Censorship, throttling, and (presumably) surveillance occurs at both layers. In some cases, also the region matters (Sistan and Baluchistan for example have experienced extended blackouts). In part that heterogeneity is because they still ideally want to keep businesses or VIPs online to mitigate the economic loss or logistical issues.
Consequently, the actual means of blocking tends to be on an ISP basis: some will simply drop packets, some will have left certain endpoints open, some will leave international DNS open, etc etc. All that changes when activists notice, exploit the opening, and then the ISP finds out. And then sometimes the TIC (the gateway) will impose blanket limitations or throttling.
My impression is that Iranian intelligence cares less about means than effectiveness, and ISP operators want to keep their license, livelihoods and lives, so they figure out how to meet the mandate. Given that this is something like the fourth blackout in recent years, they've gotten enough practice that there's few options out (that aren't Starlink).