Skip to main content

Session Explorer

Sessions are the evidence trail for agent work. Reach them from Activity, an agent detail page, alert evidence, or a global search result.

Investigate a session

  1. Confirm the tenant, agent, and time range.
  2. Review the ordered event timeline.
  3. Inspect the relevant event and its linked policy or governance context.
  4. Record the decision, alert, or containment evidence needed for follow-up.
  5. Pivot to the matching agent, policy, or incident when further action is required.

Session views display evidence retained for your tenant. If a session cannot be found, verify the active filters and telemetry path before assuming it was deleted or blocked.