FileGuard with the rest of the platform
How a FileGuard label sits with VisionX, GenGuard, Vault, and HostGuard on the same TAO agent.
FileGuard with the rest of the platform
FileGuard is not a second agent and not a second portal. It is the module that remembers a file. The modules around it already cover the screen, the browser, the credential, and the sign-in. The label gives those controls something specific to protect.
| Module | What it already does | What a FileGuard label adds |
|---|---|---|
| VisionX | Detects a phone, camera, or lens aimed at the screen | The document on that screen can already be a labeled file. VisionX still owns the visual exit. |
| GenGuard | Blocks forbidden text, keywords, and file transfers in the browser and on the workstation | The browser asks TAO before it accepts a paste, drop, or attachment, including an image or a PDF that carries the label |
| Vault & PAM | Rotates local passwords, can issue a timed local account, and encrypts File Vault with a PIN Trustity does not hold | A different store. FileGuard does not put the labeled file into the vault, and the vault password is not a FileGuard label |
| HostGuard IPS | Detects failed sign-ins and can block the source on the host firewall | The account path onto the machine. FileGuard assumes the person is already there and decides what they may do with the file |
Device groups under Managed devices still organize the fleet for VisionX, GenGuard-inside-TAO, and HostGuard. FileGuard policy itself is organization-wide. On the discovery page, those same device groups are only a filter for which stations you are looking at.
A practical split
Use the modules for the exit they actually see.
- Someone photographing the screen: VisionX.
- Someone pasting text or attaching a file in the browser: GenGuard, with the FileGuard label when the file has one.
- Someone copying a password or opening an encrypted vault file: Vault.
- Someone hammering a sign-in: HostGuard.
- A sensitive file sitting in Documents that nobody has labeled yet: FileGuard discovery, then an operator confirms the label.
* Ransomware protection, which would stop a process encrypting protected files, is scheduled for the first quarter of 2027. It is not required for the label, the discovery, or the browser block.
