Allowlists
An allowlist tells one rule to skip a path you recognize. It is how a form, login, or API can stay up when you later promote that rule.
When the card asks
Needs allowlist is the outcome for signature rules whose samples include a known-good path: login, CMS, API, payment, SSO, or a single crawler or monitor path. The card’s “what would change this” line is: add an exact-path allowlist if this is your own form.
Copilot suggests a shape from the sampled path and method. It does not invent IP addresses, tokens, or email addresses. You save the allowlist yourself. Copilot does not write it.
Some holds are explicit about not using an allowlist. Rate limits never ask for one. An allowlist on a login-fraud rule would turn that rule off for the page, so the card says keep it in count. Copilot will not allowlist an admin path. A search crawler on several ordinary paths is Hold, not an allowlist of the whole site. An attack-tool user agent on a known-good path is Hold, because an allowlist would exempt the tool.
After it is saved
The allowlist is not a block. Promote is still a separate click. If the saved rule covers the known-good samples and what remains is an explained attack, the card can say Promote. If the count is still larger than the sample, or a non-attack path remains, or a bot rule has only the allowed path left, it stays Hold.
Removing an allowlist is a recorded change. It does not by itself change the rule from count to block.