Knowledge Base is one of two detection sources for Browser Defender's dangerous browsing alerts: it flags a domain or URL because your company policy already blocks it (via allowlist/blocklist or a remediation applied to a previous alert), or because it matches an external threat intelligence list that the product checks periodically. The other source, Live Detection, based on artificial intelligence, is documented separately. Knowledge Base alerts appear on the Knowledge Base tab of the Browser Defender > Browsing Alerts page; the toolbar on that page (search, export, archive) is not repeated here.
Requires Browser Defender active for your company, the Platform Administrator role, and the extension deployed to monitored users: without it, no alerts can be generated.
What this page does
The Knowledge Base tab lets you:
- Understand why a domain or URL was flagged — due to company policy or an external source.
- Explicitly allow (Trust) or block (Block) a domain, regardless of what Live Detection decides for the same domain.
- Set, in Setup, the company behavior applied to any browsing alert (see "Enforcement modes" below).
This tab is not intended for:
- Viewing the domain table or using Search/Export/Archive functions, which are shared across both sources (Browser Defender > Browsing Alerts page).
- AI detection logic (Live Detection).
- Configuring your company allowlist/blocklist (Setup).
- Managing password reuse or dangerous download alerts (Password Reuse, Dangerous Downloads).
Alert source: Company policy or External sources
When you open a domain's details, each URL shows which of the two sources flagged it:
| Value shown | Meaning |
| Company policy | An administrator has already blocked this page — via the allowlist/blocklist or with a remediation applied to a previous alert. |
| External sources | The page matches an external threat intelligence list that the product checks periodically. |
This value differs from the Source column shown at the page level in Browsing Alerts, which indicates which tab the alert came from (Live Detection or Knowledge Base): do not confuse the two fields.
Filter and apply a remediation
The Filter menu on this tab narrows the list to Browsing blocked or Browsing allowed:
From a domain's detail panel, you can apply one of these actions:
| Action | Effect |
| Trust / Untrust | Allows browsing to the domain, canceling any active Block (except some Company policy alerts — see the NOTE in the Enforcement modes section); does not affect the Live Detection status of the same domain. |
| Block / Unblock | Completely blocks browsing to the domain, with no option to dismiss the warning. |
| Advanced options | Opens the shared policy panel for domain/URL (password reuse, browsing, phishing, and downloads together). |
Enforcement modes (Browsing Protection)
The behavior applied when a browsing alert triggers — not just for Knowledge Base, but for all browsing alerts — is configured once, company-wide, in the Browsing Protection option:
| Mode | Description |
| Prevent | The user cannot access the page flagged by the alert. |
| Prevent with bypass | The user can still access the page, despite the alert. |
| Monitoring (for "Enterprise" V0.0.10+) | Browsing alerts are visible only to administrators; users see nothing. Requires the "Enterprise" extension generation (version V0.0.10 or later). |
| Off | Feature disabled. |
Knowledge Base has no separate toggle: the only way to disable it is to set Browsing Protection to Off, which disables browsing control and enforcement for both sources (Knowledge Base and Live Detection). Live Detection's AI alert generation remains governed by its own separate toggle, in Setup > Preferences > Advanced Settings.
NOTE: some alerts with Company policy origin always remain blocked, with no option to dismiss the warning, regardless of the blocking mode configured for your company. These alerts are not visually distinguishable in the list: you recognize them by behavior, because the Trust action does not remove the block.
Settings managed on other pages
Some elements that affect what is shown on this page are configured elsewhere:
- Domains and URLs always allowed or always blocked by company policy — managed by Setup > Safelist/Blocklist; this is the source of the Company policy values seen above.
- Company-level AI detection (applies only to Live Detection, not Knowledge Base) — can be enabled in Setup > Preferences > Advanced Settings.
Troubleshooting
| Symptom | Likely cause | Solution | Escalation |
| A domain I expected to be flagged hasn't appeared yet | External sources alerts depend on periodic updates of the external list | Wait for the next update, or block it immediately in Setup > Safelist/Blocklist | Contact support if it's still missing after a day. |
| The Monitoring mode is not available among Browsing Protection options | Requires the "Enterprise" extension generation (V0.0.10 or later) | Check the extension generation shown in Setup | Contact support. |