There's one sentence in Cloudflare's July 1, 2026 traffic policy I have not been able to put down. Picture a company whose automation does three jobs: builds a search index, acts for users in real time, gathers training data. The post's advice is that such a company "separate the automation into three separate crawlers." The reason offered is transparency. Site owners should be able to see why something showed up and rule on each purpose independently. Then, one breath later, the enforcement. From September 15, defaults resolve to the most restrictive applicable rule, so a single identifier classified for search and training gets blocked everywhere training is blocked.
If you read policy for a living, that's a taxonomy. If you're the one who ships the crawler and carries the pager when it quietly stops working, it's an invoice. Your architecture just picked up a compliance cost, and the line item is the name your traffic wears.
Keep pulling on it. The label was there so a site could make a trust call. But calls made per identifier don't evaporate after they're made; the identifier starts accumulating a past. Cloudflare's verified bot criteria describe a crawler that identifies itself deterministically and hasn't abused what identifying itself bought, and then they list the ways you lose that standing. IP ranges you didn't disclose. Traffic that doesn't match the purpose you declared. Ignoring crawl-delay. Nobody calls it this, but that's a credit file, and you only have one because you agreed to be named in the first place. Traffic that stays anonymous doesn't get a history. It gets heuristics.
Now the other column, because there is one. Under the announced defaults, search stays allowed where agent and training traffic get blocked on ad-supported pages for new domains, which means the declared identity is the only reason an entire category of your work still moves at all. Non-verified traffic is default-blocked. Verification buys you eligibility, judged against your own behavior and the site owner's settings, instead of a coin flip against heuristics. Being nameable is also how you stay separable from whatever is currently getting hammered. Which turns into a pricing question, and it's yours to answer: at what request volume does the access justify carrying the file? Nobody outside your team can compute that number.
Files get pulled. In August 2025 Cloudflare de-listed Perplexity's crawlers and shipped heuristics to block them; Perplexity disputed the attribution and later pointed at a third-party service it used occasionally. Set aside who had the better case and look at the shape of it. Your company's reputation and your identifier's reputation are now two separate objects with two separate histories, and the one that decides whether you get through the door isn't the one your marketing team owns.
Which makes the defensive move obvious and completely rational. Stop hanging five jobs off one name. Decompose by purpose so that one purpose having a bad week doesn't cost the other four their access. I've watched architecture get bent by deploy risk, by blast radius, by who's holding the pager at 3 AM. Add this to the list. There isn't an engineering reason anywhere in it.
The multi-tenant case is where I start grinding my teeth. Cloudflare's documentation splits a direct identity, one narrow operator presenting as one bot, from an intermediary identity, where a crowd of end users act through software a single platform runs. Under an intermediary, somebody else's aggressive session arrives wearing your recognized name. The machinery for forwarding end-user context, so a site can tell the platform apart from the party actually responsible, is still described as experimental. Until it lands, your standing is partly a function of your loudest tenant. Anyone who has run multi-tenant anything already knows how that story goes.
Splitting doesn't firewall you either. You can publish distinct Web Bot Auth client IDs and separate discovery entries, and yes, narrow agents get legible that way. But the pieces still live under one publisher domain, and the identity drafts under discussion tie separately registered agents back to a common accountable principal. Your decomposition is visible, and it resolves back to you.
None of this is a Cloudflare quirk. Cloudflare is just where the pattern is easiest to read. Visa's Core Rules, effective April 18, 2026, require an agentic payment provider to enroll and register before it can run the formally defined transaction flow, with immediate termination for cause written into the text. Identification is the condition of admission, and there it sits inside rules that actually bind.
So here's the gradient you're choosing on. Declare yourself: you get eligibility, plus a file that can be downgraded over something a tenant did. Say nothing: you get neither trust nor penalty, which is a worse business and a much quieter life. Quieter is relative, though. Controlled measurements found agents that bypassed every anti-bot mechanism evaluated and stayed distinguishable from humans, and from each other, through combined network, HTTP, and browser fingerprints. Distinguishable is not identified. Something the web can recognize but cannot name is something nobody can hold to anything.
Recognized and unaccountable is the worst state on the menu. It's also the one the incentives are quietly pushing everybody toward.
- The September 15 squeeze: Watch whether operators of mixed-purpose crawlers actually split them before the new defaults bite, since independent coverage read the policy as a deadline for separating search traffic from agent and training traffic.
- Fixed or per-task identity: The question underneath all of this is still formally open, with NIST's identity concept paper asking whether agent metadata should be durable or task-dependent and where the boundary sits.
- Registration without remedy: Live agentic transactions are running across more than 30 European issuers, but the public record still reports no dispute outcomes for cases where the user authorized the agent and contests what it chose.
- When behavior outruns the name: If identifiers become expensive to carry, expect more attention to the fingerprinting work showing that typing, scrolling, and mouse activity separated seven browsing agents that a commercial detector largely missed.

