The WSS Agent fail behaviour can be configured on the Cloud SWG portal:
When the option "Block all traffic" it is not necessarily clear whether all traffic is effectively blocked or if the bypassed domains, ip addresses and applications are still allowed to connect?
WSS Agent - any supported operating systems and versions
Access to bypassed destinations (domains or ip addresses) and bypassed applications are allowed when the fail behaviour to "Block all traffic" is implemented by the WSS Agent.
When the agent implements the feature to "Allow all traffic" this can be refered as the failOpen state.
When the agent implements the feature to "Block all traffic" this can be refered as the failClosed state.