Frequently asked questions
Application control for businesses FAQ
What is application control for businesses?
Application control is the use of organization-defined policies to determine which applications are allowed, blocked, reviewed, or otherwise governed on managed company devices. Policies can address individual applications as well as broader application categories.
Can a business block individual applications?
Yes. GuardSphere application policies can include explicit application allow and block rules. This gives administrators a way to create specific decisions for applications that require individual treatment.
Can businesses control entire application categories?
Yes. GuardSphere supports category-based application rules. Organizations can define allowed and blocked categories such as Productivity, Communication, Collaboration, AI Tools, Social Networking, Gaming, VPN/Proxy, and other categories represented in the application policy system.
What is the difference between an application allowlist and a blocklist?
A blocklist model generally permits applications unless a matching policy blocks them, while an allowlist model can be used when an organization wants application access to follow a more restrictive approved-access model. The appropriate approach depends on the organization's operating requirements.
Can application policies follow a work schedule?
GuardSphere policies support continuous and schedule-based scopes. This allows an organization to design policies around operational periods when scheduled enforcement is appropriate rather than treating every policy as an identical 24-hour rule.
Can a business control access to AI tools as a category?
Yes. AI Tools is represented as a category in GuardSphere's classification and policy system. An organization can therefore define its own policy for that category instead of relying only on a manually maintained list of individual AI applications or services.
Does application enforcement work identically on every platform?
No. Policy capabilities and enforcement mechanisms depend on the managed platform, deployment model, permissions, and the controls supported by the endpoint. GuardSphere applies policy through the capabilities available on supported managed devices rather than assuming every operating system behaves identically.