Playbook for legal and ops stakeholders
Your main question is usually: "What is the site actually signaling, and what is it not claiming?"
Read first
Your risk model
You care most about:
- whether the language overclaims force;
- whether a policy signal is being misrepresented as hard control;
- whether documentation is being mistaken for runtime proof;
- whether public wording is reversible and auditable.
Do
- distinguish intent from enforcement;
- insist on precise wording around AI usage, archives, and scraping;
- keep published posture proportional to what the system really expresses;
- preserve reversibility and traceability.
Don’t
- present robots.txt as a legal shield;
- overstate protection against scrapers;
- imply that every declared signal is respected by every bot.