Review → Sessions
Every interactive session opened through MisterShell — SSH, file browsing, AWS / Azure / Kubernetes shells, database shells, RDP / VNC desktops, and web application sessions — is indexed here. When Recording Policy selects Record, shell sessions retain both an authoritative command timeline and terminal output; graphical sessions (RDP / VNC / Web) retain a visual recording. File sessions retain operation metadata without file content. Sessions selected for Skip keep their policy audit evidence but no replay artifact.
What you can do
- Search and filter recorded sessions.
- Replay any completed session: a terminal replay for shells, a visual replay for RDP, VNC, and Web.
- Watch an active session live and read-only (see Live Session Observe).
- Terminate an active session — either from its row here or from the live view.
- Request AI analysis directly from an ended shell session’s row.
- Open the resource where a session happened.
Which sessions are recorded — and to which store and for how long — is set by administrators in Recording Policy, not by the person in the session. A session that matches no recording rule is not recorded.
Filters
All filters apply automatically as you type or pick values. Every filter is optional and they stack.
| Filter | Notes |
|---|---|
| Username | Filters by the email of the user who opened the session. |
| Resource Name | Partial match on the resource’s name. |
| Session ID | Look up one specific session by its identifier. |
| Resource Type | Dropdown of active resource types. |
| Mode | The connection mode (SSH, RDP, database shell, …). |
| Status | Reserved, Dispatched, Active, Completed, Error. |
| Tags | Sessions on resources carrying these tags (shown when you can read tags). |
| From Date / To Date | Limits by session start date. |
The timeline
Sessions are listed on a timeline grouped by day, newest first; more entries load automatically as you scroll. Each entry shows:
- The start time and a status-colored dot.
- Action buttons — live view and terminate on active sessions, replay and eligible AI analysis on ended ones (details below).
- The resource name, linked to the resource’s detail page when it exists and you have resource-read access at its current location.
- A detail line with the session duration, the user’s email, the connection mode, the resource type, and the location — plus a Deleted resource marker when the resource no longer exists.
- A status chip — Reserved (grey), Dispatched (amber), Active (blue), Completed (green), Error (red).
- An end-reason chip on ended sessions, showing the recorded reason value (for example
user_close,idle_timeout,admin_terminated,transport_closed,error).
Reviewing a session
The buttons on a session entry depend on its type and status.
Watch or terminate a live session
While a session is Active, click the live view (cast) icon to open a read-only, real-time view. See Live Session Observe.
With session-write permission covering the resource’s current location, a red terminate (power) button also appears directly on the entry. Confirm the dialog and the operator is shown a notice and disconnected immediately.
Replay a shell session
- Find a completed shell session (SSH, AWS, Azure, Kubernetes, or database).
- Click the Replay icon. (Disabled while a session is still active or if it did not complete.)
- The replay opens with playback controls — play, pause, scrub, and speed (1x–8x). A command drawer lists every command by its stable sequence and labels completed, denied, suppressed, or incomplete commands. Select a timestamped command to jump straight to it. A warning banner appears when the recording is partial. An AI Analysis button summarizes the same indexed command evidence.
Session evidence uses the user, resource, and location values captured when the session opened. Deleting the current user, resource, or Worker definition does not rewrite or remove an authorized recording; unavailable live links are simply shown as deleted. Access remains based on the captured location ancestry and fails closed when the current reader has no matching grant. At the configured retention deadline, Recording Policy removes the shell recording and command timeline together, or the single visual recording for a graphical session.
MisterShell does not delay an interactive command while waiting for the audit broker. Normally the accepted recording events survive Core or Worker failure. A Worker dying can lose its final buffered events, and a sustained audit-broker outage can lose the outage window. Such detected gaps are flagged as partial in the replay rather than reconstructed or presented as complete. During a total loss of connectivity to the audit broker an in-product alert may arrive only after connectivity recovers; external infrastructure monitoring remains necessary.
Replay a graphical (RDP / VNC / Web) session
A completed graphical session offers a visual, video-like replay of the screen with play, pause, scrub, and speed controls. Graphical sessions have no text transcript. Clipboard content is live-only and is never part of the recording. Historical recordings created before the current 1920×1080 live-session limit remain playable at their recorded resolution.
Analyse a shell session
Click the robot icon on a completed or failed shell session to request an AI summary of its command evidence. This action requires access to the session and its current resource. It is unavailable for active sessions, file transfers, graphical sessions, or deleted resources.
Review a file transfer
A completed or failed File transfer session opens as an operation table rather than a terminal replay. Select File transfer in the Mode filter to find these sessions. They use an open-folder icon; interactive sessions use a terminal icon. It shows the time, action, source, destination or details, result, duration, and a bounded error message when an action failed. Use the Action filter to focus on browsing, uploads, downloads, or resource-side changes. A policy-denied transfer is retained as denied without implying that a Worker ran it. The history contains metadata and hashes where available, never transferred file content.
Permissions
- See and replay sessions:
app.session.read. - Observe a live session:
app.session.read; terminate it:app.session.write(see Live Session Observe). - Request AI session analysis:
app.ai.execute,app.resources.read, andapp.session.readcovering the resource’s current location. - Delete sessions: not available through the UI; session retention is managed through the data-retention settings.
Live viewing and termination use the resource’s current location, with read and write permissions checked independently. Retained evidence for deleted resources remains available according to its historical access rules.