Subscribe to the Non-Human & AI Identity Journal
Home Glossary Cyber Security Extension inventory
Cyber Security

Extension inventory

← Back to Glossary
By NHI Mgmt Group Updated August 2, 2026 Domain: Cyber Security

Extension inventory is the process of identifying, reviewing, and controlling browser add-ons installed on endpoints. It reduces shadow risk by making sure browser extensions are approved, least-privileged, and visible to security teams before they become a hidden path to sensitive data.

Expanded Definition

Extension inventory is more than a simple list of browser add-ons. In security practice, it is the ongoing process of discovering which extensions exist, understanding what each extension can access, and deciding whether that access is justified for the business use case. For NHI Management Group, the important distinction is that browser extensions can behave like persistent third-party code running inside a user’s trusted session, which makes them materially different from ordinary installed software.

The term overlaps with endpoint governance, application control, and identity risk management because extensions often request permissions that touch browsing history, page content, session data, and in some cases authentication flows. Guidance varies across vendors on how much telemetry is enough for approval, but the security principle is consistent: security teams need visibility before an extension becomes a hidden trust dependency. This aligns closely with control expectations in NIST SP 800-53 Rev 5 Security and Privacy Controls, especially where software is authorised, monitored, and reviewed over time.

The most common misapplication is treating extension inventory as a one-time audit, which occurs when organisations approve add-ons at rollout but fail to track later permission changes, new installs, or user-enabled extensions.

Examples and Use Cases

Implementing extension inventory rigorously often introduces operational friction, requiring organisations to balance user productivity and browser flexibility against tighter approval, review, and removal workflows.

  • Security teams build a recurring inventory of extensions across managed browsers, then flag any add-on that requests broad page read access or access to cookies and authentication-related content.
  • IT and IAM teams approve only a narrow extension allowlist for employees who handle sensitive data, while blocking unreviewed add-ons that could intercept credentials or session tokens.
  • Endpoint management tools detect when a user installs a new browser extension outside policy, creating a review queue before the add-on is permitted to remain active.
  • Analysts investigate a suspicious data exposure event and trace it to a browser extension that had legitimate installation status but excessive permissions and weak vendor transparency.
  • Governance teams classify extensions by risk, then require periodic recertification so that stale or abandoned add-ons do not remain trusted by default.

Browser extension risk is also addressed in broader supply-chain and endpoint guidance from the CISA Secure Browser Guidance, which reinforces the need to manage browser-based attack surface deliberately rather than assuming the browser is a low-risk workspace.

Why It Matters for Security Teams

Extension inventory matters because browser extensions can quietly expand the attack surface inside a managed endpoint without triggering the same scrutiny as native applications. If a team cannot account for installed add-ons, it may miss shadow access to web mail, SaaS consoles, internal portals, and identity provider sessions. That becomes especially important where extensions can observe or influence user actions in environments that support privileged access workflows, help desk operations, or admin console activity.

For identity security, the issue is not just software control but trust in the browser as an access layer. An extension with excessive permissions can weaken session protection, expose sensitive tokens, or create an indirect path into accounts that were otherwise well protected. That is why inventory, review, and removal need to operate as a lifecycle control, not a periodic housekeeping task. OWASP guidance on emerging application risk is useful here as a mindset, because hidden capabilities often matter more than declared intent.

Organisations typically encounter the consequences only after a browser-based data leak, suspicious account activity, or third-party extension compromise, at which point extension inventory becomes operationally unavoidable to contain the exposure.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack surface, NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST SP 800-63 set the technical controls, and ISO/IEC 27001:2022 define the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.PS-1Asset and software management expectations support visibility into browser extensions.
NIST SP 800-53 Rev 5CM-8System component inventory maps well to browser extension discovery and review.
OWASP Non-Human Identity Top 10Browser add-ons can expose secrets and session material used in NHI workflows.
NIST SP 800-63AAL2Extension risk affects assurance when browser sessions are used for authenticated access.
ISO/IEC 27001:2022A.8.9Configuration management supports control of browser add-ons as endpoint settings.

Treat extensions that can access tokens or sessions as privileged components needing explicit approval.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on August 2, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org