webfilteringdatabase.com
Home Find Your Solution
Features
Domain Categorization API Real-Time Classification 59 Filtering Categories Offline Database (100M) ML Classification Content Classification
Industries
K-12 Schools Corporate Healthcare Government ISPs
Tools
Domain Lookup Bulk Categorization Category Explorer
Resources
Pricing API Documentation Login / Sign Up
Knowledge Base

Custom Policy Management

Build Granular Web Filtering Policies with 59 Content Categories, Per-User Controls, and Flexible Allow/Block Lists

Explore API

Why Custom Filtering Policies Matter

Every organization has unique web access requirements shaped by industry regulations, workforce composition, and security posture. A financial institution must block gambling and cryptocurrency trading sites for compliance staff while permitting access for research analysts. A school district needs age-appropriate filtering that differs between elementary, middle, and high school students — districts use these same policy controls to deploy K-12 content filtering for Chromebooks and iPads with per-grade rule sets. Off-the-shelf filtering profiles cannot accommodate these nuanced needs.

Custom policy management transforms our database of over 100 million categorized domains into a flexible enforcement engine. By combining 59 content categories into tailored policy objects, administrators can define precisely which web content is permitted, warned, or blocked for each segment of their user population. Policies can be layered hierarchically, inherited across organizational units, and scheduled to adapt throughout the business day.

The result is a filtering posture that aligns precisely with organizational goals rather than forcing compromises imposed by rigid, one-size-fits-all category lists. This approach reduces both over-blocking, which frustrates productivity, and under-blocking, which introduces risk.

Building Category Groups and Rule Sets

Organize 59 content categories into meaningful groups that map to your organizational structure

The foundation of effective policy management is the category group, a named collection of content categories that represents a conceptual access tier. Rather than managing 58 individual category decisions for every policy, administrators assemble reusable groups such as "Productivity content risks" (combining Social Media, Streaming Media, Gaming, and Online Shopping) or "Security Risks" (combining unsafe content, Spam URLs, and Cryptomining).

Category groups support set operations: unions combine multiple groups, intersections narrow focus, and exclusions carve out exceptions. A "Restricted Content" super-group might union "Adult Content," "Violence," and "Drugs" while excluding a curated list of harm-reduction educational sites. Groups can reference other groups, enabling hierarchical composition without duplication.

Each category group carries a default action (allow, block, warn, or log-only) and an optional redirect URL for blocked requests. When a domain lookup returns one of the 59 categories, the policy engine evaluates which groups contain that category and applies the highest-priority action. This layered evaluation ensures that security-critical blocks always take precedence over permissive productivity rules.

Per-User, Per-Group, and Per-Network Policies

Apply the right policy to the right entity at the right scope

1

User-Level Policies

Assign filtering policies directly to individual users identified by authentication tokens, IP addresses, or device certificates. User-level policies are ideal for executives who need unrestricted research access, IT staff who must reach security tool sites, or employees on performance improvement plans who require tighter controls. Each user inherits their organizational policy by default but can receive overrides that add or remove specific category permissions without duplicating the entire rule set.

2

Group-Level Policies

Map filtering policies to directory groups imported from Active Directory, LDAP, or SAML identity providers. When the sales department needs access to social media for prospecting while engineering requires access to developer forums and code repositories, group policies ensure each team gets the access profile that matches their workflow. Group membership changes propagate automatically, so onboarding and offboarding require no manual filtering adjustments.

3

Network-Level Policies

Define policies that apply to entire subnets, VLANs, or site locations. Guest Wi-Fi networks can enforce restrictive policies blocking adult content and high-bandwidth streaming without requiring authentication. Branch offices in jurisdictions with specific regulatory requirements can have location-appropriate filtering applied at the network layer, ensuring compliance even for unmanaged devices connecting to the corporate network.

4

Policy Inheritance and Precedence

Policies follow a clear inheritance chain: global defaults are overridden by network policies, which are overridden by group policies, which are overridden by user policies. At each level, rules can be additive (grant extra access) or restrictive (remove access). A precedence weight system resolves conflicts when a user belongs to multiple groups with competing rules. Administrators can visualize the effective policy for any entity through the policy simulation endpoint.

Allow Lists, Block Lists, and Override Controls

Custom Allow Lists

Allow lists guarantee access to specific domains regardless of their category classification. When a legitimate business partner's domain is categorized under a blocked category, an allow list entry ensures uninterrupted access without weakening the broader category block. Allow lists support exact domain matches, wildcard patterns (*.example.com), and regular expressions for complex matching scenarios. Entries can be scoped to specific policies, groups, or users, and each entry carries an expiration date to prevent permanent exceptions from accumulating unchecked.

