Start with the Fastly WAF architecture and traffic path
The proof of concept should show where inspection occurs, how traffic reaches the application, what request context is preserved, and how security events reach the team. The answer may differ between an existing Fastly delivery path and a new security deployment.
- Draw client, edge, WAF inspection, origin, logging, and response paths before testing.
- Confirm TLS, real client identity, API routes, and bypass behavior.
- Assign ownership for policy changes, event triage, escalation, and rollback.