> ## Documentation Index
> Fetch the complete documentation index at: https://docs.repdata.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Respondent Status Codes

> inbound_code and isc values Research Desk records for every respondent session, including SEARCH threat codes.

Every respondent session in Research Desk ends with a status. You program **client-side** outcomes on your `rdsecured.com/return` redirects. Research Desk assigns additional statuses when it blocks, terms, or over-quotas a respondent before or during the survey.

Use this page to interpret traffic reports, ID lookups, and Defender exports. For how to program the client-side redirects, see [Entry Links and Redirects](/research-desk/guides/04-entry-links-and-redirects).

Research Desk records two related values for every respondent session:

| Field          | Where it appears                                                                     | What it means                                                              |
| -------------- | ------------------------------------------------------------------------------------ | -------------------------------------------------------------------------- |
| `inbound_code` | Client redirect URLs (`rdsecured.com/return`), traffic reports, Demand API responses | High-level outcome family (complete, term, security, over-quota, Defender) |
| `isc`          | Supplier callback links, traffic reports                                             | Specific reason within that family                                         |

Client survey platforms program **client-side** `inbound_code` values on return redirects (`1000`, `2000`, `3000`, `4000`). Research Desk assigns **Desk-side** codes (`1`, `5000`, `6000`) when it terms or over-quotas a respondent before or during the session. The `isc` is always returned on the supplier callback link.

An **Abandon** is recorded when no recognized redirect fires. It is not an `inbound_code`.

## Code families

| inbound\_code | Definition                | Assigned by     | Supplier redirect |
| ------------- | ------------------------- | --------------- | ----------------- |
| `1`           | RDefender Term            | Research Desk   | Security          |
| `1000`        | Complete                  | Client redirect | Complete          |
| `2000`        | Term                      | Client redirect | Term              |
| `3000`        | Client-Side Security Term | Client redirect | Security          |
| `4000`        | Client-Side Overquota     | Client redirect | OQ                |
| `5000`        | Research Desk Term        | Research Desk   | Term              |
| `6000`        | Research Desk Overquota   | Research Desk   | OQ                |

## isc reference

### inbound\_code `1` — Research Defender Term

Respondent did **not** reach the client survey. Redirected to the **Security** supplier link.

| isc | Definition                                                      |
| --- | --------------------------------------------------------------- |
| `2` | Failed on Research Defender SEARCH module                       |
| `3` | Failed on Research Defender ACTIVITY module                     |
| `4` | Failed on Research Defender REVIEW module                       |
| `5` | Failed on Research Defender Complete module                     |
| `6` | Failed on Research Defender SEARCH — higher CPI / higher threat |
| `8` | Failed on Research Defender REVIEW — not contextually correct   |

### inbound\_code `1000` — Complete

Respondent reached the client survey. Redirected to the **Complete** supplier link.

| isc    | Definition |
| ------ | ---------- |
| `1000` | Complete   |

### inbound\_code `2000` — Term

Respondent reached the client survey. Redirected to the **Term** supplier link.

| isc    | Definition                                           |
| ------ | ---------------------------------------------------- |
| `2000` | Client-side term (for example, a screening question) |

### inbound\_code `3000` — Client-Side Security Term

Respondent reached the client survey. Redirected to the **Security** supplier link.

| isc    | Definition                        |
| ------ | --------------------------------- |
| `3000` | Survey quality term (client side) |

### inbound\_code `4000` — Client-Side Overquota

Respondent reached the client survey. Redirected to the **OQ** supplier link.

| isc    | Definition                      |
| ------ | ------------------------------- |
| `4000` | General overquota (client side) |

### inbound\_code `5000` — Research Desk Term

Assigned by Research Desk. Redirected to the **Term** supplier link.

| isc    | Definition                                                                             | Reached client survey |
| ------ | -------------------------------------------------------------------------------------- | --------------------- |
| `5001` | Stream closed (Research Desk)                                                          | No                    |
| `5003` | Qualification mismatch. `TermedQualificationID` is appended on the supplier term link. | No                    |
| `5004` | Device compatibility mismatch                                                          | No                    |
| `5005` | Invalid L2 voter match                                                                 | No                    |
| `5006` | Suspicious device (bot-like detection)                                                 | No                    |
| `5007` | Sample group exclusion term                                                            | No                    |
| `5008` | Respondent list mismatch (recontacts / inclusions)                                     | No                    |
| `5009` | Qualification verification mismatch                                                    | No                    |
| `5101` | Attempted bypass of client survey                                                      | No                    |
| `5102` | Encryption failure (hashing)                                                           | Yes                   |
| `5103` | Speeder term (under 30 seconds or under 20% of LOI)                                    | Yes                   |
| `5104` | Suspicious re-entry attempt                                                            | Yes                   |

