Guide
Investigate browser-side changes
Apply focused playbooks to new resources, changed behavior, regressions, and provider incidents.
Last reviewed September 12, 2026
Investigate a newly observed resource
For a newly observed resource, identify its provider and URL, determine how it was loaded, review capabilities and destinations, inspect representative sessions, check issues and anomalies, confirm a business owner and purpose, and only then record an allow, block, or inherited policy decision.
Procedure
- 1.
Open the correct project and page
Use the project selector to choose the website you intend to review, then open Inventory in the left navigation. Confirm the organization, project, and monitored domain before interpreting a record or changing a control.
- 2.
Preserve the original signal
Record the finding link, current status and severity, affected entity, first and last observation, relevant session, and recent deployment context before changing disposition or detection settings.
- 3.
Provider
Confirm the URL or domain, provider association, first and last observation, and the project in which the entity was recorded. Open the linked detail record; a display name or enrichment label is not proof of ownership or approval.
- 4.
Session
Open a representative session and record its page, time, browser context, and observed resources. Use it to establish that the behavior occurred in that captured journey, not that it occurred for every visitor.
- 5.
Decision
Compare the signal with the affected entity, linked session, timing, and expected behavior before setting its disposition.
- 6.
Reproduce and compare
Repeat a representative journey when safe, then compare the new session and source records with the original finding. Verify that the selected disposition describes the reviewed evidence.
- 7.
Record the decision trail
Preserve the original finding, supporting records, expected behavior, owner, disposition, rationale, and follow-up. A workflow-state change must not replace the evidence used to reach it.
Investigate changed browser behavior
When browser behavior changes, compare the current resource identity and version, capabilities, globals, destinations, requests, and linked sessions with the previous known state. Separate a new observation caused by broader traffic coverage from a real behavior change before updating policy or baseline.
Investigate a performance regression
Investigate a performance regression by comparing equivalent pages, browsers, conditions, resources, and time windows. Review load and execution timing, response events, errors, and provider dependencies, then reproduce with and without the suspected resource where your change process permits.
Investigate a provider incident
During a provider incident, open the provider profile, identify active and recently observed resources, review Load Flow and Past Incidents, find linked sessions and findings, and document affected journeys. Use a provider block only when the response owner accepts the functional impact and a recovery path is ready.