.

  • All time(Default): Always apply policy without specific time limits
    • Exception Selection: To exclude only specific time zones among all times, specify the time to be excluded through 'Exception Selection'.
  • Select Registered Time: Select from the registered time in the conditions section of the Security365 Management Center.
    • Click 'Select a Time' to check the list of registered times.
    • [+Add Time] : Click to add a new time condition
    • Exception Selection: Use 'Exception Selection' to exclude specific time zones from the selected time.

Condition Management Notes​

  • The location and time conditions can be registered/deleted/edited in the [Condition Items] menu of the Security365 Management Center.
  • Use exception selection for fine-tuning when complex conditions are required.

Execution Policy​

Access Policy​

This conditional policy sets the access permissions when a member of the target to which this policy applies attempts to connect.

Access Permission

  • Access Denied: Completely block app access under the given conditions
  • Access Allowed: Allows app access and enables the setting of additional authentication methods.

Access via Remote Browser(Can be set only when access is allowed)

Set whether to route through the isolated browser (Remote Browser) when accessing the app. This option is only available in app conditional policies.

  • ON: Access the app via the isolation browser. The behavior control items of the isolation security policy are also applied.
  • OFF: Access the app through the user's PC's regular browser without going through the isolation browser. This is used when operating as a non-isolated app.
divisionON (Isolated Access)OFF (General Browser Access)
Access PathIsolated Browser ProxyGeneral browser of the user's PC
Access Control (Members·Conditions·Additional Authentication)ApplicationApplication
Isolation Security Policy (File·Clipboard·Keyboard·Context Menu·Input Sensitive Information Inspection)ApplicationNot applied

Even when set to unisolated (OFF), member assignment/exceptions, location/time/device conditions, and additional authentication methods operate the same way. It is recommended to configure work systems that require file export/data copy control to ON, while work systems that only require access permission management to OFF.

Additional authentication methods(Can be set only when access is allowed)

  • Not in use: Accessing the target without additional authentication
  • Email Verification: An authentication code input window appears and the authentication proceeds.
    • Time limit: 5 minutes
    • If you did not receive the authentication code in time, click 'Resend Authentication Code'
  • OTP Authentication: Initial registration QR code and recovery key instructions
    • Enter the authentication code after registration to proceed with authentication.
  • Passkey (WebAuthn) Authentication: An additional authentication method that verifies your identity using passkeys registered on the user's device, such as fingerprints, PINs, and security keys. It offers a higher level of security than email and OTP authentication, allowing for quick access using only biometric authentication without the need to enter an authentication code.

Passkey (WebAuthn) Authentication Workflow

  1. Display Additional Authentication Modal: When you access the target app, at the top of the screenAdditional AuthenticationA modal will be displayed. A message stating "For secure access, verification is required using a passkey (fingerprint, PIN, security key, etc.)" will be provided along with the [Authenticate] button. The passkey has a higher security requirement level than other two-factor authentications, so the authentication window must be opened as a popup. This modal is a step to bypass the browser's popup blocker by opening the popup with the user's **click (gesture)**.
  2. Biometric Authentication Process: Clicking [Authenticate] will open the authentication window (popup) and display the message "Authenticate with security key or biometric program." You will proceed with identity verification using the registered passkey on the device through fingerprint, PIN, or security key on the OS authentication screen such as Windows Security.
  3. Access Allowed: If authentication is successful, the authentication window will close and access to the originally requested app will be granted.
  • Display a notification popup "Authentication has failed." when authentication fails.
  • Unable to access the target.

Other Matters — Passkey authentication requires that the passkey (passwordless) credentials for the user are pre-registered. If the authentication window does not open or if authentication continues to fail, please request SOFTCAMP to check whether the passkey (passwordless) credentials are registered.

Isolation Security Policy​

Set policies to control user behavior within the app. All behavior control items can choose whether to allow or block.

Keyboard Input​

  • Allow/Deny Settings
  • When blocked: A message "Input via keyboard is prohibited by policy." is displayed at the center bottom.
  • Allow/Deny Settings
  • Allowed: Free movement to all sites
  • Block: Can only navigate to the representative URL and associated URLs.
  • When accessing a blocked site: Redirect to the "This action is prohibited by policy." guidance page.

File Security​

File Upload​

  • Allow/Deny Settings
  • Additional settings when allowed:

Only approved files are allowed

When using upload approval in SHIELD Drive, the files to be uploaded to the business system**Limited to files in the approved repository (approved).**does.

