What indicates automation?
A browser may declare automated control, or scoped action history may match a rule. Inspect the actual observation, its source and missing evidence. No observed indicator does not prove that a person performed the action.
AI-agent detection begins with what your integration can observe. Blokk assesses general automation indicators and gives teams reasons to review, while keeping actor identity, authorisation and later outcomes distinct.
An agent browsing products for a customer may be welcome. An automated process repeatedly consuming a costly application action may need a limit. The appropriate policy depends on the action, its authorisation and its effect on your service. Automation alone does not establish harmful intent.
Blokk’s research alpha uses the same general indicators for AI agents and other automation. It does not identify a particular agent, verify its provider or establish who authorised it. Signed-agent verification remains pending. Sophisticated or low-rate automation may pass without indicators.
A browser may declare automated control, or scoped action history may match a rule. Inspect the actual observation, its source and missing evidence. No observed indicator does not prove that a person performed the action.
A requester can supply a familiar name. That name is a claim until an appropriate verification method establishes it at a trusted observation point. Blokk’s current alpha leaves specific AI-agent identity unverified.
Your application still needs its normal authentication and authorisation checks. Even an established provider identity would not establish a shopper’s permission to modify a cart, spend credits or make a purchase.
Record what a reviewer later established, including the basis and any correction. A decision to allow or refuse activity expresses a policy choice; it does not by itself establish a legitimate or unwanted outcome.
The AI shopping agents guide develops these distinctions. The setup and testing guide turns them into practical checks.
Shopify is Blokk’s first commercial adapter. The current offer is a guided monitoring pilot around one recurring merchant problem. Hosted monitoring has been exercised on development stores; merchant production installation and public app approval remain pending. Review the pilot offer before planning an installation.
The core also retains browser and Node SDKs for configured application actions. These are workspace-only alpha packages. Developers can read the bot detection API overview and SDK lifecycle to understand the boundary between observation and their own application policy.
No. The current alpha assesses general automation evidence. It has no agent-specific identity verification, and a provider name in a request does not establish who acted or who authorised the action.
That depends on your policy and the action. Authorised shopping agents, useful crawlers and automation used by customers may be legitimate. A review should preserve those cases instead of equating automation with abuse.
Missing browser observations are not a standalone automation verdict. Collection may be unavailable because of consent, configuration or the client environment. Blokk keeps evidence availability separate from its automation assessment.
Read more about evidence and policy in the Blokk research notes, or discuss a scoped Shopify investigation.
Discuss a pilot