Protect staging site with built-in protect features

Can someone explain to me how I can use the built-in protect content features to protect a staging site from prying eyes? I was planning to use either ip_address or _logged_in: true, but I can't work out how to do so per-environment. The environment configuration is just a list of variables. Any ideas?

