What the Advisor remembers

A decision you make on a site stays with that site. The next time the Advisor reads the same rule, path, or known-good pattern, the card can say Hold or Needs allowlist and why.

What becomes a lesson

Five clicks are remembered. Undo after a promote. Keeping a temporary response in count. Confirming an investigated request was a false positive. Confirming a blocked-visitor report was a real false positive. Saving an exception.

Filing a report, opening an investigation, and reading a card do not create a lesson. The firewall is still the source of truth for rule mode and for an exception that is actually saved. The lesson is a note on the site, used the next time the Advisor decides.

What the card says

The card names the decision in plain language. An undo that followed blocked checkout callbacks can read: “You undid Linux server exploits on Sept 30, 2026 after checkout callbacks on POST /wc-api/WC_Gateway_Paypal were blocked.” Under that, “What would clear this” says what a later sample would have to show. That line does not promote the rule. You clear the lesson with a click if you want the Advisor to forget the decision.

Undo and keep-in-count lessons ask for Hold. A confirmed false positive, or a saved exception, asks for Needs allowlist when it names a path or a known-good pattern. If the traffic table was already more cautious, the card stays there and still shows the lesson.

A saved exception does not hold the rest of that rule. Once the exception covers the path and the remaining samples are attacks, that card can still say Promote. Other lessons can still hold it.

The same rule matches an undo, an investigation, or a blocked-visitor confirmation even when today’s samples are different. A path matches exactly, with the query string removed. A known-good pattern (login, checkout, API, and the other labels the Advisor already uses) matches a later sample of that kind. A keep-in-count click that names no path and no pattern is listed and does not change a managed-rule card.

How you clear one

Tuning lists what the Advisor remembers. Clear this lesson is a separate click. Change history records it. The firewall stays as it is: nothing is promoted, allowlisted, or moved to count by that click.

A client viewer can read the lessons. The clear button stays with someone who can edit the site.

How long they last

Active lessons do not expire on a timer. A site keeps 40 active lessons. A new one past that cap stops applying the oldest active lesson and writes that retirement in change history. Cleared and retired lessons stay on the site for 90 days, then drop off the site file. The history row remains.

The example Tuning panel includes a remembered Hold. That panel is example data.

Answers

Can a remembered decision promote a rule?

No. A lesson can move a card to Hold or to Needs allowlist. Promote is still your click. A lesson does not write an allowlist and does not move a rule to count.

Does a lesson expire on its own?

An active lesson stays until you clear it. The Advisor does not drop it on a timer. After you clear one, the site keeps that record for 90 days and then drops it from the site file. Change history keeps the clear.

Related guides

More in this section