Skip to main content

How to manage flag exclusions (exclude phrases)

Add exclude phrases to prevent specific text from triggering policy flags.

H
Written by Harriet Christie

Summary

Excluded phrases (also called exclude phrases) are phrases — such as email disclaimers — that you want flagging policies to ignore. They help reduce false positives. On the Excluded phrases page you can add, edit, delete, search, sort, and export exclude phrases.

Prerequisites

  • Access to MirrorWeb Insight

  • Flag read permission to view; flag write permission to add or edit; flag delete permission to remove

Step-by-Step Instructions

Step 1: Open the Excluded phrases page

Navigate to the exclusions area. The heading reads Excluded phrases with the subtitle "Manage phrases (such as disclaimers) that you wish to be ignored by flagging policies." If your organisation uses Sentinel, the subtitle also references "active Sentinel scenarios".

The Excluded phrases page

Step 2: Open the Add exclusion form

Click Add (disabled with the tooltip "You don't have access to add" if you lack write permission). A modal titled Add exclusion opens.

The Add exclusion modal

Step 3: Enter the exclusion details

  1. Name ("Enter a name for this exclusion").

  2. Exclusion - a multi-line text area: "Enter the phrase you wish to exclude".

The Add exclusion form fields

Step 4: Create the exclusion

Click Create (shows "Creating..." while submitting). A success toast confirms "Exclude phrase created" with "Exclude phrase successfully created".

The Create button in the Add exclusion modal

Step 5: Manage existing exclusions

The phrase appears in the table. Use the Search by name... box and the sort dropdown (Name A-Z/Z-A, Newest/Oldest) to find phrases. Each row has an edit and delete action. Deleting prompts "Are you sure? You cannot undo this action." Use the download icon at the top to export exclusions.

The excluded phrases table with edit, delete, and export controls

Notes

IMPORTANT: Exclude phrases affect both flagging at ingest time and search at query time. They are not retroactive for flagging — adding a phrase does not unflag previously flagged messages.

IMPORTANT: There is a maximum of 500 exclude phrases per organisation, and each phrase can be up to 10,000 characters.

Did this answer your question?