Setting ValueFile Management Screen
AllowedShow only repositories designated as approved
Block (default)Show all storage allocated to the user
  • Approval is obtained in advance by the user on SHIELD Drive. SHIELD Gate does not process approval requests or approvals.
  • The existing policy is차단Since it operates as a value, there is no change.

⚠️ When using grade control togetherOnly repositories where the allowed grade and approval conditions are both metIt will be displayed. If there is no rating assigned to the approval box, the file box will appear empty, so please check the rating assignment of the approval box.

File Download​

  • Allow/Deny Settings
  • When blocked: "This action is prohibited by policy. Downloading is prohibited by policy." Move to the information page, return to the previous screen with the close button.
  • Additional settings when allowed:
    • Extension Limit: Control downloadable file extensions (belowExtension Restrictions — Block / Allow MethodReference)
    • Repository Selection
      • My PC file folder: Downloading files to the user's local PC
      • SHIELDGate File Cabinet: Saving files to SHIELDrive storage (storage can be specified)
      • SHIELDViewer: Open the file in SHIELDViewer preview when downloading
        • Sub-options — Download button on the preview success screen
          • PDF Download: Allow/Block conversion of the original to PDF (Default: Allow)
          • Download Original: Allow/Block Download of Original Document (Default: Block)
          • CDR Download: Allow/Block Download After CDR Declassification (Default: Block)
        • Sub-options —Provide download button when preview is not available(PDF · Original · CDR Allow/Block respectively, belowProvide download button when preview is not availableReference)
        • Operation: A preview of SHIELDViewer opens in a new tab, and only the corresponding download button is displayed according to the set options.
  • Precautions When Using SHIELDrive Storage
    • The member must be assigned to SHIELDrive storage to be available.
    • Unable to download files if there is no storage allocation

Provide download button when preview is not available

When encountering a document that cannot be opened with SHIELDViewer, you can separately configure which download button to provide.

Existing download options (PDF · Original · CDR) arePreview screen opened normallyControls the button. This option isPreview unavailable screenIt only controls the button, so it can be set to prevent downloading the original under normal circumstances and only allow downloads when previews are not available.

screenReferencing OptionsExposed Button
Preview successfulExisting download optionsButton set to allowed
Preview not availableProvide download button when preview is not availableButton set to allowed (excluding PDF)

Applicable Situations

  • Unsupported extension (exe, zipetc.)
  • Excel cell count exceeded (total sheet limit 1 million cells)

⚠️ Preview unavailable screen shows**The PDF download button is not displayed.**Documents that have not been previewed do not have conversion results, so there is no PDF available for provision. Even if PDF is set to allowed, the buttons that are actually displayed are Original and CDR.

Existing Policy

The existing policy isCopy existing download option values as they areIt works. If you do not change the settings, there will be no change in operation.

The default values for the new policy are the same as the existing options — Allow PDF · Block Original · Block CDR.

Extension Restrictions — Block / Allow Method​

Select the extension control method for file upload and download.격리 보안 정책 > 파일 보안 > 파일 업로드 / 파일 다운로드ofExtension LimitSet in.

Selecting Extension Control Method

Select one of the two methods from the method selection button at the top of the extension limit.

  • Block Extension: Only the registered extensions are blocked, and all others are allowed. (Existing method)
  • Allowed extensions: Only the registered extensions are allowed, and all others are blocked.

Extension Registration

  • Enter the extension one by one in the input field and**[+]**When added with a button, it will be displayed in the form of a chip.
  • Enter only the file extension. For example:png ( .pnglike thispngwill be registered.)
  • The input box guidance will be displayed as "Enter the blocked file extensions." / "Enter the allowed file extensions." depending on the method.
  • If you enter an already added extension again, a message will be displayed saying "This extension is already added."

⚠️ File upload and file download**You cannot set it as "Allowed Extensions" at the same time.**If one side is changed to "Allow Extensions," the other side will automatically switch to "Block Extensions."

User Guidance When Blocked

If the file is blocked due to extension restrictions, a message "Attachment Request Failed" will be displayed on the user screen, along with the following information.

  • Allowed extensions: (List of extensions registered as allowed in the "Allowed Extensions" method)
  • Blocked file: (blocked file name)

Clipboard Access

Controls copy/paste between the isolated browser and the user PC. If clipboard access is allowed, copy and paste can be set in 3 stages respectively.

