SessionSight · /// Enterprise Session Replay
Watch what users actually did. Without compromising privacy.
Two replay modes: screenshot slideshow OR DOM reconstruction. Fixed-speed dropdown from 0.25× to 12× (eight values). Capture-time DOM masking with Strict, Balanced (default), and Relaxed modes. Fail-closed by default, with per-element overrides. RBAC-bound replay access. DEM that survives a privacy review.
Slideshow or DOM reconstructionCapture-time DOM maskingRBAC-bound replay access
Session replay. Screenshot slideshow or DOM reconstruction with fixed-speed scrub.
The Problem
Session replay vs privacy review.
Session replay is the strongest DEM tool for understanding why a user did what they did. And the biggest privacy-review risk. Most replay tools struggle in regulated industries; the trade-off feels binary.
Sensitive fields captured by default.
Standard session-replay tools capture everything in the DOM. Including password fields, PII, financial data. Privacy reviews block deployment in regulated industries.
Data leaves the boundary.
Some replay platforms route session data to vendor-hosted clouds, often outside the customer’s preferred boundary. Regulated industries can’t accept that path.
Anyone with access sees everything.
Replay tools without granular RBAC let any logged-in user watch any session. Privacy reviews require per-role, audit-tracked access.
Why SessionSight for enterprise replay
DOM-fidelity + privacy controls.
SessionSight ships the DOM-fidelity replay enterprise DEM teams need, with the privacy controls regulated industries require. Capture-time DOM masking, RBAC-bound access, fixed-speed scrub.
Two replay modes
Screenshot slideshow OR DOM reconstruction. See exactly what the user saw, exactly when. Clicks, scrolls, and form interactions are captured for stepwise review.
Capture-time DOM masking
Strict, Balanced (default), and Relaxed modes. Fail-closed by default, with per-element overrides. Masked content is redacted at capture time and never reaches the replay store.
RBAC + audit log
Replay access bound by RBAC: 30 built-in roles plus custom roles. A plain JSONL audit log retains 30 days of access events with purge, who watched what, when.
Visitor analytics
Filter to the segment that matters.
Replay isn’t useful without the segment first. SessionSight ships visitor tracking with deep filtering, country, browser, OS, device, UTM, behavioural signal. Drill from segment to individual replay in one click.
- Deep-filter by country, browser, OS, device, UTM, behavioural signal.
- Replay sessions filtered by journey event signals.
- Drop-off filtering. Replay sessions that left at a specific funnel step.
- Plain JSONL audit log (30-day retention with purge) tracks access events.
Visitor analytics. Filter and drill to replay.
Capability
What ships with enterprise session replay.
DOM-fidelity replay
Two replay modes: screenshot slideshow OR DOM reconstruction. Step through clicks, scrolls, and form interactions in either mode.
Learn moreCapture-time DOM masking
Strict / Balanced (default) / Relaxed modes; fail-closed defaults; per-element overrides. Masked data never reaches the replay store. Privacy review survives.
Learn moreDeployment-controlled data residency
LoadGen ships on four deployment models. LoadGen Appliance (hosted by LoadGen), On-Prem Appliance (ZIP delivery), Docker, and Windows Hosted (customer-managed). Air-gapped / offline operation and proxy-supported deployment are separate capabilities. Pick the path your boundary requires.
Learn moreRBAC-bound access + JSONL audit log
30 built-in roles plus custom roles, with OIDC SSO (group-to-role + JIT). Replay access is audited via a plain JSONL log with 30-day retention and purge.
Learn moreSearch + filter by segment
Filter sessions by country, browser, OS, device, UTM, and behavioural signals from journey analysis. Drill from segment to individual replay.
Learn moreAnalytics & AI surfacing
AI-flagged anomalies and analytics reports surface which sessions are worth watching from the journey-analysis layer.
Learn moreHeatmap context
Heatmaps tell you where. Replay tells you why.
Heatmaps and replay are complementary. Heatmaps surface where users click and scroll in aggregate; replay shows the individual sessions behind the aggregate signal. Both on the same timeline.
- Click and scroll heatmaps with viewport-aware thresholds across desktop, tablet, and mobile.
- Drill from heatmap signal to specific replay sessions.
- Same scrub bar across heatmaps, replay, and synthetic checks.
- Capture-time DOM masking applies to both surfaces uniformly.
Heatmaps. Drill from aggregate signal to individual replay.
Proof
Numbers from the platform.
250M+
Monitoring sessions
across the customer base
8
Products, one platform
testing + monitoring + analytics + service levels
6
Platforms covered
Citrix · AVD · Horizon · RDS · Web · FAT
From €899
Per Agent / month
published, predictable pricing
Where enterprise replay lives
Three regulated-industry workflows.
Incident root-cause investigation
When the helpdesk surge starts, replay shows what the user did before opening the ticket, without exposing sensitive fields. DOM masking redacts at capture time; the JSONL audit log records who watched.
See use caseCompliance-driven DEM
For healthcare, finance, and public-sector estates, capture-time DOM masking + RBAC + a JSONL audit log enable DEM that survives a privacy review. The DEX surface stays usable; the data stays redacted.
See use caseMulti-tenant replay (MSP)
Per-tenant RBAC and the JSONL access audit enable MSPs to operate replay across a customer book with audit-tracked visibility.
See use caseSee enterprise session replay on your stack.
We’ll deploy SessionSight against your application, configure capture-time DOM masking (Strict / Balanced / Relaxed) for sensitive fields, and walk through a replay with full RBAC + audit-log visibility. On a call.
Questions
Frequently asked.
How does DOM masking work?
Capture-time DOM masking redacts sensitive fields before they leave the browser. Three modes are available: Strict, Balanced (default), and Relaxed. Defaults are fail-closed; per-element overrides are configurable. The masked content never enters the replay store.
How fast can I scrub through a replay?
Replay uses a fixed dropdown with eight speed values: 0.25×, 0.5×, 1×, 1.5×, 2×, 4×, 8×, 12×. Two replay modes are available: screenshot slideshow OR DOM reconstruction.
Where is session data stored?
Storage follows the chosen deployment model. LoadGen Appliance (hosted by LoadGen), On-Prem Appliance (ZIP delivery), Docker, or Windows Hosted (customer-managed). Air-gapped / offline operation and proxy-supported deployment are separate, real capabilities you can layer on top.
Who can access replay sessions?
Replay access is RBAC-bound: 30 built-in roles plus custom roles. OIDC SSO with group-to-role mapping and JIT provisioning is supported with any OIDC IdP. A plain JSONL audit log with 30-day retention and purge tracks access events.
Can we replay sessions across Citrix and AVD as well as web?
SessionSight covers the web-app DEM surface, heatmaps, replay, journey analysis, visitor tracking, across applications running inside Citrix or AVD sessions where browser-based interaction is captured. EUC protocol-level recording (HDX, AVD remoting) is a different capability.
How does this compare to standalone replay platforms?
Standalone DEM platforms ship replay as a primary product. SessionSight integrates replay with the same platform that runs synthetic Citrix / AVD checks, plus heatmaps and journey analysis on the same timeline. Privacy controls (capture-time DOM masking + RBAC + JSONL audit log) are first-class.
What does enterprise session replay cost?
SessionSight is a separate module. Quoted on a call as part of the multi-module bundle. End-to-End Monitoring is €899 per Agent per month with annual subscriptions including two months free.
