Promote, confirm, and undo

Promote moves one rule, or a batch you selected, from count to block. The click is yours. Undo puts it back in count. We do not auto-rollback.

Preview

Before the click, the card shows the rule, how many requests it counted, and a sample method and path when the log has one. If an allowlist is already saved, the preview says that path is not blocked.

A rule with counted hits asks you to confirm. The confirm sentence says matching requests will be stopped immediately, and that if real visitors are hit you switch the rule back to count. A bulk promote names each rule and its counted hits, and says they switch together.

A quiet rule (zero counted hits) does not add that risk sentence on the customer path. Operator sessions can still require a confirm.

Undo

Undo sets a promoted rule back to count. The protections editor says the same thing: switch a promoted rule back to Count if it blocked real visitors. That is the undo. We never auto-rollback.

After you promote, the next step is to watch security events. If real visitors are blocked, you undo. The product does not watch for you and flip the rule back.

A 403 is what a visitor can see after you have promoted a rule to block. It is not what they see on day one, while rules are in count.

Related guides

More in this section