A bot alert gets your attention. Understanding what that traffic is doing tells you where to look next.

Is it returning to the same article? Working through dozens of different pages? Requesting numbered resources in sequence? A detection count can’t answer those questions on its own, and reading individual requests takes work.

AI Journey Insights turns an actor’s observed requests into a short, inspectable explanation. Open a journey in WebDecoy to see likely collection targets, supported access patterns, and the requests behind the observed behavior.

You get a starting point for the investigation, with the evidence already connected.

Two patterns that deserve different investigations

Two samples from traffic to webdecoy.com show why this matters.

In one journey, 38 of 48 sampled requests returned to the same article. Forty of the requests used article or documentation routes. The useful takeaway was the concentration on a particular piece of content, with repeated requests at different times.

Another journey reached 45 distinct targets across 48 sampled requests. Most targets were requested once. The busiest target was /robots.txt, with four requests. Thirty-six requests used article or documentation routes.

Both samples included substantial interest in content. Their request patterns were very different:

Observed sampleWhat stands outWhere to start investigating
38 of 48 requests to one articleRepeated attention to a specific targetInspect the repeat requests and their timing
45 distinct targets in 48 requestsBroad coverage with little repetitionReview the path distribution and pages reached

These are two observed samples, not a benchmark for all bot traffic. But they illustrate the question customers need answered: what is distinctive about this actor’s activity?

Journey Insights brings that distinction to the top of the page. For the second sample, the headline reads:

This sample reaches 45 distinct targets, mostly requesting each once.

That is a more useful place to begin than a long list of URLs.

AI interpretation with evidence you can follow

The AI classifies two aspects of an eligible journey: the information the traffic appears to seek and the access strategy supported by its request sequence.

Likely targets can include articles and documentation, prices, inventory, reviews, or contact information. Access patterns can include repeated checks, pagination, numbered resources, or archive dates. When the evidence is unclear, the result can remain undetermined.

Alongside those classifications, WebDecoy computes observations from the saved sample. A finding can show how many requests used article routes, which requests returned to a target, or which ordered paths support a sequence.

Expand Inspect matching requests to see that evidence. Select a request to open its detection details. You can follow the explanation all the way back to the event you are investigating.

Those observations help you assess the AI’s interpretation. They are measured facts from the sample, rather than a generated explanation presented as proof.

Useful facts, even when the strategy is unclear

Sometimes the paths suggest interest in your content without establishing how the actor navigated it. Journey Insights still gives you three ways to understand the activity.

Breadth shows how much ground it covered. See the number of distinct original targets and expand the path distribution to find the routes represented in the sample.

Concentration shows where its attention went. See the busiest target’s share and inspect its matching requests. A sample spread across many targets warrants a different investigation from one dominated by a single article or endpoint.

Timing shows how the observed requests arrived. Inspect the busiest 60-second window and the longest gap between sampled requests. Expand the timing details to review activity groups and their individual detections.

These measurements remain available when the AI does not identify a clear access strategy. You can still work from concrete evidence.

Go from a detection to an explanation

The feature lives where you already investigate an actor:

  1. Open Actors and select the actor you want to understand.
  2. Open Journey for the relevant property.
  3. Read the takeaway and review the likely target and access strategy.
  4. Expand a finding or a behavior measurement to inspect the requests behind it.
  5. Use View full sample to check the observation dates, coverage, and all analyzed requests.

The observed journey remains below the insights panel, giving you the broader investigation view alongside the explanation.

Analysis runs when you open an eligible journey. Saved results are reused, and expanding evidence does not request another AI analysis. When newer evidence is available, you can explicitly update the analysis.

Know what the explanation covers

Scope is part of the result. A panel that says 48 of 686 requests analyzed describes those 48 requests, with their observation dates visible. It does not claim to explain every request in the actor’s history.

The analysis uses up to the latest 48 stored requests. Earlier activity and traffic that was not recorded may differ. Activity groups are separated by gaps in the sample; they are not verified sessions or proof that nothing happened between observations.

Redaction also matters. Different original URLs can look identical after sensitive values are removed. WebDecoy checks whether the saved data supports exact target grouping before assigning repeat evidence or a target’s share of requests.

And a likely collection target is an inference. It does not establish successful collection, malicious intent, or who operates the traffic. Journey Insights leaves threat scores and enforcement decisions unchanged, giving you evidence to review before you decide what to do.

Start with the actor you want to understand

For a content team, the next question may be which articles attract repeated attention. For an engineer, it may be whether requests are spread across routes or concentrated on one endpoint. For an analyst, it may be which detections deserve a closer look.

AI Journey Insights gives each of them a clearer starting point: a takeaway, observed behavior, and direct access to the supporting requests.

Open WebDecoy and investigate an actor’s journey.

New to WebDecoy? Explore AI Journey Insights and the detection platform, or see how WebDecoy measures AI crawler activity and referrals.

Frequently Asked Questions

Where do I find AI Journey Insights? +

Open Actors in WebDecoy, select an actor, and open its Journey tab for the property you want to investigate. Eligible journeys are analyzed on demand. The panel shows a takeaway, AI classifications, observed sample behavior, and links to the underlying detections.

Does AI Journey Insights analyze every request? +

It uses a bounded sample of up to the latest 48 stored requests for the selected actor and property. The panel shows the sample count, full stored count, and observation dates. Earlier or unrecorded traffic may behave differently.

Does the AI decide which traffic to block? +

No. Journey Insights helps you investigate likely collection targets and access patterns. It does not change threat scores or enforcement decisions. Review the supporting detections before deciding how to respond.

Want to see WebDecoy in action?

Get a personalized demo from our team.

Request Demo