The panel speaks in words. The URL, the Solr document and anything you query yourself speak in identifiers. This page is the mapping, and it is the only place it exists.
An identifier is the right thing to store: it is stable, it is what a filter carries in a URL, it is what you grep a log for, and it is what a query you write yourself has to name. It is the wrong thing to show somebody who has never read the source. So the panel renders a label, and an identifier it does not recognise renders as itself — never as a wrong-but-plausible label, and never as blank.
These are the values a session’s reasons field can hold. Seventeen are weighted rules; the last three carry no weight and are not accusations at all. The scoring page explains how they combine.
automation_markerThe page exposed a definitive driver artefact — the webdriver flag, a chromedriver global, Puppeteer, Playwright or Selenium hooks. Browsers do not have these; drivers do.
ua_declared_botIt said it was a bot and it was telling the truth. Verdict bot, threat none.
rdns_claim_failedIt declared itself a major crawler and forward-confirmed reverse DNS did not back that up. Impersonating a crawler is not a mistake anyone makes by accident.
headless_rendererWebGL reported SwiftShader, llvmpipe, Mesa OffScreen or Microsoft Basic Render: software rasterisation, which is what you get when there is no screen.
beacon_forgedThe claimed dwell time is impossible against the issue time of its own token. The lie is recorded rather than discarded, because the lie is the evidence.
ua_claim_failedThe User-Agent claimed a browser version whose engine features the page does not actually have. A spoofed User-Agent string cannot retrofit a JavaScript engine.
fp_cluster_proxy_fleetFive or more distinct addresses shared this exact header fingerprint within twenty-four hours on non-mobile networks. One client, many exits.
ua_secch_mismatchA Chrome User-Agent arrived without the matching client hint, or with one that contradicts it. Chrome always sends its own client hints.
platform_mismatchThe platform client hint disagrees with the operating system the User-Agent claims.
no_js_on_htmlAn HTML page was served with a 200 and no beacon ever arrived, while the User-Agent claimed a real browser. Real browsers run scripts.
hosting_asn_browser_uaA consumer browser User-Agent arriving from a hosting network. Weak alone — VPNs and corporate egress look like this — meaningful when stacked.
periodic_timingThe gaps between requests are too regular across four or more requests. People are not metronomes.
no_interactionThe beacon ran, the session ended, and not one scroll, click or key press ever happened.
tz_mismatchThe browser timezone disagrees with the timezone of the address geolocation.
no_304_on_repeatThe same assets were fetched again with no conditional header. A browser cache would have asked.
no_assetsHTML was fetched and not a single stylesheet, script, font or image followed it.
single_page_10sOne page, gone in under ten seconds. Very weak on its own; a bounce looks the same.
provisional_sessionThe session had not ended when it was scored, so the five signals that can only be read after it ends were not evaluated and the verdict is held at unknown. Nothing was detected.
beacon_only_sessionThis site has no access log in this installation, so the session was measured by the beacon alone and the five signals that read the request log were not evaluated. Nothing was detected — but the evidence that remains is the plane a determined client controls, so treat the verdict as weaker than the same verdict on a session with a log behind it.
no_bot_signalsEvery rule was evaluated and none of them fired. This is the absence of evidence, not evidence that a person was driving.
A session with nothing against it says so explicitly, so “no signals fired” and “the scorer did not run” are different states on the document rather than the same absence.
humanScored low enough that we believe a person drove this session.
likely_humanSome weak automation signals, not enough to call it a bot.
unknownScored, and the evidence did not reach a verdict either way. Not a failure to measure.
likely_botEnough signals to suspect automation, short of the bot threshold.
botAutomation, honest or not. Look at the class to tell which.
declared_crawlerSaid what it was in the User-Agent and was telling the truth. Honest traffic.
ai_crawlerA declared crawler collecting for model training or inference.
monitorA declared uptime or availability checker.
spoofed_uaThe headers contradict each other, or a crawler claim failed reverse DNS.
proxy_fleetOne browser fingerprint arriving from many unrelated networks.
headlessA driven or screenless browser: an automation marker, a software rasteriser, or a failed engine claim.
scriptedScored as automation without falling into any of the named classes.
noneNot classed as a bot of any kind.
Classified from the network operator’s name. These seven are the whole set: the classifier can only return one of the six named types or unknown. The hosting value is the one that matters most, because a consumer browser User-Agent arriving from hosting address space is a scoring signal in its own right.
hostingCloud, colocation, VPS or CDN address space. People do not browse from servers.
ispResidential or business broadband.
mobileCellular address space, where many subscribers share few addresses. Excluded from the proxy fleet rule for exactly that reason.
vpnA commercial VPN, a private relay or a Tor exit.
eduA university, school or research network.
govA public-sector or military network.
unknownThe operator name did not match any known pattern.
directNo referrer was sent: a bookmark, a typed address, or a client that strips it.
internalReferred from this site, or from a host configured as internal.
adCarried an ad-network click id or a paid campaign medium. Tested before search, so a paid search click is never counted as organic.
aiReferred from an AI assistant or chat product.
searchOrganic: referred from a search engine with no paid click id.
socialReferred from a social platform.
linkReferred from a site that is none of the above.
| Identifier | Label | Meaning |
|---|---|---|
search | Search crawler | Indexes pages for a search engine. |
ai | AI crawler | Collects pages for model training or for answering in an assistant. |
seo | SEO tool | A commercial backlink or audit crawler. |
social | Social preview | Fetches a page to build a link preview. |
monitor | Uptime monitor | Checks that the site is answering. |
other | Other declared bot | Declared itself a bot and does not fall into the named categories. |
log_onlySeen in the web server log and never by the beacon: no script ran, or the visitor left before it reported.
log_beaconSeen on both planes, so the log counts and the measured timings describe the same visit.
beacon_onlyReported by the beacon with no matching log line — a site on another server, or one whose log has not been read yet.
This field has no schema default, so every session indexed before it existed carries none of the three — and that absence means “this installation had not started recording which planes it had”, not “log only”. So the honest way to ask for sessions that have a transport plane is to exclude the beacon-only value, which keeps all of that history; asking for log-only instead would silently drop every older session and the count would look like a fact. The None of operator is what spells it, and the panel offers the remainder as its own row labelled “Not reported”.
The same three-state discipline applies to the signed-in dimension, whose two stored values are true (Signed in) and false (Anonymous), with absent meaning not reported — see identity.
Dimensions that already hold words a person uses — a browser name, an operating system, a city, a network operator, a netname, a virtual host, a path, a TLS version — have no mapping at all. There is nothing to translate, and a half-populated map over real-world values would mean some rows got a label and some did not.
For the field names themselves and what each one is indexed, stored or faceted for, see the Solr schema.