VerifyFiltering — home VerifyFiltering — home
Learn / Filtering & DNS

Category Presets and Custom Overrides: Who They Actually Apply To

Category profiles can, in principle, apply at three levels — a single device, a group, or your whole fleet — but only one of those actually has a control in the dashboard today: group profiles, which are Enterprise-only. Fleet-wide and per-device profiles exist in the system underneath the product but don't have a picker to set them yet, so this article focuses on what group profiles actually do once you set one, including a limitation that isn't obvious until you hit it.

Group profiles are Enterprise-only, enforced twice

Setting a category profile on a group is available only on Enterprise. This is enforced both when you try to save a profile (a non-Enterprise account can't set one at all, even by sending the request directly) and separately when scans are resolved (a non-Enterprise account's scans ignore any group profile entirely, including one left over from before a downgrade).

For a browser-checked device, a group profile applies directly

When you check a device through the browser, a group's category profile — if the device is in a group with one set — determines exactly which categories get tested. If the device isn't in a group with a profile set, every category gets tested.

For an installed agent, a group profile has no effect at all

This is the part that isn't obvious: a group-level category profile has no effect on what an installed agent actually scans — only a fleet-wide default could ever reach it, and there's currently no way to set one. This isn't a bug — it's a real, current limitation of how the installed agent checks in: one request from the agent covers everything tied to your license key, with no way for the server to know which specific device is asking, so there's no way to hand it a group-specific list.

In practice: setting a group profile only changes what gets tested for devices you check manually through the browser. Devices running the installed agent scan every category regardless, no matter what group they're in.

An empty custom list never means "scan nothing"

If you pick "Custom" on a group and save before choosing any categories, that never gets treated as "restrict to zero categories." It falls back to unrestricted — every category gets tested — the same as if no profile were set at all.

Fleet-wide and per-device profiles: available on some plans, not usable yet

Every paid plan now includes fleet-wide compliance presets (CIPA, UK Safer Internet, Friendly WiFi) as an entitlement — that's real, and it's enforced correctly wherever it's checked. What doesn't exist yet is a way to actually pick one: there's no fleet-wide profile control in the dashboard for any plan, Enterprise included, and no per-device picker either. If you're evaluating a plan based on compliance-profile features, group profiles (Enterprise-only, above) are the only ones you can use today — fleet-wide and per-device profiles are on the roadmap but not yet in the product.

Compliance & Filtering

Guides on network content filtering, the standards that regulate it, and how to verify your own network actually meets them.

Standards We Test

  • CIPA
  • UK Safer Internet
  • Friendly WiFi
  • Custom Profiles

VerifyFiltering Monitoring

Move past a one-time scan — scheduled, ongoing checks across every device you manage, with alerts when something changes.

See plans →

CleanBrowsing

VerifyFiltering is a CleanBrowsing service. CleanBrowsing itself offers fast, privacy-first DNS filtering you can deploy directly.

Explore CleanBrowsing →

Contact Us

Have an idea for an article, or see something missing? Email support@noc.org.