Warda-DNSDocs Warda: from ward — to protect, guardian
v0.6.9

Business → AI services (business.ai, Warda Business, beta; internal/admin/ai.go): the AI assistants of the catalogue of services (ChatGPT, Claude, Copilot, Gemini, DeepSeek…) used on the network, and their policy. Warda reads only the names asked: it knows which device contacts which assistant, never what is sent. The use is the company policy: it covers every device of the company, those of adults included, whatever their owners chose for their own reports (the agreement of the reports of the adults does not apply); the page says so and reminds to inform the employees, with the template of the data loss prevention (tab Inform the employees).

  • Use (needs reports read): today, 7 or 30 days, today included — the queries, those blocked, the services used and the devices; the Queries to the assistants by day, By service (queries, devices, people, first use in the journal, New for a service first used within 7 days) and By device. A warning lists the services used for the first time this week ("Allow, tell or block them in the policy"). Computed on the box from the query log, as far back as it goes. GET /api/v1/reports/ai?period=today|7d|30d gives period, from, queries, blocked, services (id, name, queries, blocked, devices, people, first, last, new), devices and days.
  • Policy: for the network, a group, a person or a device (the most precise wins), the action of The AI assistants — Allow, Tell or Block. It is the same setting as the channel AI assistants of the data loss prevention (not kept twice: changing one changes the other). Assistants blocked on their own are blocked whatever the action (ChatGPT allowed and DeepSeek blocked): they are blocked services of the scope, shown on Services and safe search too. GET /api/v1/business/ai (rules read) gives services (the assistants), choices, policy (the rules of the channel ai) and blocks; PUT /api/v1/business/ai {"scope": "all|group|person|device", "target": "<id>", "action": "allow|alert|block|", "blocked": ["deepseek"]} (rules written; "" follows the larger scopes; the other channels and the other blocked services of the scope are kept; without the plan a scope may still be cleared).

Seeing what is sent to an assistant needs the HTTPS inspection (announced, see Plans).