One test page per DLP rule from the CEP POV guide (Citrix DLP track). Each page shows the rule's configuration as built in the Google Admin Console, an interactive test target, and the expected result — so testers can validate every rule end-to-end and record pass/fail.
Before testing, the following must be in place — see the POV guide for setup steps:
Chrome Enterprise Core active, domain verified, CEP trial license assigned via GCP (BeyondCorp roles + CEP project). OUs created: Managed Browsers and Users.
Endpoint Verification and Secure Enterprise Browser extensions force-installed. All five CEP connectors enabled: real-time URL check, upload, download, bulk text and print content analysis — each set to delay until analysis is complete.
Detectors All URLs = (.*) and Internal URLs word list created. Sensitive content storage and OCR analysis toggled on. Access level CEP-Unmanaged Profiles created (management_state != BROWSER_MANAGED).
Block Generative AI URL category, except Google Gemini. Test navigation to ChatGPT vs. Gemini.
Run test →Translucent watermark with user/device ID over matching pages. Verify rendering and ID differences.
Run test →Page content blacked out in screenshots and screen shares on matching URLs.
Run test →Audit event for every visited URL except the Internal URLs word list. Verify Chrome log events.
Run test →Block upload, download, paste and print of credit card data — except on Internal URLs.
Run test →Block pasting from incognito, other profiles or external applications into Chrome.
Run test →Block all downloads on non-corporate (unmanaged) profiles via context-aware access level.
Run test →Optional Chrome policy: block copying from managed profile into other profiles, incognito, or other apps.
Run test →Record the result per rule and device class as you test. Results live in this browser tab only — export to CSV before closing to add to the pilot KPI log.
| Rule | Managed browser | Managed profile (BYOD) | Unmanaged profile |
|---|