Currently in LifeTime, there is no easy way to identify which applications have bespoke (application-level) Content Security Policies configured.
To check this, we must manually open each application and review its security settings in each environment. This becomes difficult to manage at scale, especially when CSPs are applied selectively across multiple applications and environments. It also introduces risk, as teams must rely on memory or manual tracking to know where custom CSPs have been configured.
It would be highly beneficial to have:
- A way to filter or list applications with custom CSPs in LifeTime Visibility per environment to understand where overrides exist
- A clear indication of whether an application is using environment-level CSP vs application-level CSP
This would significantly improve security governance, reduce manual effort, and help teams maintain consistent and auditable CSP configurations across their platform.