Set it up
Close the gaps that remain
Each of these exists because a simple setup fails in a particular way. Read the one that matches what got through.
Friction
Filtering DNS, hosts files, standard accounts, and the settings that block workarounds.
Allowlist mode
When category filtering keeps not being enough. The strongest built-in block, and the only one that fails closed.
Mobile data and hotspots
When it works at home and not on cellular. Private Relay, tethering, carrier controls.
Apps and platforms
Search, video, social, app stores, TVs, consoles, and browsers hidden inside other apps.
Browser policy
Locking Chrome, Edge and Firefox, including their own encrypted DNS, which quietly defeats everything else.
Routers and gateways
Whole-home filtering, DNS interception, guest networks, Pi-hole and AdGuard Home.
Make it hard to undo
The part most setups skip, and the reason most of them stop working within a month.
Lockout
Handing over passcodes, separating admin accounts, and controlling the recovery paths.
Trusted person
Who to ask, what they hold, and what to agree before you need it.
Lock the DNS profile
Stopping the filter being switched off, on iPhone, Mac, Android and Windows.
Recovery audit
Finding the passwords, backup codes and reset paths that can quietly undo everything.
Handoff worksheet
A printable inventory to fill in together, including what they should refuse.
Accountability
Why browser history is an incomplete record, and how to keep one you cannot edit.
Check it, and use it
The three levels, if you want the model
Most of the site sorts into one of three tiers. You do not need to read them in order, but it helps to know which one you are currently relying on.
1. Guardrails
Built-in controls. Easy to maintain, easy to undo.
2. Friction
DNS, policy and network layers. Harder to route around.
3. Lockout
Someone else holds what you would need to reverse it.