Pages
Policy Config — Egress Allow-List
Source: c65 policy-definitions.md P10 — list-editor shape, the deep exemplar (pending→approve flow)
‹ Policy Catalog
Egress Allow-List
Agent traffic may only reach approved destinations. The exfiltration chokepoint for the risk taxonomies, and the cross-border-transfer answer for GDPR Chapter V.
Data Protection
medium
P10Satisfies
OWASP LLM
ATLAS
CSF 2.0
800-52
ISO 27001
SOC 2
HIPAA
GDPR
Underlying control— show
egress: allowlisted = falseedit as custom control →Pending destinations
3 of 83 observed non-allowlisted destinations (24h) — top by connections
telemetry.vendor-x.com14 connections · 3 agentsSDK phone-home baked into a build image
cdn.polyfill-mirror.io6 connections · 2 agentstransitive fetch during npm install
api.weatherstack.com2 connections · 1 agentone-off tool call from a scratch agent
Approved destinations
6 entries · patterns supported (* and ?)
| Destination | Scope | Added by | Last matched | |
|---|---|---|---|---|
| api.anthropic.com | global | mark | 2m ago | |
| *.openai.com | global | mark | 11m ago | |
| github.com | global | seed | 1m ago | |
| registry.npmjs.orgbuild runners | host | seed | 38m ago | |
| sentry.ioweb-ci only | agent | jess | 3h ago | |
| slack.com | global | seed | 19m ago | |
| you |
Exceptions
Scoped carve-outs with a reason and an expiry — accepted risk, on the record.
| Scope | Value | Reason | Expires | |
|---|---|---|---|---|
| agent | red-team-probe | Authorized security-testing agent — egress intentionally unrestricted | 2026-08-31 | |
Remediation shown on findings: Approve the destination at an explicit scope, or block it and point the agent at an approved endpoint.