Allowlisting Programs

Adding programs to the allowlist for secure execution.

Overview: By default, any program on a Linux server can execute, access any file, and connect to any destination. Root Lock by HeartSuite controls all three per program — not per user, per program. Two different programs running under the same user get separate allowlist entries with separate permissions. The Dashboard guides you through each approval phase and tracks your progress.

Allowlisting spans three phases of the Root Lock by HeartSuite setup process:

  • Phase 2 — Program Allowlisting ([p]): Approve which programs are permitted to execute.
  • Phase 4 — File Access Allowlisting ([f]): Approve which files and directories each program can read or write.
  • Phase 5 — Internet Access Allowlisting ([i]): Approve which outbound internet destinations each program can reach.

Start from the Dashboard — it shows how many items are waiting in each queue and the Suggested Next Step directs you to whichever needs attention. The review queues manage volume through intelligent grouping, not blind bulk approval.

In this section


Allowlisting Basics

Overview and basic procedures for allowlisting programs in Root Lock by HeartSuite.

Batch Allowlisting Tools

CLI tools for scripted and automated allowlisting workflows.