Org egress
Org egress is the Egress tab on the organization surface: where this org’s data is allowed to leave to. The controls behind it pair with Security. Treat the product UI as the source of truth for the destinations and states your tenant shows.
- Hosted sandboxes may reach the public internet by default; private, loopback, link-local, and cloud-metadata ranges stay denied. Policy chips name the posture: open public web (default), sandbox public web with CIDR denylist, browser and fetch open.
- The Public web toggle defaults on: browser, fetch, and the sandbox firewall may reach any public host while the immutable CIDR denylist still blocks private and metadata networks. Turn it off only to lock the tenant down to an allowlist.
- The lock-down allowlist applies only when public web is off. Entries are platform-blessed domains (AI gateway, package registries, fonts, object storage, GitHub); adding a new lock-down domain still requires a platform change.
- Egress changes are admin-only and land in Org audit. If a destination changed without a matching audit entry, stop and report it.

What next
Section titled “What next”- Security: the hygiene this outbound posture has to uphold.
- Integrations / Connectors: the packages that move data through these exits.
- Org audit: where egress changes are recorded.

