Roll-out playbook
A phased plan for deploying BeeSensible: pilot, second team, organisation-wide, with the deployment console as your checkpoint.
Acme Corp
5 of 10 seats used
| Name | Role | Status | Edge | Chrome | Desktop | Sign-in | Actions | |
|---|---|---|---|---|---|---|---|---|
| Sophie van Dijk | sophie@acmecorp.eu | Admin | Active | Manual | ||||
| Liam Jansen | liam.jansen@acmecorp.eu | Member | Active | Managed | ||||
| Priya Sharma | p.sharma@acmecorp.eu | Member | Active | Managed |
This is a phased plan for rolling out BeeSensible. A pilot first, then a second team, then everyone else: that way you tune configuration and communication before the whole organisation is watching. The deployment console in the dashboard follows the same phases (Configure, Validate pilot, Roll out broadly, Monitor) and tells you when the pilot is technically ready for more.
For the fastest path to one working pilot group, see Quick start for admins.
Phase 1: the pilot
Goal: confirm that BeeSensible works well in your environment and collect early feedback.
Pick a small group from a team where sensitive data comes past daily: HR, finance, legal, or support.
Before inviting them:
- Review the Default profile under Realtime Privacy → Profiles.
- Create a stricter or quieter profile where needed.
- Assign the relevant apps to that profile; see Apps and websites.
After the first period of use, review Realtime Privacy → Insights, with the 7, 30, or 90 day filters:
- Detections per platform: where sensitive data shows up.
- The most detected data types.
- The outcomes: how many detections were adjusted before sending, and how many were sent despite the warning.
Phase 2: a second team
Goal: confirm that your settings hold up outside the pilot team.
Apply what the pilot taught you. Refine profiles, discuss the app feedback, and check whether this team needs a different balance between visibility and noise. A support team sees different data than HR; sometimes it deserves its own profile.
Phase 3: organisation-wide
Goal: roll out to the rest of the organisation in a controlled way.
Before you go wider:
- Finish the most important detection profiles.
- Brief IT and support so they can answer questions.
- Tell employees why BeeSensible is coming and what they will notice.
What you tell employees
Explain briefly:
- What it does: sensitive data gets a highlight while you type, before you share it.
- What you do yourself: for each highlight you choose replace, mask, remove, or leave it. The choice stays with you; nothing is blocked.
- Why: less privacy and security risk in the tools where the work already happens.
- Where help lives: link to the user documentation.
Employees who know the purpose and the boundary treat the highlights more constructively.
Managed rollout with your own management tool
If you manage devices with Microsoft Intune or Group Policy, the extension installs by itself and employees sign in with their work account. The starting point is the deployment console in the dashboard: click your name at the bottom left, choose Organisation, and click Deployment guide.
Deployment console in the dashboardPick your deployment profile (Intune, Group Policy, or manual; Windows and macOS; Edge and Chrome) and work through the steps. The console generates the sign-in script and policy values, with the downloads to match.The console is more than an instruction page:
- Step 1, Provide work sign-in and step 2, Install the extension automatically come with the exact values and downloads for your management tool (the .ps1 sign-in script, .reg for Group Policy, .mobileconfig for macOS, .intunewin for the desktop app).
- Observed usage shows for how many members BeeSensible has actually landed, per browser and for the desktop app.
- Needs attention names whatever is holding the rollout back, each item with a likely cause, an action, and a reminder button.
- Firewall and proxy lists every host a network with outbound filtering has to allow.
Without device management, employees install the extension themselves via the store link in the invitation email and sign in once with their work account; the console shows the links and the counts for that route too.
When it stalls
The extension does not appear on managed devices
Have the device sync with your management tool and reload policy via chrome://policy or edge://policy. If the policy is there but the extension is not, check that the browser stores' download hosts are reachable and whether other browser management blocks the install. The deployment console walks you through these checks.
Invitation emails do not arrive
Email security sometimes holds them back. Ask IT to allow mail from BeeSensible.
Members stay on Pending
Send an install reminder from the members list or the deployment console; that works once per 24 hours per member. The console's Needs attention section shows who it concerns.
Lots of noise in one app
The profile for that app is too broad or too strict. Assign the app to a quieter profile, or set data types to Standard instead of Critical; see Apps and websites.
For anything not covered here, email hello@beesensible.eu.