Skip to Access control
Control · Access control

Give every AI
request a rule.

Set access rules for verified AI agents, from a whole property to a single URL. Applied at the edge, before a request reaches your website.

Access rules · news.example.com 5 rules · Evaluated at the edge
Agent Scope Outcome
GPTBotOpenAI · /news/* Section/news/* Allow
ClaudeBotAnthropic · /archive/* Section/archive/* Allow
Google-AgentGoogle · /explainers/* Section/explainers/* Agent Web
Any verified agentPremium report · /reports/annual-2026.pdf Asset/reports/annual-2026.pdf Block
UnverifiedIdentity not confirmed · whole property Propertynews.example.com Block
One property, rules from a single asset to the whole site. Unverified traffic has its own rule.
Access rules in the Citetab Publisher Console. Illustrative data.
Where a rule applies

Rules at the level you manage content.

An archive can carry one policy and a documentation library another. Set the scope around the content and properties already in place.

Property

One policy across a connected website, without applying it to the rest of the portfolio.

Section

Different terms for different collections: a documentation library, a research collection or an archive.

Asset

An individual resource, such as a report or a downloadable file, without applying the rule across the property.

URL

A specific rule for a specific address, or a defined set of addresses, when access needs to be exact.

Agent identity first

Identity comes before policy.

Citetab verifies the agent behind a request before any rule applies. A request that claims to be GPTBot but fails verification never inherits the rule meant for GPTBot.

A request claims to beGPTBot
Identity verified

The rule for that agent and the content requested applies.

Identity unverified

Handled as unverified traffic, apart from the rules for verified agents.

Enforcement at the edge

Enforced before content is served.

Access rules are evaluated before a request reaches your website. Human visitors, ordinary search traffic and unrelated requests continue through their existing routes.

One request at the edge
Traffic at the edge
Human visitorsExisting route
Other web trafficExisting route
Verified AI agentsRule applied
  1. 01
    Incoming request
    GPTBot, verified
    OpenAI
  2. 02
    Content requested
    /business/rbi-repo-rate-decision
  3. 03
    Rule
    GPTBot on /business/*
    Evaluated at the edge
  4. 04
    Outcome
    Allow
    The verified agent receives the page from the website.
Choose a rule to see where the request goes.
Next: Agent Web

Let approved agents work with your website.

Structured content delivery is live. Agent-to-agent workflows are coming soon. Your access rules decide what agents may read.

Explore Agent Web

Start with Access control

Set the rules for AI access.