Project page boundaries

Review discovered same-domain public pages without expanding scans into private, external or excluded paths.

Customers reviewing project pages and technical reviewers

Feature availability

Product, package, provider and deployment boundaries for this page.

Available from
Current documentation
Deployment modes
cloud

Product screenshots

Current customer-safe screenshots are generated from the application so examples do not drift from the product.

Generated customer-safe screenshot of Project Pages path boundary review.
Generated customer-safe screenshot of Project Pages path boundary review.

Before reviewing page boundaries

Project page boundaries decide what the scanner may inspect from a public website. The normal path is discovery first: WebRiskOps finds same-domain public pages and presents them in Project Pages before a scan starts. Use this page after [Supported public pages](/docs/projects/supported-scopes) confirms the target is eligible and [Public-page-only limits](/docs/projects/public-page-only-limits) explains the plan page budget. Keep this review short: if the discovered pages look right, continue to the scan.

Review same-domain public pages

Follow the path `Projects → Project detail → Project Pages → Actions`.

  1. Open /projects and choose the project for the domain. Result: the project detail page shows Project Pages and the current discovery state.
  2. Check that discovery found the main public URL groups. Result: the scan can start from the product, checkout, pricing or content pages customers actually use.
  3. Confirm every visible page belongs to the same project host. Result: external hosts and unrelated domains stay out of the scan request.
  4. Treat admin, account, login, payment-complete and internal paths as excluded. Result: the scan does not touch private or destructive workflow areas.
  5. Use Discover pages only when expected public pages are missing. Result: the product refreshes the same project instead of creating another configuration step.
  6. Continue to Actions when the public-page list is acceptable. Result: Run whole scan starts from the current project pages and credit state.

Understand include and exclude path rules

Path rules are guardrails for discovery and later crawl seeds. They should be easy to explain to a customer or reviewer.

  • Include paths are the public areas the scanner may follow, such as `/`, `/products`, `/pricing` or `/checkout-info`.
  • Exclude paths are areas that must stay out, such as `/admin`, `/account`, `/login`, `/checkout/complete`, `/internal` or destructive form paths.
  • Every scanned page still has to pass the same host, public-page and plan-limit checks.
  • Excluded paths should explain why a skipped URL was left out instead of silently disappearing from scan evidence.
  • If a public journey needs more pages than the plan allows, upgrade or reduce the scan request before starting the scan.

Blocked states

Do not run the scan while page boundary validation is failing.

  • Invalid URL means discovery or project setup found a URL that cannot be normalized safely.
  • Outside domain means remove the URL from the project or create a project for the correct host.
  • Private, login-required or admin path means use [Unsupported targets](/docs/projects/unsupported-targets) and keep it out of scope.
  • Outside include paths means either update the include path deliberately or remove the URL.
  • Excluded path means the page is intentionally skipped and should not be forced into the scan.

Continue to Project Pages

When Project Pages contains the right same-domain public pages and excludes unsafe paths, continue to [Project Pages review](/docs/projects/accepted-scan-scope). That page explains how to move from page review to scan execution.

Related documentation

Was this page helpful?

Feedback goes into the product documentation review queue.