OptionvalueAction
Copy in the isolated browserAllowedCopyable. Can be exported to PC clipboard.
Internal AllowanceCopyable. Not exportable to PC clipboard.
BlockCopy not allowed
Paste into the isolated browserAllowedPasteable. Importable from PC clipboard.
Internal AllowanceOnly content copied from the isolated browser can be pasted.
BlockCannot paste
  • Each direction is set independently. The ability to copy → paste (internal movement) within the isolated browser is determined by the combination of the two values.
  • The existing allow/block settings are respectively허용 / 차단It continues with. The operation of the existing policy does not change.
  • 클립보드 액세스If not allowed, the entire direction setting will be disabled.

Paste 내부 허용if set to

The PC clipboard content is not transmitted to the isolated browser. Even if the user copies from the PC and pastes,Last copied content in the isolated browserThis is entered, and a guide will be displayed on the user screen indicating what has been entered.

Cutting

Cutting is**Copying and pasting are both allowed.**works only in. paste차단If set to __PH_0__, cutting will also be blocked. If cutting occurs when there is no place to paste, only the original will be deleted, resulting in data loss.

Operation by setting combination

copyPasteExportImportInternal NavigationCutting
AllowedAllowedOOOO
AllowedInternal AllowanceOXOO
AllowedBlockOXXX
Internal AllowanceAllowedXOXO
Internal AllowanceInternal AllowanceXXOO
Internal AllowanceBlockXXXX
BlockAllowedXOXX
BlockInternal AllowanceXXXX
BlockBlockXXXX

⚠️ 복사 = 내부 허용 + 붙여넣기 = 허용In the combination, the PC clipboard content takes precedence, so you cannot paste content copied from the isolated browser. If internal copy-pasting is needed, pasting is also내부 허용Set to.

⚠️ 복사 = 내부 허용 + 붙여넣기 = 차단The combination is saved, but you cannot paste the copied content anywhere. To prevent copying itself, you need to stop copying.차단Set to.

User Selection After Warning

Copy and Paste차단or내부 허용If set to, under경고 후 사용자 선택You can check.

If checked, a confirmation modal will be displayed when the user attempts an action that is blocked by the policy, and the user will계속 진행or취소Select.

itemContent
Location격리 브라우저에서 복사 · 격리 브라우저에 붙여넣기of차단 · 내부 허용subordinate
formCheckbox (default: off)
Activation Conditionsthe direction차단or내부 허용when.허용cannot be selected in
Setting UnitIndependent by direction. You can only apply copy or paste.

Since the default value is off,내부 허용The operation of the policy currently in operation will remain unchanged.

Warning Range by Direction Value

direction valueThe timing of when the modal is displayedIf you choose to continue,
BlockWhen trying to copy and pasteThe blocked copy and paste will be performed. It is also possible to exchange with the PC.
Internal AllowanceWhen trying to copy and pasteIt is performed only within the isolated browser. It does not exchange with the PC.

내부 허용The warning in __PH_0__ is not a setting that releases control.**To inform the user that it cannot exchange with the PC and to keep a record of that fact.**and a modal will also be displayed for copy and paste within the isolated browser.

Action Based on User Selection

direction valueUser Selectionresult
BlockContinue 진행Copying and pasting will be performed (including PC export and import)
BlockCancelNo action is performed.
Internal AllowanceContinue 진행Copying and pasting is only performed within the isolated browser. It does not go to the PC clipboard, and content copied from the PC does not come in.
Internal AllowanceCancelNo action is performed. Copying and pasting inside the isolated browser also does not work.

Both results are recorded in the log. The administrator can distinguish and verify the cases that proceeded after the warning and those that were canceled in the log.

Warning modal text

direction valueActionphrase
BlockcopyAccording to the administrator policy, the content of the isolated browser cannot be copied to the PC. If you continue, the copying will be performed, and the fact of the proceeding will be logged.
BlockCuttingAccording to the administrator policy, the content of the isolated browser cannot be cut to the PC. If you continue, the cut operation will be performed, and the fact of the operation will be logged.
BlockPasteAccording to the administrator policy, the content of the PC cannot be pasted into the isolated browser. If you proceed, the paste action will be performed, and the fact of proceeding will be logged.
Internal AllowancecopyAccording to the administrator policy, the content of the isolated browser cannot be copied to the PC. If you proceed, the copying will only be performed within the isolated browser, and the fact of proceeding will be logged.
Internal AllowanceCuttingAccording to the administrator policy, the content of the isolated browser cannot be cut to the PC. If you proceed, cutting will only be performed within the isolated browser, and the fact of proceeding will be logged.
Internal AllowancePasteAccording to the administrator policy, content from the PC cannot be pasted into the isolated browser. If you continue, only the content copied within the isolated browser will be pasted, and the fact of proceeding will be logged.

