Distribution control
A published asset is reachable from anywhere unless a rule says otherwise. Distribution control is where those rules are kept.
Administration → Distribution control.
Named restrictions
A restriction is a named set of countries that published assets are blocked from reaching. Every country in one is blocked; there is no allow list, because a rule that reads backwards is a rule that will eventually be read backwards.
Click countries on the map to add and remove them, or use the search for the ones a mouse cannot hit. The list beside the map is the same set, and either one edits it.
Give a restriction a name that says what it is for: "Trade compliance", "EU sanctions", "APAC hold". The name is what an operator picks from when they publish, and what an auditor reads later.
Apply to every published asset
The switch on a restriction is the important control on this screen.
With it off, the restriction blocks nothing until an asset names it. This is right for market holds and regional rights, where each asset decides.
With it on, it blocks on every published asset in the workspace, whether or not the asset names it, and no asset can opt out. This is right for trade compliance, where one mis-set field on one asset must not be able to serve into a sanctioned country.
The badge on the list shows which restrictions are enforced, so the blast radius is visible before anyone clicks a country.
Starter catalogs
New restriction offers Start from a catalog: shipped country sets for common regimes as a starting point. Choosing one copies its countries into a restriction your workspace owns from that moment, stamped with where it came from.
They are copies, not subscriptions. Nothing updates them for you, and they are not compliance advice: sanctions regimes change constantly and include measures a country-level block cannot express, such as sectoral sanctions and named entities. Verify any catalog against your own trade compliance requirements, and keep your own list as the authority.
Changing a rule
Saving reaches the delivery edge worldwide within about a minute, for every asset the restriction governs. Editing one restriction is one change, however many assets reference it, which is why a country set kept here is better than the same countries typed onto thirty assets.
Every change is recorded with who made it and when.
Delivery settings
Two workspace settings sit behind every published URL.
| Delivery hostname | The hostname public URLs are issued against. Leave it unset for the platform default. Set it to your own subdomain, with a CNAME pointing at the platform hostname, and new URLs are issued on your domain. |
| Watermark image | The overlay drawn over published images that ask for one. A PNG, JPEG, GIF or WebP under 20 MB. |
Changing the hostname moves the address shown for every published asset. Addresses already issued on the previous hostname keep working, so links in circulation are not broken.
Where the rules are applied
Rules are enforced at the delivery edge, before any bytes leave, and they apply to a cached asset exactly as they do to a cold one. What happens on a published asset, and what an operator sees when publishing one, is in Publishing.
