CSD can bypass the process by specifying the domain in the Allow List.
https://docs.cloud.f5.com/docs-v2/client-side-defense/how-tos/configure-csd
In addition to specifying the domain, it should also be possible to bypass traffic by specifying client parameters.
For example, client IP address.
Also, bypassed traffic should be excluded from metered traffic since it is not processed by the CSD.
Can you give an example use case for why you'd want to allow a specific client to be allowed and how it gets blocked today?