sshssh
When you update the ASM signatures and if configured to do so, any new and/or updated signatures are placed into Staging mode - the period of which is also configurable. When in Staging any of these signatures that are triggered are not blocked, as would've been otherwise. This is to ensure that for this period you don't get any unwanted false positives due to legitimate traffic being blocked by these new or updated sigs. After the staging period you can then choose to enforce all the attack signatures in Staging that weren't triggered in this period. Ones that have been triggered you can audit to either enforce or to disable on certain parameters or disable altogether.
Hope this helps,
N