VisualRunner Enterprise Extension¶
VisualRunner Enterprise is a separate build of the browser extension for organisations whose IT or security team won't approve the standard Chrome Web Store version. It requests no host access, no debugger permission, and no cookie access — the worst-case install warning is "read your browsing activity on the tab you use it on". All screenshot capture runs on VisualRunner's own infrastructure.
This is a hand-sold Enterprise feature, enabled per workspace. Contact us (
support@visualrunner.comor your account contact) to start.
How it's different from the standard extension¶
| Standard (Chrome Web Store) | Enterprise | |
|---|---|---|
| Host access | <all_urls> (requested per capture) |
none |
debugger (the "started debugging this browser" banner) |
required | removed |
cookies, downloads, tabs |
required | removed |
| Notifications / alarms | required | optional — your IT can decline |
| Where captures run | in your browser | on VisualRunner's servers |
| Free Local (no-account) mode | included | not included — sign-in only |
| Distribution | Chrome Web Store | signed .crx we host, you force-install |
| Updates | Chrome Web Store | our update feed; you can pin versions via your own policy |
Language and element detection still run against the tab you're on (activeTab + scripting,
the low-alarm "when you click the extension" permissions). The side-panel UI is otherwise the
same as the standard extension.
Getting it deployed¶
- We enable the feature on your workspace and send your IT team a signed
.crx, the extension ID, and an update-feed URL. - Your IT force-installs it by ID through Google Admin console, Windows GPO, Intune, or Jamf — the same mechanism you use for any managed extension.
- Optionally, your IT sets a managed policy pinning the extension to your VisualRunner
workspace (
workspaceId). Once pinned, the extension can't be pointed at any other tenant, even by a signed-in user who belongs to other workspaces. - Your team members sign in inside the extension's side panel and start capturing. If a workspace member doesn't yet have access, an admin can send them a register link that turns on the feature (or provisions a fresh workspace) when they open it.
Windows (Group Policy / registry)¶
Extension ID: ljibdgcdnpkjlbgnkabomdngebgpamkk. Update feed:
https://ext.visualrunner.com/updates.xml.
Force-install (step 2), via the GPO console —
Computer Configuration → Administrative Templates → Google → Google Chrome → Extensions →
Configure the list of force-installed apps and extensions (Edge: same path under
Microsoft Edge) — add:
ljibdgcdnpkjlbgnkabomdngebgpamkk;https://ext.visualrunner.com/updates.xml
Registry equivalent, for deploying without the GPO console (e.g. via a login script or your own MDM):
| Browser | Key | Value name | Value data |
|---|---|---|---|
| Chrome | HKLM\SOFTWARE\Policies\Google\Chrome\ExtensionInstallForcelist |
1 |
ljibdgcdnpkjlbgnkabomdngebgpamkk;https://ext.visualrunner.com/updates.xml |
| Edge | HKLM\SOFTWARE\Policies\Microsoft\Edge\ExtensionInstallForcelist |
1 |
ljibdgcdnpkjlbgnkabomdngebgpamkk;https://ext.visualrunner.com/updates.xml |
If your network filters extension updates by host, allowlist https://ext.visualrunner.com — it
serves both the update manifest and the signed .crx files.
Workspace lock (step 3) — set your VisualRunner workspace ID (Settings → General) as a
3rdparty managed-policy value for the extension:
| Browser | Key | Value name | Value data |
|---|---|---|---|
| Chrome | HKLM\SOFTWARE\Policies\Google\Chrome\3rdparty\extensions\ljibdgcdnpkjlbgnkabomdngebgpamkk\policy |
workspaceId |
<your workspace ID> |
| Edge | HKLM\SOFTWARE\Policies\Microsoft\Edge\3rdparty\extensions\ljibdgcdnpkjlbgnkabomdngebgpamkk\policy |
workspaceId |
<your workspace ID> |
With this set, anyone who signs in with an account outside that workspace sees a "locked to another workspace" screen instead of the capture UI, even though the extension itself is installed.
To verify: open chrome://extensions and confirm the extension shows Installed by enterprise
policy with no "Errors" badge, then chrome://policy → Reload policies and confirm
ExtensionInstallForcelist and the 3rdparty workspaceId both show as OK. To remove the
extension, delete the ExtensionInstallForcelist entry (and the 3rdparty policy, if set) — the
browser uninstalls it on its next policy refresh, and locally stored session tokens are cleared.
macOS (Jamf configuration profile) and Linux (managed JSON policy) use the equivalent
ExtensionInstallForcelist / 3rdparty policy keys through their own platform's configuration
mechanism — talk to your VisualRunner contact if you need those snippets spelled out.
What your security team can rely on¶
- Manifest V3, no remotely-hosted code, no
eval, non-obfuscated bundle. - No host permissions, no
debugger, nocookies. The Free Local capture path (and itsdebuggeruse) is not present in this build at all. - No third-party analytics in the build.
- All capture runs on VisualRunner infrastructure with SSRF protection and audit logging; the only page data the browser sends is the target URL and, for the element picker, a CSS selector you chose.
- Distribution is controlled by us (signed, self-hosted); you control rollout and can pin versions through your own MDM policy.
- The extension can be locked to a single workspace via
chrome.storage.managed.
See also¶
- Chrome Extension — the standard build
- Enterprise — custom plans and the other hand-sold capabilities
- Private Runner — the companion Enterprise feature for capturing internal environments