Thank you for your feedback! More resources and education material for developers will be coming very soon.
The default policy we provide is report-only. When we started we provided a very strict policy, but it broke too many apps. It was a major turn down for a lot of adopters. We are constantly evolving and are currently working on a feature that automatically generates tailored (stricter) policies depending on the reports we receive.
No domain verification is required at this point. Content-Security-Policies are ideally delivered through the HTTP response headers and then enforced by the browser. We are working on making the integration as easy and smooth as possible.