The director who blocked a too-broad category, triggered a productivity revolt, and disabled filtering entirely

He had the budget, the mandate, and a board slide that said "reduce risky browsing." So the Monday the agent rollout finished, he switched on the social-media and web-chat categories for the whole fleet in one move. No pilot, no exception path. By Wednesday recruiting could not reach LinkedIn, marketing could not schedule posts, and the support team's vendor ran a chat widget that now threw a block page mid-ticket. He turned filtering off entirely on Thursday, and the program never came back.

The categories were not the mistake. Treating a debatable, business-adjacent category like malware and pushing it to everyone with no observation first was. The technical part worked perfectly. The program died anyway, because the first thing the company felt was friction with no visible threat behind it.

The first category you block decides the program's fate

People judge a filtering program by the first block page they hit. Interrupt a malware download and nobody mourns it. Stop a salesperson from opening a customer's Instagram and you have told the whole company that security is the team that breaks their job. Which categories you enable, and in what order, is a political decision before it is a technical one. "Ban distractions" is the worst opening move: loud, sympathetic complainants and no security win to point at.

Start with the categories nobody argues with

Begin where there is no defensible reason to be on the other side. Enable malware, phishing, and command-and-control, plus signed threat feeds like URLhaus, OpenPhish, and PhishTank. Nobody files a ticket demanding their right to reach a known C2 domain. These blocks make the case that the program protects people rather than polices them, and they buy weeks of clean operation before you touch anything contestable.

Stage enablement before you broaden

Do not flip every content category on day one. Start with malware and phishing, watch the false-positive review queue and block feed for a week or two, then add the next contested category. Schools and libraries filtering under CIPA have documented the same lesson for years: blunt category filters overblock legitimate educational and health content, and the fix is tighter scoping plus review, never a wider net. The recruiter on LinkedIn and the vendor chat widget should show up as review tickets you can fix with allowlist entries — not as a Wednesday revolt that forces a full rollback.

Roll out category by category, not with fleet-wide hammers

Fleet-wide enablement assumes every job browses the same way, which is never true. Recruiting lives on social platforms. Engineering pulls from sites that misclassify as forums or file-sharing. Finance carries its own risk tolerance. Stage categories instead of enabling everything at once: start with the always-on security set, add one content category at a time, and have the owning team sign off before the next one. The false-positive review queue tells you within a day whether a category is overblocking.

Read backlash as data, not as failure

A complaint is a misclassified site or a real business need telling you where the policy is wrong. The director who rolled everything back read the noise as proof the program was a mistake. It was proof the rollout was. Each ticket should drive an allow-list entry or a category change, with the date and decision recorded, because NIS2 and ISO 27001 surveillance audits reward a documented exception process far more than a block-count dashboard.

ClearScreen assigns blocked UT1 categories on the Customer Environment policy every enrolled device inherits. Enable malware and phishing first, use the review queue and block feed to tune allowlists, then add contested categories once owners sign off. Start the malicious-first profile from /features.