> For the complete documentation index, see [llms.txt](https://docs.birdie.so/birdie-docs/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.birdie.so/birdie-docs/security/domain-restrictions.md).

# Domain Restrictions

## Domain restrictions

Domain restrictions let you decide exactly where Birdie is used. Roll it out to one segment first, keep it to the accounts you've approved, or leave a specific set of customers out of scope entirely.

{% hint style="info" %}
Domain restrictions are available on the **Enterprise** plan.
{% endhint %}

### Common ways teams use it

* **Roll out gradually.** Start with a pilot segment, then widen the list as you're ready.
* **Scope Birdie to a specific book of business.** For example, only your commercial accounts, or a single region.
* **Keep sensitive accounts out of scope.** FedRAMP, government, healthcare, or any customer whose contract doesn't permit recording.
* **Honour per-customer agreements.** Exclude the handful of accounts that have asked not to be recorded.

### How it works

When an agent tries to create a request link, Birdie checks the customer's email domain against your rules. If the domain isn't in scope, no link is generated and the agent sees an explanation instead.

The rule is enforced **everywhere a request link can be created** — in every connected helpdesk and inside Birdie itself. There's no surface that bypasses it.

### Choosing a mode

There are two ways to define your rules. Pick the one that matches how your account base works.

#### Allow everywhere except these domains

Everyone can be recorded apart from the domains you list. Best when only a handful of your customers are out of scope.

Keep in mind that a newly restricted customer is **not** covered until someone adds their domain to the list.

#### Only allow these domains

Recording is available only for the domains on your list. Best for a staged rollout, for scoping Birdie to an approved set of accounts, or whenever you can't risk a domain being missed — anything not listed is out of scope by default.

### Setting it up

<figure><img src="/files/lbE8YnZDF5sDjuSLk50H" alt=""><figcaption></figcaption></figure>

1. Go to **Settings → Security & access → Recording restrictions**.
2. On **Domain restrictions**, click **Configure**.
3. Choose your mode.
4. Choose a source for the list (see below).
5. Click **Save restrictions**.

Changes take effect immediately for any new request link.

#### Source: manual list

Enter domains one per line, or separated by commas:

```
acme.gov
fedramp-client.com
```

Enter the domain only — no `@`, no full email addresses.

### What agents see

When a customer is out of scope, the agent gets a clear message naming the domain:

> Recording requests are turned off for `acme.gov`.&#x20;

The domain is named so the agent can tell it's a policy, not a bug — and knows what to escalate.

### Good to know

* **It isn't retroactive.** Recordings already captured stay exactly as they are. Domain restrictions only affect new request links.
* **Your team keeps full access to Birdie.** Only recording requests for out-of-scope domains are affected.
* **Matching is by domain.** Customers who contact you from a personal address (for example a Gmail account) are matched on that address's domain, not on the company they belong to.

### FAQ

**Can I scope by individual email address?**\
No — restrictions work at the domain level.

**Does it apply to every helpdesk?**\
Yes. The rule lives at the workspace level and applies to all connected helpdesks, as well as request links created directly in Birdie.

**Can I see when a request was blocked?**\
Yes — blocked attempts appear in your audit logs.
