Evidence review
What to inspect before changing anything
Start with the delivered website and the real user journey. Record the current state so the team can distinguish an observed problem from an assumption and compare the same surface after deployment.
- 01List browser capabilities the product actually needs
- 02Inspect the delivered Permissions-Policy header
- 03Check embedded frames and their allow attributes
Implementation
A practical improvement plan
Make the smallest coherent change that solves the observed problem. Keep normal code review, accessibility, security and product checks in the loop instead of optimizing for the scan alone.
- 01Deny unused capabilities explicitly
- 02Allow required capabilities only for intended origins
- 03Document each exception beside the integration that needs it
Verification
How to verify the result
Verification should test the intended outcome and the most likely regression. Use the production delivery path whenever headers, caching, rendering or third-party services affect the result.
- 01Test every capability-dependent user flow
- 02Inspect the response header in production
- 03Confirm third-party frames cannot gain broader access
Common pitfall
A shortcut to avoid
A blanket copied policy can silently break payments, video calls or embedded tools that depend on a capability.
Further reading
Primary guidance and references
These sources provide standards, security guidance or the interpretation framework used to keep this guide bounded. Product-specific implementation still requires review in the actual codebase.