---
title: Policy Exceptions
slug: policy-exceptions
docTags: 
createdAt: 2026-01-14T12:27:08.883Z
---

:::hint{type="info"}
Navigate to the sidebar menu: [Protection](docId\:AOavaXBxIc2KMEjwXC3Pi)**&#x20;&#x20;**> [Policies](docId\:i3Yd_tV8604vQf9JT7_CC), open a **Standard Policy** and select th&#x65;**&#x20;Exceptions** tab in the top navigation bar.
:::

## Overview

The **Exceptions** module serves as the final authority in your filtering hierarchy. It allows you to assign specific **Allow Lists** (Whitelists) or **Block Lists** (Blacklists) to override the general rules set in the Malware, Content, or Application modules.

- **Example:** You can block the entire "Social Networks" category in the *Content* tab but add a specific Exception to allow access to **LinkedIn** for the HR department.

## Interface Overview

The interface is designed to manage the link between your policy and your custom domain lists.

| ### <font color="#111827">Interface Element</font>       | ### Focus & Description                                                                                                  |
| -------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------ |
| **Search Bar**                                           | Located at the top left. Allows you to quickly find a specific exception group already assigned to this policy.          |
| <font color="#2563eb">`+ Assign exception groups`</font> | The blue <font color="#2563eb">`+ Assign exception groups`</font> button allows you to attach a new list to this policy. |
| **List View**                                            | Once groups are assigned, they will appear in the main area below the search bar (currently empty in the view).          |

## Understanding Exception Types

Exceptions are managed via "Groups" (lists of domains). Use this table to understand the two main types of overrides you can apply.

| ### Exception Type         | ### Function & Priority                                                                                                                                                                                        |
| -------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Allow List (Whitelist)** | Domains in this list are **always accessible**, even if they fall under a blocked category (e.g., *Malware* or *Social Networks*). This is primarily used to fix **False Positives** or grant specific access. |
| **Block List (Blacklist)** | Domains in this list are **always blocked**, even if the category they belong to is generally allowed. This is used to block specific unwanted sites without restricting the entire category.                  |

:::hint{type="warning"}
Subdomains and CDNs When adding exceptions, remember that modern websites often load content from multiple sources:

- **Subdomains:** Ensure you consider whether you need to allow just example.com or also drive.example.com.
- **CDNs**: Many sites host images and scripts on external domains (e.g., cdn-provider.net). If a Whitelisted site appears "broken" (missing images or styles), check if you need to allow its CDN domains as well.
:::

### Configuration & Logic

This page is used solely to **link** existing groups to the current policy.

- **To Assign a Group:** Click the <font color="#2563eb">`+ Assign exception groups`</font> button. This will open a dedicated selection window.
- **To Create/Edit Groups:** The actual lists of domains are managed in the global settings.

:::hint{type="info"}
Managing Groups Clicking the Assign button opens a separate interface for selecting and managing your custom lists: [New exception](docId\:XEsj0REJztBh0D1gxRUP7)&#x20;
:::