The selection button is계속 진행 · 취소There are two things.

⚠️ 차단in경고 후 사용자 선택is an action blocked by the administratorSettings that allow the user to pass on their ownis.내부 허용The scope of control does not change, and the purpose is user notification and record keeping.

⚠️ 경고 후 사용자 선택When turned on, a modal will be displayed for each copy and paste in that direction. In particular, pasting is displayed every time regardless of whether the content was copied from a PC or from an isolated browser. In frequently used business systems, please configure it considering user burden.

User Interface Guide

situationGuide text
Clipboard access not allowedClipboard usage is prohibited by policy.
copy =차단Copying is restricted.
copy =내부 허용The copied content can only be used within the isolated browser.
copy =내부 허용+ Paste =차단It is set so that copied content cannot be pasted.
Paste =차단Pasting is restricted.
Paste =내부 허용, execute pasteContent copied from the isolated browser has been pasted.
Paste =내부 허용, no content to attachThere is no content copied from the isolated browser.
Cannot cutCutting cannot be used as pasting is restricted.

Session Persistence​

After the idle time has passed, the isolated browser session will be reclaimed. Depending on the nature of the screen, set the retention time and choose how to display the screen after the session has been reclaimed.

itemSettings
Session PersistenceUsed / Unused. If unused, all values below will not be applied.
Viewing Screen Retention TimeApplied to the screen with no keyboard input (in minutes)
Work Screen Retention TimeApplied to the screen where keyboard input has occurred at least once (in minutes)
Idle Processing Method정지 화면(default) /잠금 화면

Screen Judgment and Maintenance Time Criteria

  • A screen where keyboard input has occurred at least once is classified as a working screen and will not revert back to a viewing screen. The type of input is not distinguished.
  • Retention time isElapsed time since the last operationCalculates with. After opening the screen, it is not the total usage time.
  • It is not considered idle while the video is playing.
  • Calculations are performed individually for each screen (tab). If one screen is paused, it does not affect other screens.
  • The judgment result and remaining time are not displayed on the user screen.

Idle Processing Method

methodScreen after session retrieval
Stop Screen (Default)The last screen you were viewing is frozen as it is. It does not display any guidance message.
Lock ScreenA solid color background covers the last screen and displays a guide message. It is used in business systems where the screen content needs to be obscured.
  • When the user clicks on the screen or scrolls, a message "You have not used it for a certain period of time, resuming the session." will be displayed in the lower right corner, and the previous address will reopen in a new session. Once the page opens, the message will automatically disappear.
  • The mouse cursor movement alone will not resume.
  • Only the previous address will be restored. The site login status, content being entered, and scroll position may not be restored.
  • If you cannot resume due to resource shortage or simultaneous connection limit, you can try again with the message "You cannot resume at this time."
  • Session retrieval and resumption are all recorded in the logs.

Setting Scope and Existing Policies

  • both valuesCompany-specific upper limitis limited. The upper limit is set by SOFTCAMP on a company basis.
  • The existing policy applies the previously set retention time to both the viewing and working values without any changes in operation. To keep the working screen for a longer time, please change the working screen retention time directly.

Number of Concurrent Screens​

Limits the maximum number of screens that a user can open simultaneously in an isolated browser. This is a setting to prevent excessive resource usage and maintain system performance reliably.

SettingsAction
According to system settings (default)The upper limit set at the company level will be applied as is. If there is no upper limit, it can be used without restriction.
Specify maximum number of screensYou can enter the quantity directly. You can set it from 1 to the company's upper limit.
  • The upper limit is set by SOFTCAMP at the company level.
  • If the specified value exceeds the upper limit, it will be automatically adjusted to the upper limit, and a notification will be displayed stating, "The existing settings N have been adjusted to M as they exceeded the system maximum value (M)."
  • The number of screens is calculated per user.

User screen when exceeding the maximum number of screens

When the user opens a new screen while reaching the limit, a "Maximum Concurrent Screen Count Reached" window will be displayed.

