Plan availability: IP allowlist is available as a paid add-on for Enterprise plans.
The IP Allowlist allows admins to restrict access to a Contentsquare account to specific IPv4 addresses or CIDR ranges. Once enabled, any request from an IP address not on the list is blocked, regardless of authentication method, including via Single Sign-On (SSO) or Multi-Factor Authentication (MFA).
Important
Before enabling IP allowlist, you are responsible for including the IP addresses used by Contentsquare teams that need access to your account, including your Customer Success Manager (CSM), Support, and Solutions teams. Discuss the required Contentsquare IP addresses with your CSM before activation and add them to the allowlist alongside your organization’s approved addresses.
If these IP addresses are omitted, Contentsquare teams may be unable to access your account after enforcement is enabled. This may limit the level of support available to you and delay support response times.
Before you begin
- The IP Allowlist is a paid add-on for Enterprise plans. Contact your Customer Success Manager (CSM) or Account Executive to request activation.
- Only Account Admins can configure the IP Allowlist.
- Gather your list of approved IPv4 addresses or CIDR ranges from your IT or network team before starting. IPv6 is not supported.
- You must include your own IP address in the allowlist before enabling enforcement, or you will be locked out of your account.
- Once the IP Allowlist is enabled, Contentsquare employees (CSM, Support, Solutions) lose access to your account unless their IP addresses are also included in your allowlist. This may delay support response times. Discuss this with your CSM before enabling.
Step-by-step setup
Step 1: Open the IP allowlist settings
Click your profile icon and select Account settings.
- Click IP allowlist from the left hand menu.
Step 2: Add IP addresses or CIDR ranges
- Click Add IP.
- Enter a valid IPv4 address or CIDR range. Inline validation checks the format as you type.
- Click Save. The IP address will then appear in the IP allowlist.
Repeat for each address or range you want to allow.
Note
Multiple addresses can be added at once if required. An overlap may occur from a single IP address and a CIDR range that includes it. If a single IP is already covered by a CIDR range on your list, both entries remain. An overlap message appears; to completely remove a specific IP, delete all entries containing it.
What is a CIDR range?
A CIDR range describes a block of IP addresses in the format IP address/number, for example, 198.51.100.0/24. The number after the slash defines the block size: a smaller number covers more addresses, a larger number covers fewer. Your IT or network team can provide these values.
- /32 — a single IPv4 address (one device)
- /24 — 256 addresses, typically one office or network segment
- /16 — 65,536 addresses, typically a large corporate network
Step 3: Enable the IP restrictions
Once your list includes at least one entry and your current session IP is covered, the Enable IP restrictions toggle becomes active.
- Review the confirmation dialog and click Confirm.
- Enforcement takes effect immediately: all access from IP addresses not on the list is blocked.
Account admins are notified by email when IP restrictions are enabled.
Additional configuration options
Adding entries after enabling
You can add IP addresses or CIDR ranges at any time, whether restrictions are enabled or disabled. Account admins are notified by email when entries are added while restrictions are enabled.
Removing an entry
When restrictions are disabled: Hover the entry row and click the remove icon. No confirmation is required.
When restrictions are enabled: Hover the entry row and click the remove icon. A confirmation modal appears before the entry is removed. Access from the removed IP is blocked immediately. Account admins are notified by email.

Removing your own current session IP
While restrictions are enabled, you cannot remove the IP address you are currently connected from. To remove it, disable IP restrictions first using the toggle, then delete the entry.
Disabling IP restrictions
Disabling the IP Allowlist immediately lifts all access restrictions. All previously saved entries are kept so you can re-enable the list later without re-entering them.
- Use the toggle to disable IP restrictions.
- A warning appears: "This will immediately allow Contentsquare access to all IPs."
- Type your admin email address to confirm.
- Click Confirm and disable. Account admins are notified by email.
Add-on removal
If the IP Allowlist add-on is removed from your contract, enforcement is deactivated automatically; previous entries will be stored. All Account Admins on the account receive an email notification when this happens.