▶
ExecutionTrigger
Automation/Browser/Navigation
Restricts where Go To and Execute Browser Action Plan may navigate in this session: URL schemes, domain allow and block lists, and private network addresses. The final URL after redirects is checked too; a blocked landing page is left for about:blank and the node fails. Requests the page makes on its own are not filtered.
Scores range from 0 to 10. Higher values mean more impact, exposure, or operational weight.
Trigger
Automation session
Browser context info if browser is attached
Current page info if a page is open
Visible text contained in the element; script, style and head content is ignored.
ARIA role, optionally filtered by accessible name: `button`, `button|Sign in` (case-insensitive substring), `button|=Sign in` (exact) or `button|/^sign/i` (regex).
Element ref from the latest Browser Snapshot, such as `e12`.
Disable to remove the policy and restore the default rules (privileged schemes such as file: and javascript: stay blocked)
URL schemes that may be opened; empty allows all except file, javascript, chrome, edge, devtools and view-source
Host globs such as example.com or *.example.com; empty allows any host
Host globs that are always blocked
Block loopback, private, link-local and cloud metadata addresses (hosts are resolved; unresolvable hosts are blocked)
Continue
Updated automation session
Browser context info if browser is attached
Current page info if a page is open
Visible text contained in the element; script, style and head content is ignored.
ARIA role, optionally filtered by accessible name: `button`, `button|Sign in` (case-insensitive substring), `button|=Sign in` (exact) or `button|/^sign/i` (regex).
Element ref from the latest Browser Snapshot, such as `e12`.
The policy now in effect
Allowed URL schemes such as `http` and `https`. When empty, every scheme except the privileged ones (file, javascript, chrome, chrome-untrusted, edge, devtools, view-source) is allowed; privileged schemes are only allowed when listed.
Host globs such as `example.com` (that host only) or `*.example.com` (its subdomains). Empty allows any host. URLs without a host (about:, data:) are governed by schemes only.
Host globs that are always blocked; checked before the allowlist.
Blocks hosts that are, or resolve to, loopback, private, link-local, CGNAT, multicast or cloud metadata addresses. Hosts that cannot be resolved are blocked too.