CompositionContent
Guide text"The isolation browser screen can be opened simultaneously up to N times." "To open a new screen, please select and close an open screen."
Open ScreenThe list of titles and addresses of the currently open screens. The screen the user was viewing is at the top.현재 화면is indicated. Next to the address복사You can copy the address.
Screen SelectionChecking the screen to close. Multiple selections and select all are possible.
선택한 화면 닫고 새 화면 열기Closes the selected screen and opens the screen you were about to open. You cannot press it if no screen is selected.
취소No screen will be closed. A new screen will not open.
  • The window will display a message saying "If you close the screen, unsaved work may be lost."

Screen Marking​

  • Activation/Deactivation settings available
  • When activated: Display a watermark containing user name, email information, etc. on the screen.
  • Data Leakage Prevention and Enhanced Accountability Tracking
  • The screen mark display method can be customized in the 'Business System > Security Screen Settings > Screen Marking/Watermark Settings' menu.
  • Available for enabling/disabling settings
  • When activated: Display a watermark containing user name, email information, etc. on the screen.
  • Data Leakage Prevention and Enhanced Accountability Tracking
  • The watermark display method can be customized in the menu 'Business System > Security Screen Settings > Screen Marking/Watermark Settings'.

Video Conference Mode​

  • Activate in business systems that require video conferencing
  • Activation Restrictions: SHIELDGate shortcut function not available (shortcut icon not provided in the upper right corner)
  • Settings for Optimizing Video Conference Performance

Context Menu​

  • Available for enabling/disabling settings
  • When activated: Individually control the context menu items displayed when right-clicking in the RBI browser by target.
  • Context Menu Settings > Clicking the link will open the detailed settings slide. The current setting status is summarized text (e.g:32개 표시 | 2개 숨김) is indicated.

Context Menu Detailed Settings

Individually control the ON/OFF state of menu items to be displayed for each clickable target area.

areaExplanation
Page Background AreaContext menu displayed on right-clicking empty space (Back, Forward, Refresh, Print, View Page Source, Inspect, etc.)
Text Selection AreaContext menu displayed after right-clicking after dragging text (copy, print, etc.)
linkMenu displayed when right-clicking on a link (Open in new tab, Copy link address, etc.)
imageMenu displayed when right-clicking on an image (Save image, Copy image, etc.)
videoMenu displayed when right-clicking on the video (Play/Pause, Save video, etc.)
AudioMenu displayed when right-clicking on the audio (Play/Pause, Save Audio, etc.)
Input FieldContext menu displayed when right-clicking in the text input field (Cut, Copy, Paste, etc.)
  • Each item within the area is controlled by an individual ON/OFF toggle,All ON / All OFFYou can collectively toggle all items within the area using the button.
  • bottomInitializationClicking the button will reset all items to their default values.
  • If all items in a specific area are OFF, the context menu will not be displayed when right-clicking in that area.

⚠️ Shortcut Key Integration: If you set the menu item to OFF, the associated keyboard shortcuts will also be blocked. (e.g.: Print item OFF →Ctrl + PBlock)

⚠️ Top Button Constraints in Browser: Setting the back/forward/refresh menu items to OFF does not block clicks on the navigation buttons at the top of the browser. Shortcut keys (Alt+←, F5Only (etc.) will be blocked.

  • Video/Audio: You can control the basic playback-related menu for video and audio, which is applied based on the standard context menu items of the browser.
  • Shortcut keys: The browser's default shortcuts associated with context menu items are controlled together, while custom shortcuts are excluded.

Data Security — Sensitive Information Input Inspection​

Input Prompt Firewall (formerly Custom Overlay) feature checks sensitive information (such as regular expressions, etc.) in the text entered by the user,Before the original text is delivered to the siteControls. This item is displayed according to company settings.

Settings

  • Input Sensitive Information Check(ON/OFF): Turns the inspection on or off for this policy target. It operates as follows depending on the inspection method.
  • Self-Inspection (Regular Expression): If you turn the inspection ON,Regular Expression Selection(Select from the list registered in sensitive information management, new additions possible) andLog OptionsSet.
    • Log storage scope: All cases / Only blocked cases
    • User input content included: Whether to include the text entered by the user in the inspection log.
  • External Integration: Only the inspection ON/OFF is set, and the regular expression and log detail settings are handled by the external inspection system.

If this item (Data Security > Input Sensitive Information Check) is not visible, you need to enable the input prompt firewall. Please contact SOFTCAMP.

