“We block a lot of bots” is not a metric — it is a vibe. A defensible bot program measures block rate alongside the numbers that reveal whether those blocks are right, and presents them where the whole team can see.
Block rate alone is meaningless
Bot-block rate is simply the share of traffic your engine blocks as automated. On its own it tells you nothing, because it moves for two opposite reasons: you got better at catching bots, or you got worse at sparing humans. A rising block rate could be a win or a slow-motion incident.
That is why block rate must always travel with its counterweight: the false positive rate.
The core metric set
Track these together, and never in isolation:
| Metric | Definition | Healthy direction |
|---|---|---|
| Block rate | Share of traffic blocked as bot | Stable, explainable |
| False positive rate | Good users wrongly blocked | Low and steady |
| Catch rate | Known abuse actually stopped | High |
| Challenge rate | Sessions routed to friction | Controlled |
| Conversion | Real users completing actions | Flat or rising |
The relationship between them is the story. Block rate up and false positives flat and conversion steady is a genuine improvement. Block rate up with conversion sliding is a warning that you are catching customers, not bots.
Estimating false positives without perfect ground truth
The hard part is that you rarely know for certain which blocked sessions were real users. Three practical techniques get you close:
- Monitor mode: shadow a rule so it records would-be blocks without acting, then sample those for review before enforcing.
- Manual sampling: pull a random set of blocked sessions each week and have an analyst judge them.
- Appeal and ticket signals: track how often blocked users complain or successfully appeal — a rising trend is a false-positive smell.
None is perfect alone; together they give you a reliable estimate of how many good users you are losing.
Segment by reason code
An aggregate block rate hides the mechanism. Break it down by reason code — bot_automation, datacenter_ip, proxy_detected, new_device_velocity — and the picture sharpens immediately.
If datacenter_ip drives most blocks, that is usually safe. If new_device_velocity alone drives a spike, investigate: it might be a real attack, or it might be catching legitimate users on new devices during a marketing push. Because Prynt attaches reason codes to every verdict and exposes editable risk weights, you can trace a block-rate change to a specific signal and adjust it deliberately. For a broader metric framework, our bot detection engine surfaces these codes at decision time.
Watch for drift and attacks
Sudden movement in block rate is a signal in itself. A sharp jump concentrated in a short window and a single reason code usually means an attack — good, your defense is working. A slow, broad creep across many codes more often means a rule has drifted out of calibration.
Set expected ranges for each metric and alert when they break. A block-rate alert paired with a conversion-drop alert should page someone; a block-rate move that matches a known attack should not.
Share the numbers beyond the fraud team
Bot-block metrics are most valuable when they leave the fraud team’s screen. Finance cares about the conversion line, product cares about the false-positive rate, and security cares about attack spikes — and all three are on the same dashboard.
Reporting these numbers regularly builds trust in the program and makes tradeoffs explicit. When you propose tightening a rule, stakeholders can see the expected effect on both catch rate and conversion, and the decision becomes a shared, informed one rather than a unilateral call the rest of the business only notices when something breaks.
Build the dashboard once, watch it always
Put block rate, false positive estimate, catch rate, challenge rate, and conversion on one view, segmented by reason code and by action (signup, login, checkout). Review it weekly. The goal is not a bigger block rate — it is a block rate you can explain, next to a false-positive rate you can defend.
Measured this way, bot defense stops being a vibe and becomes a number you can stand behind in front of finance, product, and security alike.
Want to see the reason codes that would populate your dashboard? Try the playground, then review pricing when you are ready to instrument your own traffic.
Try it free
Prynt is device intelligence with a free tier — visitor IDs, bot & fraud Smart Signals, and behavioral biometrics, powered by a cross-site network. Start free.