Secure Your Front-end

Request a Demo

Join the leading security teams protecting their digital supply chain with CellWall.

By submitting this form, you agree to our privacy policy and terms.

Guide

Review your first observations

Follow a practical first-session path through providers, resources, relationships, sessions, and findings.

Last reviewed September 12, 2026

This tutorial begins after SiteWall is installed and your test journeys have produced data. You will learn where each core view is located, what its records mean, and what to capture for a deeper review. You do not need to configure policies during this walkthrough.

The review sequence

Use the following table to understand how each area supports the task.

ViewQuestion to answer
Project contextAm I reviewing the correct website, environment, and observation period?
ProvidersWhich third-party services appeared, and how did they enter the website?
InventoryWhich individual resources ran, and what did SiteWall observe them doing?
Exposure MapHow are pages, providers, resources, destinations, and capabilities connected?
SessionsWhich observations occurred together during the journeys I tested?
Issues and AnomaliesWhich findings require explanation, ownership, or follow-up?

1. Confirm what you are reviewing

  1. 1.

    Select the project

    Use the project selector in the upper-left area of SiteWall. Choose the project associated with the website you just tested.

  2. 2.

    Confirm the website and environment

    Check the selected project name and domain. Make sure you are not interpreting staging observations as production activity, or data from another customer or business unit.

  3. 3.

    Anchor the review to your test

    Note when the test began and ended, which pages were visited, and which actions were performed. Use that context when comparing last activity, sessions, and findings.

2. Review detected providers

  1. 1.

    Open Providers

    In the left navigation, open Providers. This page groups observed resources by the service or organization associated with them.

  2. 2.

    Scan the provider list

    Review each provider’s loading type, resource count, last activity, and status. Direct means the website loaded it without another observed third party in between; Indirect means another observed provider or resource introduced it.

  3. 3.

    Open a provider profile

    Select a provider you recognize. In About, confirm its described purpose and activity dates. Open Inventory to see its resources, Load Flow to inspect relationships, and Past Incidents to review relevant historical context when available.

  4. 4.

    Record what needs confirmation

    Note unfamiliar providers, unexpected indirect relationships, unusually large resource counts, or services whose business owner is unclear. A new or unfamiliar provider is a review prompt—not proof of risk.

3. Inspect individual resources

  1. 1.

    Open Inventory

    Select Inventory in the left navigation. Unlike Providers, this view lists the individual client-side resources SiteWall observed.

  2. 2.

    Start with a relevant resource

    Use search or filters to narrow the list to a provider, hostname, risk level, category, or status related to your test. Open a resource from a critical journey or a provider you flagged in the previous step.

  3. 3.

    Read the observed behavior

    Review the resource name and host, performance information, browser or API access, security score, and status. Treat these fields as observations from captured traffic, not as a complete description of everything the resource could ever do.

  4. 4.

    Capture questions for the owner

    Record resources with unexpected destinations, capabilities, execution cost, status, or purpose. Include the resource name, provider, affected page or journey, and observation time so another reviewer can reproduce the context.

4. Trace a relationship in the Exposure Map

  1. 1.

    Open Exposure Map

    Select Exposure Map in the left navigation. The map visualizes how the website, providers, resources, network destinations, and browser capabilities relate to one another.

  2. 2.

    Find the provider or resource

    Search for an item you reviewed earlier or use the available grouping control to reduce the graph. Start from the website or provider node and follow its connected path.

  3. 3.

    Select a node

    Choose a resource or destination to focus its connected relationships. Look for the upstream entity that introduced it and the downstream destinations or capabilities associated with it.

  4. 4.

    Describe the complete path

    Write the relationship as a short chain—for example: website → provider → resource → destination. This makes the observation easier to validate with the website or service owner.

5. Compare the sessions you generated

  1. 1.

    Open Sessions

    Select Sessions in the left navigation. A session groups activity observed during a browser visit or journey so you can review events in their runtime context.

  2. 2.

    Match a session to the test window

    Use the session time, page, and available context to find a visit created during your test. Open it and confirm that the journey matches what you performed.

  3. 3.

    Compare two meaningful states

    Review another session from a different page, user state, consent choice, or feature path. Note providers or resources that appear only under one condition.

  4. 4.

    Identify missing coverage

    If an expected conditional service does not appear, confirm that the journey actually triggered it. Record untested states rather than assuming that an absent observation means the resource can never load.

6. Triage issues and anomalies

  1. 1.

    Review Issues

    Open Issues under Monitoring. Start with records that affect important journeys or have the highest displayed severity. Open a record to understand the affected entity, detected condition, supporting context, and current status.

  2. 2.

    Review Anomalies

    Open Anomalies under Monitoring. Look for changes that coincide with your test or a known deployment, such as a newly observed provider, resource, destination, or behavior.

  3. 3.

    Separate signals from conclusions

    Determine whether each record is expected, needs technical investigation, or lacks enough context. Do not classify a provider as malicious or block it solely because the observation is new.

  4. 4.

    Assign the next action

    For every consequential finding, record an owner and a concrete follow-up: validate the business purpose, compare a deployment, reproduce a journey, inspect the resource, or prepare a reviewed control.

What to record before you finish

Use the following table to understand how each area supports the task.

RecordInclude
Expected baselineProviders and resources that match the journeys you tested.
Ownership questionsUnfamiliar entities or purposes and the person responsible for validating them.
Important relationshipsThe page-to-provider-to-resource paths that support critical functionality.
Behavior questionsUnexpected capabilities, destinations, performance, or conditional loading.
Findings to investigateIssue or anomaly, supporting context, owner, and next action.
Coverage gapsPages, user states, consent states, regions, devices, or features not yet tested.
Secure Your Front-end

Request a Demo

Join the leading security teams protecting their digital supply chain with CellWall.

By submitting this form, you agree to our privacy policy and terms.

Review your first observations | SiteWall Docs