What do Allow and watch, Ask and Lockdown do in Tattle?
The mode decides only what happens to a connection that no rule covers. Allow and watch lets it through and lists it; Ask asks you; Lockdown blocks it. Your rules always come first, whatever the mode.
Tattle isn’t out yet: the download button on the home page starts working on release day.
Allow and watch
The default. Nothing is blocked unless one of your rules says so, and every connection is listed under the app that made it. It is the way to learn what your apps do before deciding anything.
Ask
When an app makes a connection no rule covers, the pill at the top of your screen asks: “Safari wants to connect”, with the host, port and protocol. Choose Allow or Block, how wide the answer is (this host, the whole domain, or anything from this app) and how long it holds (just this once, for an hour, until the app quits, or forever). An answer that lasts becomes a rule, listed in Rules under “From your answers”. On a Mac without a notch, the question appears in a small window instead.
A connection waits for your answer for 30 seconds by default; then it gets the default answer, which is to allow it unless you change that in Settings › Firewall. Connections that can’t wait, such as most voice and video calls, get the default at once, and the question stays open so your answer decides next time. Later hides the question until a new one arrives. No key answers a question: a stray Return never allows or blocks anything.
Lockdown
Lockdown blocks every connection that no rule allows. The built-in Essentials rules keep basic networking working: name lookups (DNS), joining networks (DHCP), local discovery (Bonjour), the clock (NTP) and Tattle’s own license and update checks. You can turn each Essential off in Rules.
Block All
Block All, in the main window’s toolbar, blocks every connection, Essentials included, until you turn it off. A banner says it is on.