Security headers should describe the actual pageStart with a narrow policy, then expand it only when a documented feature needs another resource.