Installing the Cisco Umbrella root CA onto the user's device is the action that accomplishes the goal of inspecting traffic without alerting end-users. This is because the root CA allows the user's device to trust the certificates issued by the Cisco Umbrella intelligent proxy, which acts as a man-in-the-middle for SSL sites on Umbrella's grey list. Without the root CA, the user's browser would raise errors when accessing those sites, as it would detect an untrusted certificate. By installing the root CA, the user's browser would accept the certificate and allow the traffic to be proxied and inspected by the intelligent proxy. References: * Enable SSL Decryption - Umbrella User Guide * SSL Decryption in the Intelligent Proxy - Cisco Umbrella * Cisco Umbrella Intelligent Proxy and SSL Decryption * Intelligent Proxy and SSL Decryption with Cisco Umbrella