Evose
GovernDesktop

Desktop · Policy Push

Centralized control of security policies on desktop clients

Centralized push of enterprise security policies to all desktop clients. Supported in both SaaS and Private deployment.

Policy Categories

CategoryControls
LoginSSO / email + password strength + max concurrent devices
Data accessLocal cache scope + offline access scope
File uploadType allowlist + per-file size + total quota
Screen watermarkUsername / email / timestamp + anti-screenshot
Auto-lockIdle timeout in N minutes
Download restrictionsWhether to allow exporting conversations / files
Copy/paste restrictionsRestrict copying sensitive conversations

Configuration Flow

Admin console → Desktop · Policy → Edit → Save

    Auto-pushed to all online clients

    Client enforces at action time (login / cache / file / copy, etc.)

    Violations: blocked + written to audit log

When Policies Take Effect

PolicyEffective
Login policyNext login
Data accessImmediately (cached data is purged per the new policy)
Screen watermarkImmediately
Auto-lockImmediately
File upload / downloadImmediately (already-downloaded files not retroactive)

Difference vs Resource Policy

Resource policyDesktop policy
ObjectResources (Agent / KB / Tool)Device behavior of the desktop client
ScopeWeb / API / clientDesktop client only
Example"Finance can't edit Marketing Agents""Disable copy/paste / enable watermark"

A Real Example

Policy: Finance Compliance
- Login: SSO required; email login disabled
- Multi-device: max 2 concurrent
- Screen watermark: username + email + timestamp
- File upload: no zip / exe / files > 100MB
- Copy/paste: external copy disabled
- Auto-lock: 5-minute idle

After push, all clients run under this policy immediately. Violations enter audit events.

Next Steps

On this page