Application visibility and control
The console classifies applications using documented names and addresses, showing per-zone volumes and the unclassified share. Zone policies can allow, block or block and report categories and applications. Per-client detail stays disabled until an administrator enables it; metadata handling requires attention to privacy.