Core Values

  • Prevention: Unlike the existing method that detects after transmission, it inspects and blocks before the input is sent externally.
  • Original text not leaked: Designed to only transmit results that have passed inspection, preventing sensitive information from being sent to external services or remote screens.
  • Bypass Blocking: Perform inspection and judgment at a control point rather than the user local, blocking bypassing inspections by local tampering.
  • Judgment·Record: It determines whether the text file is allowed or blocked, and logs the entire process as an audit log.

Policy Settings​

You can set the usage and validity period of this conditional policy.

Usage Status

  • use: The policy is activated and works immediately
  • Not in use: The policy is disabled and does not operate.

Expiration Date

  • If not set: Operates indefinitely
  • Expiration Date Usage: Checking the 'Expiration Date' item activates the calendar.
  • Set the period by selecting the start date and end date.
  • Policy operates only during the set period.

Policy Application Priority​

  • If multiple policies conflict, the policy with a higher priority (a smaller number) will be applied.
  • You can adjust the priority by dragging and dropping in the policy list.
  • If multiple policies are set for the same conditions, the most restrictive policy takes precedence.
  • Policy priorities are important for the effective management of policies, so they should be set carefully.

Priority Quick Move​

After selecting a policy, you can quickly change the priority using the following method.

  • Move to top / Move to bottom: Move immediately to the top or bottom
  • Priority Move Dropdown: Select the desired number to move directly to a specific location

⚠️ Priority changes are not possible when search filters are applied. Please proceed after clearing all filters.

Download Policy Status​

You can download the list of conditional policies as an Excel (.xlsx) file. This is provided separately from the existing JSON backup feature.

  • Download All: Save all registered policy information as an Excel file
  • Download Search Results: Save only the results with the current search filter applied as an Excel file

💡 JSON download is for policy backup and restoration, while Excel download is used for status analysis and reporting purposes.

Management of Default Execution Policy​

This is a feature that allows you to pre-set and manage default values that are automatically filled in for execution policies and isolation security policies when registering new conditional policies. It reduces repetitive manual settings and prevents setting omissions and input errors.

Accessing the Default Value Management Screen​

Click the [Execution Policy Default Management] button on the right side of the policy list top button bar.

[+ Policy Registration]  ...  [Execution Policy Default Management]

※ The default values of the app and the URL input field are managed independently. Changing the default value in one menu does not affect other menus.

Default Value Setting Range​

The items that can be set in the default value management screen are as follows.

itemWhether to apply default valuesNote
Policy Name / Description❌Unique input for each policy
Members / Target App❌Unique designation for each policy
Condition (Location·Time)❌Set directly for each policy
Execution Policy (Access Policy · Additional Authentication)✅
Isolation Security Policy (Keyboard, File, Clipboard, Session, Context Menu, etc.)✅
Settings (Usage Status · Validity Period)❌

Save Default Value​

After setting the execution policy and isolation security policy items on the default value management screen, click the [Save] button.

Actionresult
[Save] ClickThe current settings are saved as the default values for the app conditional policy. Automatically applied when registering new policies thereafter.
[Cancel] ClickReturn to the list screen without saving changes
Default value not set (initial)Display in system initial value (fully allowed, not set) state

Automatically apply when registering a new policy​

[Add Policy] When clicked, the execution policy and isolation security policy items are automatically filled with the default values saved. Enter the policy name, members, target app, and conditions, and register by modifying only the necessary items.

statusAction
When a default value is setExecution policy · Isolation security policy reset to default
If no default value is setInitialize to system default values (same as existing operation)
If manually modified after automatic applicationThe modified value takes precedence and does not affect the default value.

※ Automatic application only applies to the initial value setting at the time of new registration. It does not affect existing saved policies.

Apply default values in bulk to the selected policy​

After selecting the policies with checkboxes in the list, clicking the [Apply Default Enforcement Policy] button in the top button bar will overwrite the enforcement policy and isolation security policy items of the selected policies with the current default values.

How to use

  1. Select the checkbox for the policy to apply the default value from the list.
  2. Click the [Apply Default Execution Policy] button in the top button bar.
  3. Check the default values to be applied in the confirmation dialog (execution policy · isolation security policy summary).
  4. Clicking the [Apply Default] button will immediately apply the default values to the selected policy.

⚠️ The application of default values is saved immediately. Policy name, description, members, target app, conditions, and settings are not changed.

⚠️ If no default value is set, the system's initial value will be applied.