The problem
People sign in to personal email and messaging on work laptops, often for harmless reasons. But a personal inbox is a channel your company doesn’t control, and your network tools can’t tell it apart from a work one: both are encrypted connections to the same website.
How LayerT handles it
- A rule names the sign-in field on the sites you care about. LayerT ships with rules for personal Google sign-ins, Telegram Web and WhatsApp Web, and you can point at any other site to write your own.
- The check happens in the page. When someone submits, LayerT compares the typed address or phone number with your rules. If it isn’t a company account, LayerT cancels the submission before the site sends anything.
- The person sees why, in a card that shows your message, never the rule’s internal name.
- They can ask for access if the rule allows it. An approver picks how long: a single attempt, 15 minutes, or up to 24 hours. Permanent exceptions are for Compliance to grant.
- Everything is logged, with the address that was blocked, so an auditor can check the decision.
Good to know
- Start with monitor rules to see what happens before you block anything.
- LayerT works in Chrome today. Edge, Firefox and Opera are coming.
- It’s sign-in control, not content scanning: it doesn’t look at files or the clipboard.

