1. Does the activity show automation?
A browser may declare automated control. A sequence of actions may show a pattern worth reviewing. Neither establishes harmful intent. Conversely, missing automation indicators do not prove a human acted. Ordinary fast interaction and assistive tools need to remain valid control cases.
Describe the observation: “browser declared automated control,” “pattern matched,” or “insufficient evidence.” These statements are more useful than assigning every session to a supposedly certain human, bot or malicious-agent category.
2. Who is making the provider claim?
A user-agent string is a claim supplied by the requester. Verification needs a current provider-specific method and an observation point that can actually supply the required evidence. For example, Google documents matching the original request IP against published ranges or checking reverse DNS followed by a matching forward lookup. A Google-looking name alone is insufficient. Google’s crawler verification methods.
A Shopify pixel event does not give Blokk control of the original request to Shopify. It cannot authenticate a crawler that never contacted a Blokk-controlled observation point. Keep the status unknown when that evidence is unavailable.
3. Is the particular action authorised?
Even established provider identity would not, by itself, establish permission from the purchaser. Browsing a product, modifying a cart and committing a purchase have different consequences. An application still needs its ordinary authentication and action-authorisation controls. Provider verification must not silently bypass those controls.
4. What did the activity actually do?
A merchant may permit product discovery while limiting a repeated costly action where a real intervention exists. Review scoped behaviour and later outcomes. Do not infer a person behind several accounts from a shared IP address, or treat every automated purchase as abuse.
Keep policy and outcome separate: allowing a request expresses a business choice, not proof that it was legitimate; refusing it does not prove it was malicious. Preserve corrections when a shopper or merchant later supplies better evidence.
Translate the distinction into a safe policy.
- Record automation indicators separately from actor claims.
- Show verification method, scope and expiry when verification exists.
- Require action authorisation independently of provider identity.
- Test authorised automation alongside unwanted scenarios.
- Keep unsupported enforcement and unknown identity visible.
Blokk does not identify or verify specific AI shopping agents in this alpha. Signed-agent support remains pending; the present offer is inspectable evidence and scoped policy review.