A Fleet-wide list of banned phrases (Settings -> Blacklist), matched against a step's command text the moment it's submitted. Any step containing an active phrase is blocked everywhere by default -- add a phrase as a plain substring, or check "Is Regex" for a pattern match.

Allowing a phrase on a specific server, job, or step

Blocked doesn't mean blocked forever, everywhere: open the Blacklist tab in that object's Permissions dialog (the same lock-icon entry point used for permission grants) to exempt one specific phrase at that exact scope. A step-level override, a job-level override, and a server-level override (evaluated against wherever the step actually runs) are all independent -- exempting phrase #5 on one step has zero effect anywhere else. Overrides can be applied to many targets at once with the same "Apply To" picker permission grants use.

Checking a phrase's blast radius

The Test button on a phrase shows exactly what it would catch right now, grouped Server > Job > Step so "which servers does this touch" is the first thing you see -- each match is marked Blocked or Overridden.

A phrase can be temporarily disabled without losing it or its overrides -- useful for troubleshooting a false positive without having to recreate everything once you re-enable it.