Users are getting access denied exception from Cloud Secure Web Gateway (Cloud SWG, formerly WSS).
How to identify which policy rule on Cloud SWG is blocking a URL?
For Example : - User is being denied due to content categorization of "Gambling"
Based on the example screenshot, you can see the Error ID: CF-G4
So the rule is located at Content Filtering Section, Rule G4
For more details about Content Filtering Editor see Cloud SWG Content Filtering Policy