Separate reader traffic
All bot traffic is not equal; discovery bots, AI crawlers, and scanners have different business impact.
A class-based policy protects both traffic quality and safety.
Requests are not readers
The useful question is not whether traffic looks busy; it is which activity represents readers, monitoring, crawlers, retries, or system errors.
Check the logs first
- Create a five-tier bot policy: discovery, AI citation, training, monitoring, anomaly
- Keep the test narrow: one low-risk task or tool entry before connecting permissions, logs, failure handling, and human takeover to production
What still needs proof
Binary allow/deny usually harms one objective at least. Keep the original source open so the announcement, the evidence, and this site's interpretation stay separate.