GPR-007 · low risk
Allow a reviewed domain
Allow network actions to a domain that your team has explicitly reviewed and approved.
Decision
allow
Matcher
domain = trusted.example.com
Reviewed
2026-08-09
Safe test cases
matching synthetic case
domain = trusted.example.com → allow
different benign synthetic case
domain = benign-trusted.example.com → unmatched
Limitations
- Replace the example domain with an organization-reviewed destination before applying.
Review before applying
This recipe is a starting point, not a universal security policy. Open it in Policy Studio, replace example identifiers where necessary, review scope and blast radius, simulate where supported, and use the normal approval flow before enforcement.
Recipe SHA-256: 4d8e6005dd31519872a2ec8e9a15bba7ec7fd7490daf5174f3ffb352ab295c1e
When a policy is saved and delivered through Guard Cloud, it uses the existing Guard policy-bundle compiler. If the policy-bundle signing key is configured, that compiler produces an RSA-PSS-SHA256 signed bundle that local Guard verifies before applying.