What's safe to block on a WAF?

The WAF that tells you what's safe to block. Campus and agency forms have to keep working. Managed rule packs that deny on day one cause false positives. ProtectMyWebsite starts rules in count. After about 24 hours, your dashboard shows what's safe to block — one click. Promote Copilot adds a plain-English Promote, Hold, or Needs allowlist recommendation and why. You still decide.

How count → promote works

1. Rules start in count (log / observe). Nothing is blocked on day one.

2. Real traffic runs for about 24 hours.

3. Your dashboard surfaces what's safe to block.

4. You click once to promote.

That's how ProtectMyWebsite runs it: Rules start in count. After 24 hours, your dashboard shows what's safe to block — one click.

Block-first is how you get false positives on admissions forms, CMS editors, and monitoring scanners. Count-first means you see the hits, then tighten.

What Promote Copilot adds

Promote Copilot reads your count window and names Promote, Hold, or Needs allowlist — plus why, in two to four sentences.

It also shows evidence from that window: hit count, a sample path and method, and the rule id.

It does not flip a rule to block on its own. You still click once.

If the rewrite is unavailable, the same dashboard still shows the recommendation from the count window. You still decide.

Promote vs Hold vs Needs allowlist

Promote: the hits look like junk or abuse. Promoting is a low-regret block after you click.

Hold: the window is mixed, sparse, or timed oddly. Keep counting and wait.

Needs allowlist: legitimate traffic is matching the rule. Add an Allow match or tighten scope first. Copilot does not write the allowlist. Re-check the count window before you promote.

Campus and agency form examples

Higher-ed admissions and registration: a managed pack can misfire on unusual field names. Count first. If Copilot says Promote, the hits were junk — one click. If it says Needs allowlist, scope the form path first.

LMS and SSO callbacks: login and callback paths look noisy. Copilot will often Hold or Needs allowlist until the window is clean.

CMS editors: admin and editor POSTs can resemble exploit strings. Count, then allowlist the editor path if Copilot says so — do not promote into a locked-out newsroom.

Agency permitting: a blocked permit form is an outage the public notices. Same pattern — count, read Copilot, then you click.

Monitoring scanners: uptime and vulnerability scanners that are not on your allowlist yet will light up rules. Needs allowlist first, then re-check.

FAQ

What's safe to block? A rule that fired on junk or abuse in the count window — not on your own forms, editors, or scanners. That's a Promote.

How do I promote a rule? After about 24 hours, the dashboard names what's quiet. You click once. Nothing flips on its own.

How do count mode and Promote Copilot work together? Count mode observes. Copilot explains Promote, Hold, or Needs allowlist in plain English, with why and evidence. You still click once.

How do campuses reduce false positives? Start in count so registration and financial-aid forms stay up. Promote only junk. Allowlist real LMS, SSO, editor, and scanner traffic first.

Does Promote Copilot flip rules to block on its own? No. It explains. You still click once.

Start here

Self-serve is $150/site/mo with a 14-day trial. Campus Estate is quote on request — Talk to sales team. We do not publish Estate list prices.

Related

See what's safe to block — then start in count