Applies to: Khoros Communities (Classic and Aurora).
Audience: community managers, administrators, and anyone asked "what is this bot protection?"
See also: Allowing your monitoring tools and API integrations through CommunityGuard.
The basics
What is CommunityGuard?
CommunityGuard is an advanced intelligence layer for the AI-bot era, deployed and managed by Khoros in front of your community. It identifies AI crawlers, scrapers and human-mimicking automation, and deals with them before that traffic ever reaches your community's servers. Your team gets enterprise-grade bot protection without implementing or maintaining a separate solution.
Why does my community need it?
The internet has changed. Across much of the web, automated traffic now exceeds human traffic, and online communities are no exception. AI crawlers, scrapers and automated agents:
- drive up infrastructure load and can cause the traffic spikes behind slowdowns and outages;
- count as visitors in analytics, so your engagement numbers overstate real activity;
- count as usage against your contract, so they can push you into overage charges;
- take your community's content in bulk while sending almost nothing back. A search engine sends a visitor back for every handful of pages it crawls; AI services crawl thousands, sometimes tens of thousands, of pages for each visitor they return.
Traditional firewalls ask "does this request match a known attack?" CommunityGuard asks "is this visitor actually human?"
Does it replace the firewall and spam protection my community already has?
No. The platform's existing protections (web application firewall, spam filters, rate limiting) keep covering known attack signatures such as credential stuffing, denial-of-service attempts and spam. CommunityGuard adds two layers on top:
| Layer | What it does |
|---|---|
| Platform protection (included) | Firewall rules, spam filters and rate limiting against known attack signatures |
| AI content protection | Identifies AI crawlers individually and applies your policy to each: allow, rate-limit or block AI assistants, AI search and AI-training crawlers independently |
| AI agent and synthetic traffic detection | Behavioural scoring, device fingerprinting, protocol analysis and machine-learning models detect automation that pretends to be a person |
Your visitors
Who actually visits my community?
CommunityGuard sorts every visitor into one of four classes.
| Class | Who they are | Without CommunityGuard |
|---|---|---|
| Real users | People in real browsers. The audience your community exists for. | Normal access. Counted correctly. |
| Declared bots | Bots that identify themselves and can be verified, such as Googlebot and Bingbot. | Long-established names were already recognised. Newer crawlers slipped through as "users" until someone added them to a list. |
| Named AI services | The AI companies (OpenAI, Anthropic, Perplexity, Google AI, Meta, Apple, Amazon, Microsoft, ByteDance and others), recognised by name. | Visible in logs but unmanaged: full load on your community, no per-service control, often counted as users. |
| Anonymous scrapers | Unknown operators on residential proxy networks and bulk datacenter fleets, using spoofed browser identities, plus impostors wearing a famous bot's name. | Invisible. Counted as users, billed as users, and fought only after a spike. |
What does CommunityGuard do with each visitor?
Every request gets exactly one of four outcomes.
| Outcome | Meaning |
|---|---|
| Allowed | The request reaches your community normally. |
| Challenged | The visitor is asked to prove it is human before the request goes any further. A real browser passes the check automatically and the request is then allowed; automation cannot complete it and gets no further. |
| Rate-limited | The request is served, but the visitor is throttled to a sustainable pace and cannot hammer the site. |
| Blocked | The request is denied before it reaches your community. |
Whatever the outcome, every request is labelled with its class, and that label is what keeps bot traffic out of your user metrics.
By default: real users are allowed, verified search engines are allowed, named AI services are rate-limited, and anonymous scrapers are challenged or blocked.
Will my real users notice anything?
In practice, no. Real users in real browsers are effectively never challenged. When a check is issued, it runs automatically inside the browser and usually completes without the visitor doing anything. The observed false-positive rate is below 0.1%.
If a specific person on your community reports being blocked, ask them for the URL, the time and their network (office, VPN, home) and open a support case. Shared corporate networks and VPN egress points are the most common reason a real person looks like automation.
Will CommunityGuard hurt my search rankings?
No. Verified search engines such as Googlebot and Bingbot are never blocked, in any configuration. That guarantee is built into every CommunityGuard posture. Throttling an abusive crawler remains available as a deliberate, per-community choice, and even then the crawler still receives your content.
Impostors are a different matter. On one high-traffic community, 8.4% of traffic claiming to be Googlebot came from datacenter bots wearing Google's name. CommunityGuard verifies the identity rather than trusting the name, so those impostors are treated as the scrapers they are, and the real Googlebot is unaffected.
What about AI crawlers such as OpenAI, Anthropic, Perplexity or Google AI?
That is your decision, per service. For each named AI service you can choose:
- Allow if you want that service to have your content without restriction;
- Rate-limit (the default) if you are happy for it to have your content, but at a pace your community can sustain;
- Block if your content is your value and no AI service should take it.
In every case the traffic is labelled as bot traffic and excluded from your user metrics, so allowing an AI service never inflates your analytics or your usage. Anonymous scrapers stay blocked regardless of how you set the named services.
Your community
Does CommunityGuard change my analytics or my billing?
It makes both more accurate. Automated traffic is labelled and excluded from user metrics even when it is allowed through, so analytics reflect real engagement and billable usage reflects real people. Customers typically see less load, cleaner numbers and a lower risk of overage charges.
Can I see what CommunityGuard is doing on my community?
Yes. Your Customer Success Manager can share a CommunityGuard report for your community covering:
- Traffic composition: how much of the traffic arriving at your community is human, declared bots, named AI services and anonymous scrapers;
- Enforcement outcomes: what was allowed, challenged, rate-limited and blocked;
- Load with and without CommunityGuard: the traffic that arrived versus the traffic that reached your community, with the gap being the load removed;
- Who the bots are: every named bot on your community, how much it consumed, and its current policy.
The comparison is measured on live traffic every day, not estimated.
Could my own IT team do this instead?
Similar protection can be implemented independently, but it would sit in front of a platform your team does not operate. CommunityGuard is tuned for how Khoros Communities behave, is managed by the people who run the platform, and is offered with Khoros's implementation expertise and preferred pricing.
Getting help
How do I change the policy for a specific bot?
Open a support case naming your community, the service (for example "Perplexity" or "GPTBot") and the outcome you want: allow, rate-limit or block. Search engines can be allowed or rate-limited but not blocked. Changes are applied by Khoros and confirmed in your case.
My monitoring tool or integration is being blocked. What do I do?
Automation that you run yourself, such as an availability monitor or a server-to-server API integration, can be granted a scoped exception. See Allowing your monitoring tools and API integrations through CommunityGuard for what to include in your case. Exceptions are not available for crawlers or bulk content downloads; those go through the Khoros data export process.
Is bot traffic really that big a problem?
Independent industry sources on the trend:
- Thales (Imperva) 2025 Bad Bot Report: automated traffic now exceeds human traffic, at 51% of global web traffic.
- WP Engine 2025 Website Traffic Trends Report: bot-heavy traffic and its performance cost, measured with first-party data.
- Google Cloud Threat Intelligence on the IPIDEA residential proxy network: how residential proxies let bots look like home users.
- PCWorld on 9 million Android devices hijacked into a proxy network: the scale of consumer devices feeding proxy infrastructure.
- Forrester renamed the market category from "Bot Management" to "Bot and Agent Trust Management" in late 2025; every major security vendor now ships a dedicated AI-traffic product.
Keyur Saxena
Comments