Block a visitor

Updated May 22, 2026

Blocking a visitor is an organisation-wide action. There are two ways to block someone: ban them from the inbox (available on any plan) or block them in Security (on plans that include Security). An inbox ban lets you choose how far the block goes — block them from human agents only (they keep the AI assistant) or block them from the chat completely. A Security block is always a full block.

Block a visitor from the Security visitors page

  1. Go to Security → Visitors.
  2. Find the visitor by name, email, or trust score. You can use the search bar or filter by status.
  3. Click the visitor's name to open their security profile.
  4. Click Block at the top of the profile.

The visitor's status changes to Blocked immediately and they're blocked from chat across your organisation. Blocking is a manual override — it doesn't add a risk signal or change the visitor's trust score; it simply marks them blocked no matter what their score is.

Ban a visitor from the inbox

You can block a visitor straight from an open conversation, on any plan — you don't need Security for this. Open the conversation, click the visitor's name in the sidebar, and choose Ban visitor. You'll pick a level, enter a reason, and choose a duration — from 1 hour up to 30 days, or Forever (the default is 24 hours):

  • Block from agents — the visitor keeps the AI assistant but can no longer reach a human. The AI won't connect them to an agent, and won't pretend it did. Use this for someone who shouldn't take up agent time but can still self-serve with the bot.
  • Block completely — the visitor can't use the chat at all. Use this for spam or abuse.

Timed bans lift on their own. When the duration ends, the block simply stops applying — nobody has to remember to unban. The visitor is never told they're banned and never sees a countdown; once a timed ban ends, chat just works again for them. For heat-of-the-moment abuse, a timed ban is usually the better choice than a permanent one.

If the visitor was banned before, the dialog also lists their previous bans — level, duration, reason, date, and whether each one was lifted early or expired — so repeat offenders stand out at a glance.

While someone is blocked, the conversation shows a block card with the level and, for timed bans, when the ban expires. From there you can escalate an agents-only block to a full block, downgrade a full block back to agents-only, or lift it — changing the level keeps the remaining time. A blocked conversation also locks agents out — you can't reply, assign it, or start a workflow until you lift the block. Banned visitors are listed under Audience → Visitors → Banned visitors together with each ban's expiry (lapsed bans show Expired), where you can change the level or unban them later.

Block their connection too. A full ban ("Block completely") comes with a pre-ticked Also block their connection box. Leave it on and their connection — the internet address their browser uses (for IPv6, the household-sized block of addresses) — can't start new visitor sessions or new conversations on your widget for as long as the ban, up to 24 hours at most. That is what stops the classic trick of opening a private window, or clearing site data, to come back as a "new visitor". People already mid-conversation on the same connection (a colleague on the office Wi-Fi, another customer on the same mobile network) are never affected, and the blocked person just sees the usual disabled chat input. The box is only offered when the visitor was seen on that connection in the last 24 hours — if their last visit is older, it's disabled with a hint, because the connection may belong to someone else by now. Agents-only bans never block a connection, and the Yaplet mobile app currently bans without this option.

With the box on, the dialog also lists the other visitors seen on that connection in the last 24 hours — name or email (or "Anonymous visitor"), country, last seen, last message — all pre-selected. Confirm, and the same ban (level, reason, duration) is applied to everyone selected in one click, so a spammer with five browser windows open is dealt with once. Use Select all / None, and untick anyone who is obviously a different person. The confirmation message tells you exactly what happened.

Security → Network also lists what Yaplet's automatic flood detector flagged — a connection creating an unusual number of new visitors or conversations in a day. For now it only watches: those rows say "Would have blocked", and nothing is blocked automatically.

What blocking does

  • Block from agents — The visitor keeps the AI assistant but can't reach a human, and agents are locked out of the conversation. Apply it mid-chat and the AI takes over with a short message letting the visitor know a human isn't available but it can still help. If the widget has no AI assistant, this applies as a full block instead.
  • Block completely (and all Security blocks) — The visitor cannot start or continue conversations; any attempt to send a message is blocked, and proactive outreach chat messages stop too (banners, surveys, and tours still appear). Inbound calls from phone numbers on their record are also refused before Telnyx answers — no ring-through, no per-minute charge — and a timed ban that expires lets the next call connect normally. (An agents-only block doesn't affect voice — voice has no live-agent handoff anyway.) When Also block their connection was ticked, new visitors and new conversations from that connection are turned away too, for up to 24 hours — every blocked connection is listed under Security → Network.
  • Scope — The block applies across your entire organisation, not just one widget.

Unblock a visitor

How you unblock depends on how they were blocked:

  • Blocked in Security — open their security profile and click Clear status (revert to automatic scoring) or Allow (mark them trusted, which overrides future automatic flagging even if their score stays low).
  • Banned from the inbox — unban them (or change the level) from Audience → Visitors → Banned visitors, from the conversation's block card in the sidebar, or from their security profile (the red "This visitor is blocked" banner has a Remove manual ban button). Lifting the ban also releases the connection block it created. To release only the connection — for example when a colleague blocked the office connection by banning a test visitor — open Security → Network (needs the Security permission) and click Release on that row; the visitor's own ban stays.

If a visitor was blocked by more than one source, you'll need to clear each one before they can chat again — their security profile shows which sources are active (a connection block appears there too, with when it ends), and the Security block and the inbox ban can both be cleared right there (Clear status / Allow for the Security block, Remove manual ban for the inbox ban); a connection block is released from Security → Network.

Block from the Visitors list

You can block someone straight from Security → Visitors without digging into menus. Select one or more rows and use the bulk Block action, or open a visitor's profile and click Block. To focus on the people most likely to need action, filter the list to the Low trust band first. See Check low-trust visitors.

Block words, not people

If the problem is specific language rather than a specific person, set up an organisation-wide blocked words list instead — messages containing those words simply can't be sent, and the visitor is asked to rephrase. See Block specific words in chat.

Did this article answer your question?