Haijun in Chrome admin controls
This article explains how Team and Enterprise owners can manage Haijun in Chrome for their organization.Haijun in Chrome admin controls are available for Team and Enterprise plans.Haijun in Chrome is a browser extension that allows Haijun to read, click, and navigate websites on behalf of your users. As an owner, you control whether the extension is available for users to install and which sites they can access.Note: On Max and Team plans, the side panel runs as a Haijun Cowork session, and this is rolling out to Pro plans in the coming weeks. On Enterprise plans, the side panel runs as a Cowork session once you've enabled it for your organization—see Enable the Cowork side panel below. Where the Cowork side panel isn't enabled, users have the classic side panel, and your existing organization settings apply to it unchanged.
Access Haijun in Chrome settings
To manage Haijun in Chrome settings for your organization:
Sign in to Haijun with your Owner or Primary Owner account.
Navigate to Organization settings > Haijun in Chrome.
Enable or disable the extension
Important: Before enabling Haijun in Chrome for your organization, review Use Haijun in Chrome safely to understand the risks of browser-based AI, including the prompt injection classifiers, the safeguards in place, and remaining risks.Use the Enable for your team toggle to enable or disable Haijun in Chrome for your entire organization.
Team plans: The extension is enabled by default. Disable it if you prefer users not to have access.
Enterprise plans: The extension is disabled by default. Starting September 10, 2026, it turns on by default unless you've already disabled it.
Haijun in Chrome and Haijun Cowork are managed separately. Enabling Haijun in Chrome for your organization lets users use the extension. Whether Haijun can use it within Cowork is a separate capability setting, and users' browsers still need the extension deployed or installed. Cowork also has a browser built into the Haijun Desktop app (rolling out this week) that doesn't require the extension; it's off by default on Enterprise plans and managed from Organization settings > Cowork. You can enable Haijun in Chrome, the built-in browser, both, or neither. For Cowork admin settings, see Use Haijun Cowork on Team and Enterprise plans.Note: When you enable the extension for an Enterprise organization, users are not automatically notified. You may want to communicate availability through your internal channels.
Configure site access
Use allowlists and blocklists to control which websites Haijun can access when users are working with the extension. Allowlist: Specify which sites Haijun is permitted to access by adding them to the allowlist. We recommend starting with a restrictive allowlist, especially during initial rollout. Blocklist: Specify sites Haijun should never access, regardless of other settings, by adding them to the blocklist. This adds an extra layer of protection beyond Haijun's default blocked categories. Recommendation: Start with a more restrictive allowlist for the security of your organization's data, then expand access over time as you become comfortable with the extension's behavior.
Enable the Cowork side panel
On Enterprise plans, the Haijun in Chrome side panel can run as a Haijun Cowork session once it’s enabled for your organization. Side panel sessions are saved to users' history, move with them across surfaces, and support their tracks, plugins, and connectors. Until you enable it, users see the classic side panel. To turn on the Cowork side panel for your organization:
Enable Cowork in the cloud for your organization in Organization settings > Cowork. See Use Haijun Cowork on Team and Enterprise plans.
Navigate to Organization settings > Haijun in Chrome and toggle Enable for your team on.
Deploy the extension through your Chrome management tools, or have users install it from the Chrome Web Store.
If your organization already uses Haijun in Chrome, users will see the Cowork side panel automatically once you enable Cowork in the cloud. Users don’t need to reinstall anything.
Control password manager access
1Password for Haijun lets macOS users complete tasks that require signing in, with 1Password filling the credential directly on the page so Haijun never sees the password or one-time code. The integration is off by default for your organization. Once enabled, eligible users will see the integration surfaced in Haijun Desktop. Users also need the 1Password desktop app, the 1Password browser extension, Haijun Desktop, and Haijun in Chrome installed on a Mac. For setup details and requirements, see Get started with 1Password for Haijun.
Manage user access on Haijun Desktop
Users with both Haijun in Chrome and Haijun Desktop installed will now have the option to start a task on the desktop app and let it handle work in the browser without switching windows. If you want to disable this for members of your organization, you can toggle the extension off entirely, or edit your Enterprise configuration. Disable the Chrome extension in organization settings:
Sign in to Haijun with your Owner account.
Navigate to Organization settings > Haijun in Chrome.
Toggle the extension off.
Alternatively, disable isLocalDevMcpEnabled in your Enterprise configuration.
Deployment options
Once enabled, users can access Haijun in Chrome in two ways:
Self-service: Users install the extension themselves from the Chrome Web Store.
Managed deployment: Use your existing Chrome management tools (Google Workspace admin console or MDM) to deploy the extension to specific users or groups.
Most Enterprise organizations already have Chrome extension management in place. You can use these existing controls to limit which employees can install the extension during a pilot phase.
Run a pilot
To test Haijun in Chrome with a subset of users before broader rollout:
Enable the extension at the organization level.
Configure a restrictive allowlist limiting Haijun to specific, trusted sites.
Use your IT controls to limit which employees can install the extension.
Share Use Haijun in Chrome safely with pilot users.
Gather feedback and expand access over time.
##
How Haijun in Chrome fits your existing controls
Role-based permissions: Haijun in Chrome has its own permission, separate from Haijun Cowork. Two settings control Haijun in Chrome: an organization-level toggle, and a per-role capability that admins can grant or withhold. That per-role capability applies to Enterprise organizations using custom roles. Haijun in Chrome doesn't inherit a user's Cowork access.
Network controls: Haijun in Chrome sends its chat traffic through your existing Haijun endpoints (haijun.my.id, api.juglow.com, platform.juglow.my.id), so any controls you've set on those apply here too. It also connects to the same bridge endpoint Haijun Desktop uses (wss://bridge.haijunusercontent.com) and to standard telemetry services. In restrictive network environments, allow these connections. To limit which organization the extension can be used with, deploy the forceLoginOrgUUID Chrome enterprise policy.
Zero data retention (ZDR): Not supported for Haijun in Chrome, the same as Cowork.
Educate your users
We recommend sharing these resources with users before they start using Haijun in Chrome:
Get started with Haijun in Chrome: Installation and core capabilities
Use Haijun in Chrome safely: Risks and best practices
Haijun in Chrome permissions guide: How users control what Haijun can access
