Meet Willow (Formerly Webrix): One Governance Layer for Every AI Agent
Read More

Govern Claude on Chrome before it clicks the wrong button.

The policy layer for Claude in Chrome. Block the critical actions. Approve them in one click. Decide what Claude can touch, send, and submit. Per app. Per URL. Per user.

Trusted by
the risk

Claude in Chrome just emailed your client list to an outsider.

One prompt. The agent opens Salesforce, exports every account and what it pays as a CSV, attaches it in Gmail, and addresses it outside the company. The only thing in its way is a yellow "high risk" banner and an "act without asking" toggle.

Claude in Chrome acts as the user, carrying the user's cookies, tokens, and OAuth scopes across every open tab.

Gmail. Salesforce. Jira. Your admin consoles. Permissions are blanket, and the first misread instruction becomes the postmortem.

You don't need to ban it. You need to govern it.

What it does

Three controls. Built for security teams. Free for the org.

01

Approve

Nothing risky leaves the browser until a human says yes. Send, submit, post, pay, delete, publish, upload. Willow freezes the agent at the action and shows the full payload: recipient, body, attachment, URL. Deny. Allow once. Always allow. Nothing ships until someone signs off.

02

Scope

The agent's allowlist is too wide. Willow narrows it. Most tools hand the agent the keys to a whole domain and every subdomain. Willow scopes access down to the page and the data. The agent works in Salesforce, but the financial view stays locked. Per app, per URL, per action.

03

Guard

The agent only sees what you allow. Tell Willow the agent can't read email, and the inbox comes back blank. PII and secrets fade out before the agent ever reads them. Redaction happens in the browser, before the data reaches the model.

What you control

Policy at the action level. Not the tab level.

Per-app permissions. Read, edit, send, block.
Per-URL rules. Strict in production. Loose in staging. Different per environment.
Critical action triggers. Send, submit, post, pay, delete, share, publish, upload.
Human-in-the-loop approvals. Full action context before sign-off.
Pre-egress secret scanning. AWS keys, GitHub PATs, Stripe live keys, JWTs. Blocked before they leave the browser.
Shareable team configs. One link, every teammate, same policy.
Audit log export. Splunk and Loki ready.
SSO and team management. Okta, Azure AD. Connect when you're ready.
Policies
Approvals (4)
Audit Log
Google logo
Google Drive
READSHARE
Figma logo
figma.com
READCREATE
GitHub logo
github.com
READPUSHMERGE
AWS logo
aws.amazon.com
ALL
Jira logo
jira.com
CREATEDELETE
Slack logo
slack.com
DMPOST
How it works

Install once. Govern from day one.

Install the extension
1

Install the extension.

Chrome Web Store or your MDM. 30 seconds.

Pick a policy
2

Pick a policy.

Start with Willow defaults. Customize anytime.

Share with your team
3

Share with your team.

One link. Same rules. SCIM and Okta optional.

Watch from the Basecamp
4

Watch from the Basecamp.

Every action flows back. Splunk and Loki ready.

Why this matters

The OWASP LLM06 problem, solved at the browser.

Browser agents fail three OWASP LLM06 sub-categories at install time. Willow closes all three at the action layer.

OWASP LLM06 sub-categoryWhat it controlsClaude in Chrome defaultWillow for Chrome
Excessive FunctionalityWhich tools an agent can reachPer-user allowlist onlyOrg-managed, per-action
Excessive PermissionsWhat it can do inside each toolBlanket. Domain-level.Read / edit / send / block, per verb
Excessive AutonomyWhen, on what data, under what conditionsModel heuristicPolicy-enforced, human-in-the-loop, audit-logged
Built to deploy

Built like enterprise infrastructure. Shipped like a free tool.

Open source

Chrome Web Store and GitHub. Read the code yourself.

Runs locally

No prompt, action, or page content leaves the browser by default.

SSO ready

Okta, Azure AD, JumpCloud. Optional, when you're ready.

Enterprise governance at scale

2M+ tool calls governed every week.

SOC 2 Type II

Willow platform certified. GDPR-aligned.

Audit-ready logs

Splunk and Loki integrations available. Real-time.

The bigger picture

Chrome is one surface. The Willow Basecamp governs the rest.

Willow for Chrome is the forward outpost. The AI Basecamp is the platform underneath. One control plane for every AI agent your org runs.

Willow governance table

Your agents already work in your browser. Decide who's in charge.

FAQS

Does Willow for Chrome see what I'm doing in my browser?
No. It activates only when Claude takes an action. It does not read your tabs, keystrokes, or content otherwise.
Does it work with other AI browser agents?
Today, Claude on Chrome. ChatGPT Operator, Gemini in Chrome, and others are on the roadmap.
Can I deploy it to my whole org?
Yes. SCIM and Okta provisioning for team plans. The extension stays free.
Where's the source?
github.com/willow-ai/willow-for-chrome (placeholder until repo URL is fina
What does Willow do at the platform level?
Governs every AI agent (browser, IDE, MCP, custom) connecting to your internal systems. See the Basecamp.

Your agents are already in the wild.

Give them a Basecamp. Go from AI chaos to AI work, in minutes.