What we never do

The product is built so a person decides when a rule starts blocking. The screens, the mail, and the decision table all stop short of that click.

No automatic blocking

Rules start in count. Promote Copilot never changes the mode. A Promote card is a recommendation. Hold is a recommendation. Needs allowlist is a recommendation. Alerts, the weekly digest, the ready-to-promote email, the trial recap, Estate Brain, and the protection report are all read-only.

Adding a virtual-patch group puts that one group in count. It does not put it in block, and it does not change any other group.

You still click Promote. Nothing is blocked automatically.

No automatic rollback

If a promoted rule blocks real visitors, you switch it back to count or use Undo. The product does not watch the block log and undo for you. The confirm sentence says that explicitly.

No automatic allowlist

Copilot can tell you a path looks like your own form. It does not save the allowlist. It also refuses the cases where an allowlist would be the wrong tool: rate limits, login fraud, admin paths, a wide crawler, and an attack tool sitting on a sensitive path.

No invented certainty

A missing CloudWatch series is “not confirmed.” It is not shown as zero requests, and it is not treated as a quiet site that is safe to block. The trial recap does not invent a days-left number. Change history does not invent rows from before recording started. The virtual-patch card does not say you are exposed.

Related guides

More in this section