A customer types the right password three times and gets locked out anyway. She calls support. The agent asks her to describe what happened and opens a blank ticket. Nobody tells her that a system already watched the attempt, scored her as human, and let the block stand regardless.
That system is standard in enterprise stacks now. Akamai calls its version Bot Manager. DataDome and F5 sell competing versions under similar names. Fraud engines, multi-factor authentication gateways, real user monitoring dashboards: all of them instrument the same customer session a support agent will later ask her to describe from memory.
A Blocked Login and a Blank Ticket Are the Same Event, Twice
Security operations owns the system that saw the friction happen. Customer support owns the system that answers the phone after it does. The two rarely share a queue, a data feed, or a Tuesday morning standup. F5's research on bot economics found that CAPTCHA and multi-factor authentication, deployed to stop fraud, increase account lockouts and customer support call volume as a side effect of doing the job they were built for.
A CAPTCHA challenge alone can cut form conversions by up to 40 percent, according to Stanford research cited by DataDome. That number describes customers who gave up. It says nothing about the ones who called instead, and started the story over for a stranger.
Akamai Already Proved the Data Can Move
Akamai's real user monitoring product, mPulse, ingests classification data straight from Bot Manager. A company can look at one dashboard and see conversion and bounce rates split between human visitors and bot traffic. Akamai has documented a customer where bot traffic made up 30 percent of total volume and distorted every business metric the site's team relied on, until the two data sets were separated.
That integration is proof the wall between security telemetry and customer experience data can come down. No law or system architecture stops security classification data from living inside a customer experience tool.
The documented use case is analysis after the session ends: cleaning up a quarterly report, correcting a conversion metric. The open frontier is the live session itself, reaching the flagged customer or her care team while she is still on the page.
The Industry Already Knows the Move, Just Not From This Data
Proactive support platforms like FullStory already trigger in-session help from behavioral signals: repeated errors, stalled navigation, a customer who circles the same page three times. The technique works. It just runs on engagement data, not security data. A locked account or a failed CAPTCHA gets classified as a security event and handed to a different team's dashboard, even though a proactive support tool would already act on the same kind of signal if it turned up anywhere else on the page.
The cost of leaving that signal stranded is measurable on the help desk side of the house. Citing Gartner research, Avatier puts password resets and account lockouts at 20 to 50 percent of service desk calls, with Forrester estimating $70 or more in labor cost per reset.
Some of those calls are legitimate account recovery, and a human should handle them.
Nobody is proposing that number should be zero.
The Contract Never Asks for the Handoff
Procurement conversations for bot management, fraud scoring, or real user monitoring rarely include a line for what happens the moment the system flags a real customer instead of a bot. That question gets answered later, if at all, usually after a support cost report lands on a CFO's desk and someone asks why lockouts are still driving call volume a year after the fraud tool went live.
Building the handoff by hand means custom middleware, a shared identifier between the security platform and the support platform, and an owner willing to sit in both meetings. Most companies skip it. The security team hits its detection targets. The support team answers its calls. The customer is the only one who experiences both systems as one bad afternoon.
The Fix Needs a CIO, a CX Leader, and a Product Leader at the Same Table
Pendo already closes half of this loop from the product side. It flags behaviors that signal risk, low feature adoption or an inactive user, and targets that exact cohort with an in-app guide before the account churns. Nothing in Pendo's stack looks at a bot manager or a fraud engine. Nothing in Akamai's stack looks at feature adoption. Both platforms already do proactive, in-session intervention. They intervene on different signals, owned by different budgets.
Closing that gap is an org chart problem before it is an integration problem. The CIO owns the security and observability contracts, tools like Akamai's, Datadog's, or Dynatrace's, that see the friction first. The CX leader owns the support budget that absorbs the cost when nobody acts on it. The product leader owns Pendo or an equivalent adoption platform that already knows how to trigger a message inside a session. None of the three has a reason to call this meeting alone.
A CIO who brings CX and product into the same room can define one shared customer identifier across the security, observability, and product stacks, then agree on what a verified friction event should trigger: an in-app message the customer sees before she reaches for the phone, or a queue alert a live agent sees before she dials.
Bring your CX and product leaders to the next security or observability renewal and ask one question together: can this platform hand a verified friction event to Pendo, or whatever adoption tool you already own, so it reaches the customer or her care team inside the same session? If the three of you have never asked that question in the same room, the handoff will keep getting built by hand, one support cost report at a time.
Akamai. "Visualize and Analyze Bots With Real User Monitoring." Akamai, 2026, akamai.com.
Avatier. "The Hidden Cost of Password Reset Tickets: Beyond Help Desk." Avatier, 2026, avatier.com.
DataDome. "How False Positive Rates Impact Conversion Rates." DataDome, 2025, datadome.co.
F5. "From Bots to Boardroom: How Bad Bots Negatively Impact Your Balance Sheet." F5, f5.com.
FullStory. "Proactive Customer Care: Anticipate Needs, Prevent Friction and Earn Trust." FullStory, 2026, fullstory.com.
Pendo. "Pendo for Product Teams and Beyond." Pendo, 2026, pendo.io.
