Reference
Policy fields and precedence
Reference configured values, inherited values, effective state, scope, and precedence.
Last reviewed September 12, 2026
Policy precedence is Global, then Provider, then Resource. Inherit uses the upstream value; explicit Allow or Block overrides it. Network region, destination restrictions, and browser capabilities may also inherit or be customized. The effective state is the resolved result, not simply the value shown at one layer.
What to review
Use the following table to understand how each area supports the task.
| Area | How to use it |
|---|---|
| Defaults | Read the configured value at Global, Provider, and Resource layers and identify the resolved effective state. Apply the narrowest approved change, validate critical journeys, and retain the previous state for recovery. |
| Inheritance | Distinguish the configured value at each layer from the effective value resolved through Global, Provider, and Resource precedence. |
| Overrides | Read the configured value at Global, Provider, and Resource layers and identify the resolved effective state. Apply the narrowest approved change, validate critical journeys, and retain the previous state for recovery. |
| Effective state | Read the configured value at Global, Provider, and Resource layers and identify the resolved effective state. Apply the narrowest approved change, validate critical journeys, and retain the previous state for recovery. |
Apply the reference
- 1.
Open a representative source record
Use the project selector to choose the website you intend to review, then open Policies in the left navigation. Confirm the organization, project, and monitored domain before interpreting a record or changing a control.
- 2.
Read the field with its context
Interpret the value with its entity type, project, observation window, state, and source link. Do not compare values collected under materially different conditions as if they were equivalent.
- 3.
Carry the definition into the workflow
Use the field to navigate or prioritize, then make the operational decision in the provider, resource, session, finding, policy, or evidence workflow that owns it.