Executive overview
Posture across the production people-search estate: how much automated traffic each zone absorbs, how effectively Cloudflare turns it away, where the residual risk concentrates, and how ready the estate is to consolidate onto a single bot-protection layer.
Figures on this page are illustrative placeholders. The assessments in the report library are authoritative and unmodified. Charts are wired to them in the next phase; until then, read the reports for any figure you intend to act on.
Protection score
62/ 100
Mean of 10 zones. The strongest zone already runs the target configuration; the spread between it and the weakest is the work.
Score weighs enforcement coverage, bypass exposure, and observed mitigation effectiveness.
Human vs bot
42%automated
Automated clients are a first-order requirement, not an edge case. Verified search and AI crawlers sit inside this band and must survive any tightening.
Highest risk
58/ 100
Ranked first by residual risk, then by lowest score: 30% automated traffic against a 21.2% block rate, with the managed WAF not enforcing.
Risk distribution
Cloudflare effectiveness
93.9%abandon
Challenged clients that gave up rather than proving they were human — the most direct available measure of deterrence.
Mean block rate 27.4%. Managed WAF is enforcing on 1 of 10 zones — the single largest unrealised control.
DataDome readiness
31%complete
Sequenced so the estate is standardised and proven at parity before a live defence is switched off. Reversible at every gate.
The decision gate is evidence-based: retire DataDome only once a parallel run quantifies its incremental catch.
Top priorities
Every item below is a configuration or discipline change on controls already licensed and deployed.
Move the managed WAF from detect-only to enforcing
Nine of ten zones deploy the managed ruleset without enforcement. No new spend required.
Close unproxied hostnames that bypass the edge
Public records expose paths that resolve straight to origin, making edge controls inapplicable.
Extend enforcing rate limits to search and API endpoints
Confirmed scraping targets sit behind log-only or absent rate-limit rules.
Run Cloudflare and DataDome in parallel to prove parity
Quantify incremental catch before retiring a live defence layer. Reversible by design.
1 further priority not shown.
Evidence
Composition is a share of scored traffic; unscored cached hits are excluded because they never reach the bot engine and would otherwise flatten every ratio.
Share of scored requests by bot-score band, bot-heaviest first.
Bands follow Cloudflare guidance: automated below 30, likely human at 80 and above, the remainder uncertain.
Blocks, challenges, and flagged threats across the evidence window.
Rising challenge volume alongside a stable block rate is the expected signature of behavioural enforcement doing the work.