CSP Builder turns the script hosts cside already observes on your site into a Content-Security-Policy you can deploy.

Pick a domain and you get a suggested policy across seven directives: script-src, connect-src, img-src, style-src, frame-src, font-src and media-src. Every host we observed is listed and grouped by what we know about it, so you can switch off anything that does not belong, add a host we have not seen yet, and restrict everything the policy does not name to your own origin. Copy the report-only header first and watch the violations land in your dashboard, then switch to enforce once it is clean.
CSP Builder is rolling out now. Contact us to enable it for your team.