Correct. I understand that concept. The issue is still when the rule was below the Group User roles, Google Gemini was still being allowed because the traffic log indicated that Google Gemini fell under Google Services and Google Web Advertisements. Under a different object and a different category. Therefore, users hit the rule that allowed Google services and Google Web Advertisements (which has to be allowed for certain things to work), therefore they could get to Google Gemini.
For example,
Rule 15 --> Marketing --> Access granted to Google Web Advertisements
Rule 19 --> Inline Rule for Blocking AI except for CoPilot
Marketing users try to use Google Gemini. Google Gemini being AI is accepted on Rule 15 because of Google Web Advertisements being allowed. (miscategorization or secondary categorization).
Google Gemini is strictly AI and shouldn't fall under this.
Now I've moved my rule above the Marketing rule which now blocks Google Gemini.
The part I'm battling with is that Google Gemini SHOULD NOT BE categorized under Google Web Advertisements correct? But if this is somehow correct (which I don't understand why), what can be done differently without moving the AI rule? I mean if Gemini has a primary of AI and secondary category of Web Advertisements, can the rulebase somehow be set to only match the primary category?
And that's assuming that's why Gemini is even matching the Marketing rule in the first place is because they are allowed the Web Advertisement category. They don't have the AI category in their rule. I'm just not wanting Gemini to match under the category Web Advertisements or Google Services.
I hope this is clear enough.