Secure Your Front-end

Request a Demo

Join the leading security teams protecting their digital supply chain with CellWall.

By submitting this form, you agree to our privacy policy and terms.

Guide

Set a zero-trust default for new scripts

Configure a reviewed project default for newly discovered browser resources, then validate and approve necessary exceptions.

Last reviewed September 12, 2026

A zero-trust default for newly discovered scripts blocks matching unapproved resources until a reviewer allows them at the appropriate policy scope. Use this posture only after validating enforcement prerequisites, essential website journeys, ownership, and recovery. It is a configurable browser control, not a guarantee that every unobserved or transformed execution path is blocked.

Global policies

The Global tab defines the project default: whether unknown resources are allowed or blocked, where applicable network requests may be sent, and which browser capabilities untrusted code may use. Provider and resource policies can inherit or override that default.

What to review

Use the following table to understand how each area supports the task.

AreaHow to use it
DefaultsCompare observed browser access with the resource’s documented business purpose and the journeys that depend on it. Observed use can inform a least-privilege baseline, but unobserved use may still occur in untested states.
RegionCompare observed browser access with the resource’s documented business purpose and the journeys that depend on it. Observed use can inform a least-privilege baseline, but unobserved use may still occur in untested states.
Browser capabilitiesCompare the observed browser access with the resource’s expected function before allowing or restricting it.

Set a zero-trust default for newly discovered resources

Enable Enforce Zero Trust (Block Unknown) to make Block the default for newly discovered third-party resources. Existing explicit provider or resource decisions remain more specific. Turn this on only after observing representative traffic, identifying essential resources, and preparing a tested allow and recovery plan.

Procedure

  1. 1.

    Open the correct project and page

    Use the project selector to choose the website you intend to review, then open Inventory in the left navigation. Confirm the organization, project, and monitored domain before interpreting a record or changing a control.

  2. 2.

    Record the effective policy

    Inspect Global, Provider, and Resource layers. Capture both the configured value at each layer and the resolved effective state, together with the critical journeys and current working behavior.

  3. 3.

    Behavior

    Read the configured value at Global, Provider, and Resource layers and identify the resolved effective state. Apply the narrowest approved change, validate critical journeys, and retain the previous state for recovery.

  4. 4.

    Validate the effective result

    Reload the policy view and confirm the resolved effective state. Exercise every affected critical journey and verify required browser access and network requests before expanding the change.

  5. 5.

    Document approval and recovery

    Record the policy layer, previous and new effective values, reason, approver, validation journeys, result, monitoring window, and exact recovery action.

Secure Your Front-end

Request a Demo

Join the leading security teams protecting their digital supply chain with CellWall.

By submitting this form, you agree to our privacy policy and terms.

Set a zero-trust default for new scripts | SiteWall Docs