Skip to content

Destination groups

Destination groups are where policy rules apply — the “into” of every rule.

Destination groups page

Platform groups are managed for you and follow the app catalog automatically. The categories:

GroupExamples
AI chatChatGPT, Claude, Gemini, Copilot, Perplexity, DeepSeek
AI codingCursor, GitHub Copilot, Replit, Windsurf, v0
Local AI runtimesOllama, LM Studio, Jan
AI image, video and audioMidjourney, Runway, ElevenLabs, Sora
AI meeting notesOtter, Fireflies, Descript
AI developer platformsOpenAI Platform, Anthropic Console, Hugging Face
AI writing and documentsGrammarly, Notion, Jasper
Cloud storageGoogle Drive, Dropbox, OneDrive, Box, iCloud Drive
Code hostingGitHub, GitLab, Bitbucket, Azure DevOps
File transferWeTransfer, Gofile, Filemail
MessagingSlack, Teams, WhatsApp, Discord, Telegram, Signal
Paste and snippet sharingPastebin, GitHub Gist, CodePen
TranslationDeepL, Google Translate
WebmailGmail, Outlook, Yahoo Mail, Proton Mail

When the platform catalog adds a new AI tool’s domains, every rule targeting AI chat covers it with no action from you — that is the point of referencing groups instead of hand-typed domain lists. Exact app lists and selector counts follow your catalog version; the Destination groups page in the console always shows the live set.

Everywhere is the reserved whole-device scope: rules scoped to it enforce at copy time, device-wide, before any destination is known. It cannot be forked or deleted. Use it for the small set of data types that should never even sit on a clipboard un-redacted.

Custom groups are yours: fork a platform group to add or trim apps, or build one from scratch (e.g. “Approved client portals”) with New group. Custom groups are targeted by rules exactly like platform ones — including as Allow carve-outs above stricter rules.

Each group lists its apps and its selectors (domains, desktop bundle ids, executable names). Selectors are maintained in the catalog by the platform team; you choose which groups your rules point at, not the raw domains.

The same catalog defines what the traffic proxy can intercept — the device’s certificate is constrained to exactly the catalog’s domains (see How the proxy works). A destination outside the catalog is not un-policied: pastes into it are still governed by your everywhere rules — it simply is not intercepted at the network layer.