> ## Documentation Index
> Fetch the complete documentation index at: https://developers.aptranet.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Policies and rules

> Tune managed protection and create scoped exceptions, custom rules, IP firewall rules, and advanced rules.

Open a protected domain to configure its security controls. Changes apply to that domain. Check the selected project and domain before saving.

## Managed protection

Open **Managed protection** to inspect available policies and enable or disable them. Policies that require bot management, API security, or threat intelligence are gated by the corresponding add-on. Disabling a paid policy remains possible after its entitlement expires.

Use **Protection settings** to select active or monitor mode and configure DDoS thresholds. Review requests from normal browser sessions and API clients when changing these settings.

## Policy exceptions

Open **Policy exceptions** when a specific managed detection blocks legitimate requests. Select the target policy and constrain the exception to the relevant traffic. Verify the affected request in **Security events** before broadening the exception. Delete exceptions that are no longer necessary.

## Traffic rule types

| Rule type | Use it for | Availability |
| - | - | - |
| Custom rules | Actions based on request conditions | Advanced or Business, within the current rule limit |
| IP firewall rules | IP-based traffic controls | Advanced or Business, within the current rule limit |
| Advanced rules | Source-based rules with supported phases | Eligible plan and Advanced rules add-on |

<Steps>
  <Step title="Create a scoped rule">Open the relevant rules page. Set a recognizable name, conditions or source, and the intended action.</Step>
  <Step title="Review before enforcing">Save the rule disabled when you need to review its configuration first. A disabled rule remains saved without enforcing its action.</Step>
  <Step title="Enable and verify">Enable the rule and check representative legitimate and unwanted requests in Security events.</Step>
  <Step title="Maintain the rule set">Update or disable a rule when application behavior changes. Use bulk deletion only after reviewing every selected rule.</Step>
</Steps>

## API behavior

Use `/shield/domains/{domain_id}/policies`, `/custom-rules`, `/firewall-rules`, and `/advanced-rules` as documented in the endpoint reference. A policy update sends `{"mode": true}` or `{"mode": false}`. A rule toggle sends `{"enabled": true}` or `{"enabled": false}` to the individual rule.

Rule limits return `409` when reached. Missing add-ons or an ineligible plan return `403`. These errors require a configuration or entitlement change; repeating the same request will not resolve them.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.