Overview
The Swif Browser Extension and Agentic Security agent provide full visibility into Shadow IT and AI usage, allowing organizations to detect and manage unauthorized applications in real-time. By integrating with Swif’s compliance and device management, these tools ensure better control, security, and compliance across all devices without disrupting workflows.
This article covers how to deploy these tools organization-wide using Swif MDM Policies and Google Workspace.
Method 1: Deployed By Swif MDM Policies (Recommended)
Swif provides automated policies to enforce the installation of the browser extension and Agentic Security agent across your fleet.
Supported policies included:
1. Fleet Coverage & Monitoring
Admins can now monitor deployment progress directly from the Shadow IT or Agentic Security pages:
Coverage Info Alert: A new info alert displays the real-time count of devices where the tool is installed versus missing.
Auto-Hide: Once 100% coverage is achieved across your managed devices, the deployment alert will automatically hide to declutter your dashboard.
Review Devices: Clicking Review Devices opens a modal listing the specific devices that are still missing the deployment.
2. Configuring Deployment Policies
Clicking Manage Deployment or Configure Policies opens a centralized modal where you can manage settings for macOS, Windows, and Linux:
Policy States:
Platform Support:
macOS: Seamless deployment via Swif MDM.
Windows: Deployed as a robust system service (via
swifteam.exe).Linux: Supports both x64 and arm64 (e.g., AWS Graviton) architectures.
Note: Once a policy is assigned, the device's browser may need to be restarted for the extension to activate, while the Agentic Security agent will begin reporting status immediately upon sync.
Method 2: Google Workspace "Force install apps and extensions"
Force install apps and extensions
This can apply to signed-in users on any device or enrolled browsers on Windows, Mac, or Linux. For details, see Automatically Install Apps and Extensions.
In your Google Admin console (at admin.google.com)...
Go to Menu Devices > Chrome > Apps & extensions. The Overview page opens by default.
If you signed up for Chrome Browser Cloud Management, go to Menu Chrome browser > Apps & extensions.
At the top, click the type of app or extension you want to automatically install:
Users & browsers—For users who sign in with a managed Google Account on any device, and for enrolled browsers.
Managed guest sessions—For users who sign in to a managed guest session on a managed ChromeOS device.
On the left, choose who you want to automatically install the app for:
Users & browsers—To apply the setting to all users and browsers, leave the top organizational unit selected. Otherwise, select a child organizational unit or group.
Managed guest sessions—To apply the setting to all users, leave the top organizational unit selected. Otherwise, select a child organizational unit.
Find and click the Swif extension that you want to automatically install.
In the panel that opens on the right, under Installation policy, choose Force install or Force install + pin to ChromeOS taskbar.
Click Save. Or, you might click Override for an organizational unit.
Policy Revocation
If a policy is removed or a device is unassigned, Swif will automatically update the device status to reflect that security enforcement is no longer active, ensuring your audit trails remain accurate.





