/

Resource exclusions

Resource Exclusions

Resources can now be configured to bypass Twingate entirely. Admins can mark specific addresses within a broader Resource's scope, like a public sub-domain under a wildcarded corporate domain, to route directly to their destination via the local OS, skipping Twingate Connectors and Relay infrastructure. This gives you a clean way to carve out exceptions without restructuring your Resource topology or maintaining fragile, overlapping rules. Every change to a Resource's routing mode is captured in the audit log, so bypassing an address stays an explicit, traceable decision rather than a blind spot.

For more information, see our documentation.