# Verdicts

A verdict is Octet's estimate for one session: the country the session appears to operate from, how certain Octet is, and how much the session's signals contradict that country. The exact field list is in [Verdict Reference](/docs/browser/reference/verdict/).

## `country`

`country` is an ISO 3166-1 alpha-2 code, for example `"GB"`. Territories come back as their own codes, not their parent country's. Puerto Rico is `"PR"`, not `"US"`, and Guam is `"GU"`. If your policy covers a country and its territories, list every code.

`country` is absent when Octet could not estimate one. Treat an absent `country` as unknown, not as a pass.

## `confidence`

`confidence` is a number from `0` to `1`. It measures how certain Octet is of `country`. To judge whether the connection is masked, use `alarm`, not `confidence`.

## `alarm`

`alarm` has four levels:

| Level | Meaning |
|---|---|
| `none` | Nothing contradicts `country`. |
| `low` | A minor inconsistency. A traveller, or someone whose device is set up for another country, looks like this when there is no sign of masking. `country` is still the best estimate. |
| `medium` | The connection appears masked, for example by a VPN or proxy. Don't trust `country`. |
| `high` | The connection is masked, and the user appears to be in the returned `country`. It is also `high` when the device itself points to a country under comprehensive sanctions, masked or not. |

At `high`, `country` is the country Octet estimates the user is really in, which can differ from the country of their IP address.

## Choosing a policy

You decide what each verdict means for your service. A common starting point for a regulated action:

```js
const RESTRICTED = new Set(['US', 'PR', 'GU', 'VI', 'AS', 'MP', 'UM']);

function needsKyc(verdict) {
  const masked = verdict.alarm === 'medium' || verdict.alarm === 'high';
  const restricted = verdict.country === undefined || RESTRICTED.has(verdict.country);
  return masked || restricted;
}
```

This requires KYC when `country` is on your list, when there is no `country`, or when `alarm` is `medium` or above. Adjust the list and the action to your own obligations. Octet makes no decision for you.

A few rules hold for any policy:

- Read the verdict on your backend. Never act on anything the browser reports.
- Treat `medium` and `high` as reasons to distrust `country`.
- Don't block on `low` alone. It is how honest travellers usually appear.
