Our decision log · 2 September 2026
Ship the Content Security Policy in report-only first
HeldA real decision from building Decize, written down before the outcome.
- The decision
- Deploy the CSP as report-only, watch it, and promote it to enforcing only once the reports came back clean — keeping an environment variable to demote it again.
- Why, at the time
- An enforcing CSP that is wrong breaks the site for everyone at once, and the failure mode is silent for anyone not watching a console.
- What happened
- Report-only ran clean, the policy was promoted to enforcing, and nothing broke. The escape hatch has not been needed.
- Lesson
- Ship the observation before the enforcement.
Every entry in this ledger is real and was checked against the commit or migration that carries it. Want to keep your own this way? Start with the free decision log template.