# Distribution control

A published asset is reachable from anywhere unless a rule says otherwise. Distribution
control is where those rules are kept.

**Administration → Distribution control.**

## Named restrictions

A restriction is a named set of countries that published assets are blocked from reaching.
Every country in one is blocked; there is no allow list, because a rule that reads
backwards is a rule that will eventually be read backwards.

Click countries on the map to add and remove them, or use the search for the ones a mouse
cannot hit. The list beside the map is the same set, and either one edits it.

Give a restriction a name that says what it is for: "Trade compliance", "EU sanctions",
"APAC hold". The name is what an operator picks from when they publish, and what an
auditor reads later.

## Apply to every published asset

The switch on a restriction is the important control on this screen.

With it **off**, the restriction blocks nothing until an asset names it. This is right
for market holds and regional rights, where each asset decides.

With it **on**, it blocks on every published asset in the workspace, whether or not the
asset names it, and no asset can opt out. This is right for trade compliance, where one
mis-set field on one asset must not be able to serve into a sanctioned country.

The badge on the list shows which restrictions are enforced, so the blast radius is visible
before anyone clicks a country.

## Starter catalogs

**New restriction** offers **Start from a catalog**: shipped country sets for common
regimes as a starting point.
Choosing one copies its countries into a restriction your workspace owns from that moment,
stamped with where it came from.

They are copies, not subscriptions. Nothing updates them for you, and they are not
compliance advice: sanctions regimes change constantly and include measures a country-level
block cannot express, such as sectoral sanctions and named entities. Verify any catalog
against your own trade compliance requirements, and keep your own list as the authority.

## Changing a rule

Saving reaches the delivery edge worldwide within about a minute, for every asset the
restriction governs. Editing one restriction is one change, however many assets reference
it, which is why a country set kept here is better than the same countries typed onto
thirty assets.

Every change is recorded with who made it and when.

## Delivery settings

Two workspace settings sit behind every published URL.

| | |
|---|---|
| **Delivery hostname** | The hostname public URLs are issued against. Leave it unset for the platform default. Set it to your own subdomain, with a CNAME pointing at the platform hostname, and new URLs are issued on your domain. |
| **Watermark image** | The overlay drawn over published images that ask for one. A PNG, JPEG, GIF or WebP under 20 MB. |

Changing the hostname moves the address shown for every published asset. Addresses already
issued on the previous hostname keep working, so links in circulation are not broken.

## Where the rules are applied

Rules are enforced at the delivery edge, before any bytes leave, and they apply to a cached
asset exactly as they do to a cold one. What happens on a published asset, and what an
operator sees when publishing one, is in [Publishing](/guide/media/publishing).
