Change history
Each site has a read-only history of protection changes. It lists what was recorded. It does not invent earlier events from the current WAF.
What a row can be
The page lists a rule added in count, Promote to block, Undo, an allowlist added or removed, a custom rule change, a go-live check that changed state, and support actions.
Support actions are read from the operator audit log. Owner and teammate events are appended when they happen. Recording of those owner events starts with the version that added this page. Changes before recording began are not recorded.
No protection changes are recorded for this site yet. Changes before recording began are not recorded.
What a row shows
The site page previews the latest 5 rows. The history page shows 25 at a time. Times are Eastern Time and UTC.
Support email addresses are masked. Full IP addresses are not stored. A Promote row includes the Promote Copilot recommendation from that click when the screen had one. If it was not captured, the row says the recommendation was not recorded.
The history is read-only. Changing a rule still happens on Tuning, not by editing a history row.