TRAFFIC ORCHESTRATION RULES

Decide who gets in, in what order, under what conditions

Turn traffic signals into automated decisions with flexible rules for access, abuse protection, customer experiences, and infrastructure control.

Orchestration Rules

Signal, condition, action: what an orchestration rule is

Every traffic decision starts with a signal, a condition, and an action.
Queue-it continuously evaluates traffic and automatically applies the right response in real time.

The signal:
what the engine sees

Every request carries signals about identity, intent, and context, whether it comes from a customer, bot, or AI agent

The condition:
when a rule applies

Stack conditions with match-all or match-any logic to distinguish customers from bots, VIPs from visitors & normal traffic from exceptional demand

The action:
what happens next

The engine acts the instant a rule matches: who gets access, who waits, who gets challenged & who gets blocked

Four stages of automated traffic control

Integration rules dashboard

EVALUATE

Decide what Queue-it evaluates with Integration Rules

  • Define which pages, actions and APIs Queue-it evaluates with Integration Rules, from your full site to a single “Add to Cart” action
  • Minute control based on six trigger parameters: URL (host, path or full address), HTTP header, user agent, cookie, request body, and JavaScript
  • Exempt static assets and good bots with Ignore rules, from search crawlers to AI agents you welcome, so they never cost you SEO or a queue spot

FILTER

Decide who gets access with Traffic Access Rules

  • Challenge, hard block or bypass visitors with Traffic Access Rules that go live the moment you publish, with no redeployment
  • Segment traffic on 12 condition types, from IP, ASN and user agent to classifiers refreshed every 24 hours
  • Block or challenge bad bots with Visitor Reputation, a dynamic 0–100 trust score spanning seven levels from Genuine to Malicious
  • Integrate seamlessly with best-in-class bot detection from Akamai or Netacea and act on their signals directly in your rules
Traffic Access Rules dashboard

CONTROL

Decide how fast traffic reaches your systems with the virtual waiting room

  • Control how many visitors reach your systems by activating a waiting room when demand exceeds capacity, preventing overload and crashes
  • Allocate limited inventory fairly with access mechanisms like randomization, first-in-first-out queuing, and invite-only entry
  • Deliver transparent wait information and an interactive, on-brand visitor experience

MANAGE

Decide what happens after entry with session management

  • Control session validity to the minute and choose whether sessions can extend, so capacity recycles
  • Enforce one purchase per user journey with a Cancel Action, invalidating sessions after key actions like checkout
  • Run additional checks at the point of purchase to ensure the visitor has followed the correct journey

Flip the switches

The traffic orchestration simulator models a live onsale: flip the three rule groups (fast-track trusted, screen suspicious, stop malicious) and watch outflow quality rise while your origin holds steady

Traffic Orchestration Simulator
Product drop scenario · configurable inflow
Attempted
visitors/min
Inflow quality
% human before any rules
Blocked + failed
0/min
Traffic stopped
Reaching origin
500/min
of 5,000 attempted
Outflow quality
Origin status
Stable

Customize your rules for cost, control & customer experience

Commonly asked questions

They work at different stages of control. Integration Rules decide what Queue-it evaluates: which pages, actions, and APIs, triggering on six condition types like URL, cookie, and user agent. Traffic Access Rules decide the treatment matching traffic gets: challenge, hard block, or bypass. In short, Integration Rules put requests in front of your policy, and Traffic Access Rules decide how the policy answers.

They can't. Rules evaluate in priority order, top-down, and the first matching rule wins. Place specific rules first and broad rules last, and the outcome is always predictable. You can rearrange, enable, or disable rules at any time from the GO Platform.

No. Integration Rules run inside your connector, at your CDN edge or on your server, as part of normal request handling. Traffic Access Rules are enforced on Queue-it's infrastructure, before traffic ever reaches the waiting room or your site.

Traffic Access Rules are part of the Bots & Abuse feature on your Queue-it subscription. Everything else described on this page, from Integration Rules to flow control and session settings, is configured per waiting room. Book a demo and we'll map the right setup to your traffic.

Yes. Traffic Access Rules go live the moment you publish, with no redeployment of your integration. Rules and outflow are adjustable in real time via the GO Platform or API. Alerts flag aggressive IPs and unusual behavior as they happen, and the Monitor dashboard shows the effect of every change live.

You can integrate Queue-it with a client-side, server-side, edge, or mobile SDK connector. Queue-it offers over 25 connectors and dedicated support staff for implementation.

Explore integrations

Turn your business logic into rules that run 24/7

Control your online traffic with orchestration rules

Decathlon logo
Sydney Opera House logo
Pokemon Center logo
Cathay Pacific logo
Ticketmaster logo
Minnesota State logo