Choose what will be used
Anything a product depends on is added for you. Counts update as you go.
Fitting the cap
Which of these are actually necessary?
Nothing in this tool can tell you. The registry records what somebody believed; a capture records what a browser contacted. A page contacts analytics, fonts, survey widgets and spare CDNs, and blocking every one of them changes nothing a child would notice — so a capture always over-states the list. Necessity only comes from removing something and seeing whether it breaks.
- Put the sign-in-only list below on one test iPad.
- Use the product as a pupil would. It will break.
- Capture it and upload it — every failed host is something genuinely needed.
- Add those, and go again. Each round has fewer failures; it converges in three or four.
- Then try dropping a whole batch you suspect is unnecessary. If it still works you have proved all of them at once — record that as a trial so nobody repeats it.
Nothing chosen yet
Pick a product on the left to see the URLs it needs and why.
Upload a capture
A HAR file is what the browser records in its Network tab. Comparing one against the registry is the only way to know which hosts a product really needs.
For staff-only hosts it is the other dimension: a staff session and a pupil session of the same product, both unchallenged.
What is kept: host names, how many requests each served, how many failed, and one path per host with the query string removed. The HAR itself is never saved — it contains cookies and sign-in tokens, and none of that is needed to answer which hosts were contacted.
What was this a capture of?
Which products were being used?
Needed to tell "this host is not required" from "the session never opened that screen". Without it a capture can still show what is MISSING, and nothing else.
Anything else worth knowing?
Captures on file
Each one is evidence, and what it can prove depends on what it can be compared with. Two captures that differ in one dimension answer a question; two that differ in both answer nothing.
Record a trial
You took some URLs off a device and used the product. What happened? This is the only evidence of necessity anywhere in the tool, and recording it means nobody has to sit with the iPad and find it out again.
What did you test?
Which products were you using?
Which hosts were NOT on the device?
One per line. Hosts, not full URLs — a trial is a fact about the world and has to survive the registry being edited.
What happened?
What broke?
Trials on file
What the captures propose
Proposals only. Marking a URL staff-only or two-factor-only takes it out of a pupil's list, so nothing here is applied until somebody says so.
Check a list somebody gave you
Paste the school's existing whitelist, a vendor's setup page, or an email from a coach. Nothing is written — this only says what the registry already covers.
Audit
Only checks that can be decided from the data, so every finding is one you can apply yourself and get the same answer. Where judgement is needed it says what to go and find out rather than what to do.