Blog / Engineering

From a bot score to a policy: allow, flag, block

A score is not a decision. This is how the bands, verdicts, and actions fit together, and why enforcement belongs on your server.

A score on its own does nothing. The value is in the policy you build around it — the rules that turn a reading into an action your application is willing to stand behind.

Volance keeps three concepts separate so the policy stays legible: the score, the verdict, and the action. The target contract starts with enforcement disabled and simple thresholds; you tighten it from there.

The starting bands

These are the contract's provisional defaults, not a production guarantee:

  • 80 and above — human; allow.
  • 70 to 79 — likely human; allow.
  • 40 to 69 — suspicious agent; flag, and consider a cascade for more evidence.
  • Below 40 — bot; block.

Verified automation is a separate path: a signed request that checks out returns authorized_agent and can be allowed without ever being called human. Hard overrides cap the score when there is a strong contradiction, such as an exposed automation flag or spoofed disclosure.

Start in monitor mode

Do not begin by blocking. Point your backend at the scoring API, log the verdicts, and compare them with what you already know about your traffic. Watch which sessions trip the flag band and whether any of them are customers you care about.

Only once the split looks right do you let the policy act. Because enforcement runs on your server, switching from monitoring to enforcing is a change in your code, not a change in a vendor's black box.

Keep the decision yours

There are good reasons to keep the final call on your side:

  • You know the context — a login attempt is not a newsletter signup.
  • You can be more forgiving for authenticated users and stricter for anonymous ones.
  • You can explain every block, because you hold the evidence and the rule.

Volance returns a recommendation; it never enforces anything on your behalf. It is not in your request path, so nothing of ours can take your site down or change your response.

Let the good automation through

A policy is not only about blocking. Some automation belongs: search crawlers, partner integrations, and agents acting for a real user. Because Volance classifies agent separately from bot, you can write a rule that admits a verified agent while still catching abuse.

That is the shape of a healthy policy: allow the clear and the signed, flag the uncertain, block the clear abuse — and revisit the thresholds as your traffic teaches you where the lines belong.

Frequently asked

Should I block on day one?

No. Run in monitor mode first, compare verdicts with known traffic, and only then enforce. Volance starts with enforcement disabled for that reason.

Who applies the allow, flag, or block decision?

Your server. Volance returns the score, verdict, and evidence; your application reads them and applies its own policy.

See the evidence
for yourself.

One script on your site.
One API call from your server.
Every signal behind the verdict, in your own portal.

Open the portal Read the docs