Custom Block Lists

Block lists enforce denial of access to specific domains even if their category would normally be permitted. This is essential for blocking newly discovered restricted content domains before they appear in the main classification database, preventing access to competitor intelligence sites during sensitive M&A periods, or enforcing HR-mandated restrictions. Block list entries take absolute precedence over allow lists and category rules, ensuring that critical security and compliance blocks cannot be accidentally overridden.

Temporary Override Tokens

Override tokens allow authorized users to bypass a block for a limited time window. When a researcher encounters a blocked site that is essential for their current project, they can request a time-limited override through a self-service portal or manager approval workflow. The token grants access for a configurable duration (typically 15 minutes to 8 hours), logs all activity during the override period, and automatically revokes access when it expires. This balances security enforcement with operational flexibility.

Time-Based Scheduling and Adaptive Policies

Policies that evolve throughout the day, week, and calendar year

Business Hours Enforcement

Define separate policy profiles for business hours and after-hours. During work hours, social media and streaming may be blocked to maintain productivity. After 6 PM, the same users can enjoy relaxed filtering that permits entertainment categories. Transition is seamless and requires no user action.

Day-of-Week Schedules

Accommodate organizations with variable schedules. Retail companies might enforce strict filtering on weekdays but relax policies on weekends when only warehouse staff are active. Educational institutions can apply exam-period restrictions that tighten access to entertainment and social media during testing windows.

Calendar-Driven Policies

Integrate with corporate calendars to trigger policy changes during company events, holidays, or compliance audit windows. Automatically enable stricter filtering during regulatory examination periods, relax policies during company social events, or enforce training-mode filtering during onboarding weeks.

Emergency Lockdown Mode

Instantly switch all policies to a pre-configured emergency profile during security incidents. One API call can restrict the entire organization to essential business sites only, blocking all uncategorized and non-critical domains until the security team resolves the content risk and restores normal operations.

Administration, Auditing, and Compliance

Maintain visibility and accountability across your entire policy infrastructure

Role-Based Admin Access

Delegate policy management through granular admin roles. Global administrators can modify any policy, while departmental admins can only adjust policies within their scope. Read-only auditors can inspect policy configurations and logs without modification rights. All admin actions are authenticated and logged for accountability.

Version History and Rollback

Every policy change creates a versioned snapshot with timestamp, author, and change description. If a policy update causes unexpected access disruptions, administrators can instantly roll back to any previous version. Diff views highlight exactly what changed between versions, making audit reviews efficient and thorough.

Compliance Reporting

Generate reports showing policy configurations, exception lists, override usage, and block statistics organized by category, user group, or time period. Pre-built report templates align with CIPA, HIPAA, PCI-DSS, and SOX compliance frameworks. Scheduled reports can be automatically delivered to compliance officers via email or SFTP.

Policy Simulation and Testing

Before deploying a policy change to production, test it against real traffic patterns using the simulation API. Submit a list of domains and user contexts to see exactly how the proposed policy would classify each request. Compare simulation results against current policy behavior to identify unintended access changes before they impact users.

API-Driven Policy Management

Automate policy lifecycle through comprehensive REST endpoints

RESTful Policy CRUD

Create, read, update, and delete policies through standard REST endpoints. JSON payloads define category groups, actions, schedules, and scope bindings. Idempotent operations ensure safe retries, and ETags prevent conflicting concurrent modifications by multiple administrators.

Directory Sync Integration

Automatically synchronize organizational units, groups, and user attributes from Active Directory, Azure AD, Okta, or any SCIM-compliant identity provider. Policy bindings update in real time as group memberships change, eliminating manual maintenance and ensuring access controls reflect current organizational structure.

Webhook Notifications

Receive real-time notifications when policies are modified, overrides are granted, or block thresholds are exceeded. Integrate with Slack, Microsoft Teams, PagerDuty, or custom endpoints to keep security and compliance teams informed of policy changes as they happen.

Infrastructure as Code for Filtering Policies

Treat filtering policies as infrastructure by storing policy definitions in version-controlled repositories. Our API accepts declarative policy documents in JSON or YAML format, enabling teams to use familiar DevOps workflows including pull request reviews, automated testing, and CI/CD deployment pipelines. Terraform and Ansible providers are available for organizations that manage their infrastructure through these tools — an approach that makes web filtering at enterprise scale reproducible and auditable.

This approach brings software engineering best practices to policy management: changes are peer-reviewed before deployment, rollbacks are a single git revert away, and the entire policy history is captured in commit logs. For regulated industries, this provides an auditable chain of custody for every filtering decision.

Ready to Build Custom Filtering Policies?

Leverage 100 million categorized domains and 59 content categories to create filtering policies tailored to your organization.

Get Started with Policy Management