Example dataInvented site example.edu. Not a customer. Not live traffic.
Example Promote Copilot
The WAF that tells you what's safe to block.
Rules start in count. After about 24 hours, Promote Copilot reads the window and recommends Promote, Hold, or Needs allowlist — with the evidence, the "If you promote" preview, and an exact-path allowlist draft when a real workflow is matching. You still click Promote. It never flips a rule to block on its own.
The Promote and Undo buttons below are that human click. On this example they do not change a rule.
- PromoteQuiet in the window — safe to start blocking after you click.
- HoldStill watching or noisy — keep counting.
- Needs allowlistLooks like real visitors — allow that traffic first.
Example dataInvented counts for example.edu. Not a customer. Not live traffic.
Promote Copilot
Tuning is count → promote. Rules start in count. After 24 hours, Promote Copilot names what's safe — you click once. Nothing auto-blocks. It never flips a rule to block on its own.
The 24-hour window is over. Promote quiet rules, or hold / allowlist anything noisy.
Rule-based notes from this count window. You still click once.
1 ready to promote · 1 needs an allowlist · 1 on hold.
Linux server exploits (linux_exploits) counted 12 hit(s) in the 24-hour window, and every sample path looks like a probe (GET /.env).
Promoting blocks those probe shapes, not a known-good login or payment path. You still click Promote — Copilot does not flip the rule.
- 24h window
- Counted 12
- GET /.env
- 3GET /.env
- 2GET /wp-config.php
- 1GET /.git/config
Sample rows only. Counted 12 is the full 24h window.
- GET /.env · 203.0.113.xx
- GET /wp-config.php · 203.0.113.xx
- GET /.git/config · 198.51.100.xx
- 12 counted request(s) on Linux server exploits in this 24h window would start being blocked.
- Includes GET /.env.
- Only this rule switches to block. Undo puts it back in count — we do not auto-rollback.
Low confidence to promote — review the evidence first. You still click once.
Common attacks (OWASP) (common_attacks) flagged a large share of requests (620 counted) in the 24-hour window.
That pattern often includes real campus traffic — LMS, registration POSTs, monitoring, CMS, or SSO paths. Keep it in count until you confirm the hits are abuse, not students or editors. Copilot will not promote this for you.
- 24h window
- Counted 620
- GET /search
- 2GET /search
- 1GET /calendar
- 1GET /news/story
Sample rows only. Counted 620 is the full 24h window.
- GET /search · 203.0.113.xx
- GET /calendar · 203.0.113.xx
- GET /news/story · 198.51.100.xx
Low confidence to promote — review the evidence first. You still click once.
Known exploits (known_exploits) counted POST /saml/acs in the 24-hour window.
It looks like SSO. Allow that path before you promote. You still click — Copilot does not block.
- 24h window
- Counted 64
- POST /saml/acs
- 4POST /saml/acs
Sample rows only. Counted 64 is the full 24h window.
- POST /saml/acs · 192.0.2.xx · SSO
False-positive risk: SSO.
Allow this path before you promote. The rule stays in count until you click.
- Allows POST /saml/acs exactly.
- Other paths still hit your managed rules.
- This does not turn a managed rule off. Count and block stay as they are until you promote.
Known exploits counted this traffic. The draft allows only what the preview says.
- Review the draft. It matches the preview.
- Save to add it. Nothing is written before that.
- Come back here. The decision updates after the save.
Blocked counts are the current 24h window. Sampled blocks are log rows at or after the promote time. Undo is one click back to count. We never auto-rollback.
- Blocked 27 in 24h
- Sampled blocks since promote: 2
No known-good paths in the sampled blocks since promote.
Questions
Is this a real customer?
No. This page is example data: an invented site, invented counts, and masked sample IPs. It is not a customer and not live traffic.
Does Promote Copilot block traffic on its own?
No. It recommends Promote, Hold, or Needs allowlist and explains why. You still click Promote. It never flips a rule to block on its own.
What is the Needs allowlist draft on this example?
The example shows POST /saml/acs, an SSO path, as the exact path to allow before that rule is promoted. Copilot does not write the allowlist. You still decide.
See it on your site
Rules start in count. After 24 hours, your dashboard shows what's safe to block — one click.
Start a 14-day trialCard at Stripe checkout. Cancel before the 14-day trial ends and you won't be charged.
$150/site/mo after the trial
What is Promote Copilot? · How count mode works · What's safe to block · Pricing