Rollout checklist
Before enforcing verdicts in production, follow this sequence:1. Report-only mode
Start by logging verdicts without blocking anyone. This lets you understand your traffic baseline.2. Soft challenge
After a week of report-only data, add friction for suspicious sessions:- Show a CAPTCHA for
inconclusiveverdicts - Add email verification for
botverdicts - Let
humanverdicts through without friction
3. Hard enforcement
Once you’re confident in the signal quality:- Block
botverdicts outright - Challenge
inconclusiveverdicts - Pass
humanverdicts through - Treat tokens whose
decision.evaluated_atis more than a few minutes old as missing, because the server SDKs don’t check token age. See What verification doesn’t check.
Monitoring
Track these metrics in your dashboard:- Verdict distribution - what % of traffic is human/bot/inconclusive?
- False positive rate - are real users being flagged?
- Block rate - how many sessions are you blocking?
What’s next
- Verdicts & scoring - understand verdict thresholds
- Troubleshooting - common production issues