### inbound\_code `6000` — Research Desk Overquota

Assigned by Research Desk. Respondent did **not** reach the client survey. Redirected to the **OQ** supplier link.

| isc    | Definition                                                                                       |
| ------ | ------------------------------------------------------------------------------------------------ |
| `6001` | Overall quota achieved (Research Desk)                                                           |
| `6002` | Sub-quota achieved (Research Desk). `TermedQuotaID` is appended on the supplier over-quota link. |
| `6003` | In-survey maximum exceeded (Research Desk)                                                       |

## SEARCH threat codes (rdThreat)

When `isc=2` (SEARCH failure), Research Desk appends an `rdThreat` value to the supplier redirect. These codes identify the SEARCH signal that terminated the respondent.

| rdThreat | Termination reason                    | Explanation                                                                                                                                                                                                                               |
| -------- | ------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `02`     | Duplicate entrant into survey         | The respondent has already attempted this survey, detected via IP address or digital fingerprint.                                                                                                                                         |
| `03`     | Emulator usage                        | Emulator software can recreate browsers, machines, and operating systems, and spoof other devices. Emulators also allow a respondent to create unique digital fingerprints on a single device.                                            |
| `04`     | VPN usage detected                    | VPN use alone does not fail SEARCH. Combined with a public proxy and an internet-fraudster flag, VPN usage has a high correlation to fraudulent activity and is terminated.                                                               |
| `05`     | TOR network detected                  | TOR conceals a user's location. TOR use alone does not indicate fraud, but combined with other flags it contributes to the fraud likelihood. This status means the respondent is currently using TOR or has been linked to a TOR network. |
| `06`     | Public proxy server detected          | A proxy is an intermediary between the respondent and a remote connection. This status means the respondent is accessing the survey through a publicly available proxy server, which can be used by multiple respondents at once.         |
| `07`     | Web proxy service used                | Web proxies are a subset of public proxies that can be accessed via the internet with no software or security.                                                                                                                            |
| `08`     | Web crawler usage detected            | The respondent has been linked to web-crawling activity, which has a high correlation to fraudulent activity, especially in ad-tech.                                                                                                      |
| `09`     | Internet fraudster detected           | The respondent has been linked to general fraud or abuse on the internet, flagged by one or more third-party vendors that compile digital-fingerprint databases of historically fraudulent respondents.                                   |
| `10`     | Retail and ad-tech fraudster detected | Same as `09`, except the respondent was flagged for fraud or abuse specifically in retail or ad-tech.                                                                                                                                     |
| `11`     | Subnet detected                       | A subnet recreates an IP address to spoof technologies that look for a direct match, making an IP address appear unique.                                                                                                                  |
| `12`     | Recent abuse detected                 | The respondent was recently flagged for fraud or abuse by a fraud-prevention provider (similar to `09`).                                                                                                                                  |
| `13`     | Duplicate survey group detected       | Deduplication at the survey group / project level.                                                                                                                                                                                        |
| `14`     | Navigator Webdriver detected          | SEARCH detected automation tools (Selenium, Puppeteer, Playwright) in the respondent's browser or machine.                                                                                                                                |
| `15`     | Developer tool detected               | SEARCH detected a developer-tools window open in the respondent's browser, often used to manipulate API responses or digital fingerprints.                                                                                                |
| `16`     | WebRTC detected                       | WebRTC lets SEARCH identify respondents attempting to hide their IP addresses and store the actual IP. This failure is always returned for Threat Potential scores of 31 when 31 is configured as a medium threat level.                  |
| `17`     | Proxy detected                        | A T-Mobile proxy was detected on the respondent's session.                                                                                                                                                                                |
| `18`     | MaxMind failure                       | The respondent was flagged as a known internet fraudster.                                                                                                                                                                                 |
| `19`     | Batch fraud entrants                  | Automatically flags respondents when large groups of survey completes are submitted within unusually short intervals — often seconds or minutes apart.                                                                                    |
| `20`     | ChatGPT / Claude emulators            | ChatGPT or Claude emulators and similar automated programs can mimic human behavior. These devices are tracked so survey responses are not automated.                                                                                     |
| `21`     | Previous explicit behavior            | Respondents with a history of poor or fraudulent activity in the Defender ecosystem, flagged from prior explicit behavior patterns.                                                                                                       |
| `22`     | Obfuscation mechanisms detected       | Virtual environments or privacy tools (for example, incognito mode) used to conceal true respondent identity or activity.                                                                                                                 |
| `23`     | SEARCH locale detected                | SEARCH found a mismatch between the session's language or regional settings and the project's configured locale.                                                                                                                          |

## Related guides

* [Entry Links and Redirects](/research-desk/guides/04-entry-links-and-redirects)
* [Research Defender](/research-desk/guides/21-research-defender)
* [Exporting and Reporting](/research-desk/guides/12-exporting-and-reporting)
* [Glossary](/research-desk/support/glossary)
