Threat score and threshold
The threat score summarizes suspicious signals on a 0–100 scale. It is one input to protection, alongside rules, history, AI influence and safety checks.
On this page
How a score becomes an action
Use the current settings shown for your website. A score crossing a threshold does not bypass other eligibility, whitelist or safety checks. A visit below that threshold can still meet an independent rule.
| Input | What to check |
|---|---|
| Threat score | The underlying signals and configured threshold. |
| Click-frequency rules | The paid-click count and configured time window. |
| AI findings | Whether the verdict and the relevant influence settings qualify. |
| Block duration | The recorded block and expiry, rather than assuming one duration from the score alone. |
Tuning protection
Start with the applicable industry profile and inspect your traffic. Change one setting at a time so you can relate a result to its cause.
False positives are possible. Inspect the reason and available evidence, adjust the relevant settings and whitelist a known legitimate visitor when appropriate.
Conversion-based recovery
Eligible high-intent events from accepted sources can reverse a false-positive block. Browser tag-passthrough events do not qualify for this recovery path, and a page view or add-to-cart does not automatically clear a block. External exclusion removal remains subject to synchronization.
Frequently asked questions
What is the best threshold?
It depends on your traffic and tolerance for false positives. Use the website’s profile as a starting point and inspect the evidence before changing it.
Does a high score always create a permanent block?
Do not infer duration from the score alone. Check the actual block record, configured action and expiry.