Guide
Configure provider and resource policies
Apply or inherit policy at provider and resource scope, including controlled blocking and restoration.
Last reviewed September 12, 2026
Provider policies
The Providers tab applies policy decisions to all observed resources associated with a provider. It shows provider identity, resource impact, last policy update, and effective Allowed or Blocked state. Edit a provider to inherit the global default or set a provider-specific action, network boundary, and capability policy.
What to review
Use the following table to understand how each area supports the task.
| Area | How to use it |
|---|---|
| Inherit | Distinguish the configured value at each layer from the effective value resolved through Global, Provider, and Resource precedence. |
| Allow | Read the configured value at Global, Provider, and Resource layers and identify the resolved effective state. Apply the narrowest approved change, validate critical journeys, and retain the previous state for recovery. |
| Block | Read the configured value at Global, Provider, and Resource layers and identify the resolved effective state. Apply the narrowest approved change, validate critical journeys, and retain the previous state for recovery. |
| Custom overrides | Read the configured value at Global, Provider, and Resource layers and identify the resolved effective state. Apply the narrowest approved change, validate critical journeys, and retain the previous state for recovery. |
Block or restore a provider
Block a provider when an incident, unexpected behavior, or unacceptable performance makes temporary containment appropriate and the response owner accepts the impact. Record the current inherited state, apply Block, validate containment and website behavior, then restore Inherit or Allow after the exit criteria are met.
Procedure
- 1.
Open the correct project and page
Use the project selector to choose the website you intend to review, then open Providers in the left navigation. Confirm the organization, project, and monitored domain before interpreting a record or changing a control.
- 2.
Record the effective policy
Inspect Global, Provider, and Resource layers. Capture both the configured value at each layer and the resolved effective state, together with the critical journeys and current working behavior.
- 3.
Incident use
Read the configured value at Global, Provider, and Resource layers and identify the resolved effective state. Apply the narrowest approved change, validate critical journeys, and retain the previous state for recovery.
- 4.
Recovery
Preserve the failing state, test the most local dependency first, and make one reversible change at a time. Reproduce the original journey after each check and stop when the evidence points to a different layer.
- 5.
Validate the effective result
Reload the policy view and confirm the resolved effective state. Exercise every affected critical journey and verify required browser access and network requests before expanding the change.
- 6.
Document approval and recovery
Record the policy layer, previous and new effective values, reason, approver, validation journeys, result, monitoring window, and exact recovery action.
Resource policies
The Resources tab is the most specific policy view. Search or filter resources, compare observed capabilities and potential risk, review effective status and network policy, and edit only the resource that needs a narrower decision than its provider.
What to review
Use the following table to understand how each area supports the task.
| Area | How to use it |
|---|---|
| Apply decisions to an individual resource | Confirm the URL or domain, provider association, first and last observation, and the project in which the entity was recorded. Open the linked detail record; a display name or enrichment label is not proof of ownership or approval. |
Configure a resource policy
Open a resource policy, choose Inherit, Allow, or Block, and configure only the required network and browser-capability overrides. Recently observed external domains can inform a restricted destination list, but an operator must confirm which destinations are necessary.