How to create a rule for app banners
You can use rules in the Push admin console to set conditions for how app banners are displayed to employees.
By using rules, you can:
Show a banner message to only specific employees or employee groups.
Set different banner modes for different groups.
Apply a banner based on an app’s sensitivity level, approval status, or custom label.
And others.
Common use cases include:
Blocking a recently breached app while you investigate the incident.
Blocking all unapproved apps.
Blocking Team A from using an app while allowing Team B to use it.
Showing one message to employees and a different one to administrators of a tool.
Creating an employee group for testing purposes and restrict app banners to just that group.
Create a rule
From the Controls page in the Push admin console, go to the App banners tile and then select Add rule to get started.
First, select the banner Mode. To see examples of each banner Mode, refer to this related help article.
Note: The mode type of Show no banner allows you to set conditions for when a banner will not show, which supports more complex scenarios. For example, you may wish to block all employees except your security team from using a specific app.
Then set the Scope (all employees, specific employees, or employee groups) and whether the rule applies to all apps, specific apps, or app attributes (e.g. sensitivity and approval status or custom labels).
Then write your message text and use the Preview banner option to see how it will look.
Push will automatically create a rule name using the combination of criteria you selected. You can edit the rule name if you like.
Rule order
You can control the order in which rules are applied by setting the rule order on the configuration slideout.
Rules are executed from the top down. Use the handlebars in the Order column to drag and reorder rules.
Sample rule logic
Here are some examples of how you can configure rules for common use cases:
Use case | Rule logic |
---|---|
Block an app while you investigate a potential incident. | Mode: Block Scope: All employees Using: Apps > Select the specific app under investigation |
Block all unapproved apps. | Mode: Block Scope: All employees Using: App attributes > App approval status > Not approved |
Exempt security administrators from being blocked by a banner while blocking everyone else, for a given app. | Mode: Block Scope: Employee groups > Exclude > Admins group Using: Apps > Select the specific apps |
Create a group for testing app banners before rolling out to everyone. | Mode: (Select the mode you want to test) Scope: Employee groups > Include > Test group Using: Apps > Select the specific apps |