Why Detection Systems Score Instead of Blocking
Detection systems rarely answer the question "is this a bot" with a yes or a no. They produce a number, and the reason is that a binary answer discards information the site needs.
No single signal is conclusive
Every individual indicator has innocent explanations. An unusual header order might mean an automation library, or it might mean corporate security software rewriting requests in transit.
A datacentre address suggests a server rather than a person, but privacy relays and corporate VPNs put ordinary users behind exactly those addresses.
Because each signal is ambiguous alone, a system that converts any one of them into a verdict will be wrong at a rate the site cannot control.
A score carries uncertainty forward
A score preserves the difference between a visit that tripped one weak indicator and a visit that tripped several strong ones. A boolean flattens both into the same answer.
That preserved detail is what makes downstream decisions possible. The team consuming the score can decide how much doubt they are willing to act on.
It also makes the system auditable. When a legitimate user is affected, the score and its contributing factors explain why, which a bare verdict cannot.
Thresholds are business decisions, not technical ones
Where to draw the line depends on what is being protected. A login endpoint guarding financial accounts tolerates friction that a news article never would.
Detection vendors deliberately avoid choosing this for their customers. The same score means different things on a checkout page and on a public search results page.
Moving a threshold is also the fastest available control during an incident. Retraining a model takes time; changing where the cut sits takes effect immediately.
Different actions suit different score bands
Sites typically define several bands rather than one cut. Low scores pass silently, middling scores draw a challenge or reduced rate limit, high scores are refused.
Intermediate responses matter because they are recoverable. A user wrongly placed in the middle band can prove themselves, whereas a wrongly blocked user simply leaves.
Some responses are invisible by design, such as serving cached content or omitting expensive personalisation. These reduce cost without telling the client it was suspected.
Scores make review and tuning possible
A stored score distribution shows how traffic is spread and where a threshold change would land. That is the basis for tuning without guesswork.
It also surfaces drift. When the distribution shifts without a corresponding change in real traffic, the model or the population has moved and the thresholds need revisiting.