Skip to content
User Guide

Review → Live Session Observe

Administrators can watch an interactive session while it is happening, read-only, and end it if necessary. This is the supervision tool for live access: confirm what an operator is doing on a sensitive system, shadow a colleague during an incident, or cut off a session that should not continue.

The observed session is unaffected by your watching — your keystrokes and clicks are never sent to it.

Reaching the live view

  1. Open Review → Sessions.
  2. Find a session whose status is Active.
  3. Click the live view (cast) icon on its entry.

The page opens as Live View — <resource>, marked Covert · read-only, and begins streaming the session in real time. (The sessions list also offers a direct terminate button on active entries, if ending the session is all you need.)

What you see

  • For shell sessions, a live terminal mirroring exactly what the operator sees as they type.
  • For graphical (RDP / VNC / Web) sessions, a live view of the remote screen, with a LIVE badge that flips to ENDED when the session closes.
  • A banner reminding you the view is read-only: your keystrokes are never sent to this session.
  • If the stream cannot start, an error banner with Back and Retry; once the session is over, a This session has ended. notice.

Terminating a session

If you have permission, a Terminate button appears at the top right:

  1. Click Terminate.
  2. Confirm in the dialog. The operator is shown a notice and disconnected immediately.

The button is shown while the session is live and your session-write permission covers the resource’s current location.

Permissions

  • Observe a live session: app.session.read.
  • Terminate a session: app.session.write.

Read and write scopes are independent: being allowed to watch a session does not automatically allow you to terminate it.