Guide
Review your first observations
Follow a practical first-session path through providers, resources, relationships, sessions, and findings.
Last reviewed September 12, 2026
This tutorial begins after SiteWall is installed and your test journeys have produced data. You will learn where each core view is located, what its records mean, and what to capture for a deeper review. You do not need to configure policies during this walkthrough.
The review sequence
Use the following table to understand how each area supports the task.
| View | Question to answer |
|---|---|
| Project context | Am I reviewing the correct website, environment, and observation period? |
| Providers | Which third-party services appeared, and how did they enter the website? |
| Inventory | Which individual resources ran, and what did SiteWall observe them doing? |
| Exposure Map | How are pages, providers, resources, destinations, and capabilities connected? |
| Sessions | Which observations occurred together during the journeys I tested? |
| Issues and Anomalies | Which findings require explanation, ownership, or follow-up? |
1. Confirm what you are reviewing
- 1.
Select the project
Use the project selector in the upper-left area of SiteWall. Choose the project associated with the website you just tested.
- 2.
Confirm the website and environment
Check the selected project name and domain. Make sure you are not interpreting staging observations as production activity, or data from another customer or business unit.
- 3.
Anchor the review to your test
Note when the test began and ended, which pages were visited, and which actions were performed. Use that context when comparing last activity, sessions, and findings.
2. Review detected providers
- 1.
Open Providers
In the left navigation, open Providers. This page groups observed resources by the service or organization associated with them.
- 2.
Scan the provider list
Review each provider’s loading type, resource count, last activity, and status. Direct means the website loaded it without another observed third party in between; Indirect means another observed provider or resource introduced it.
- 3.
Open a provider profile
Select a provider you recognize. In About, confirm its described purpose and activity dates. Open Inventory to see its resources, Load Flow to inspect relationships, and Past Incidents to review relevant historical context when available.
- 4.
Record what needs confirmation
Note unfamiliar providers, unexpected indirect relationships, unusually large resource counts, or services whose business owner is unclear. A new or unfamiliar provider is a review prompt—not proof of risk.
3. Inspect individual resources
- 1.
Open Inventory
Select Inventory in the left navigation. Unlike Providers, this view lists the individual client-side resources SiteWall observed.
- 2.
Start with a relevant resource
Use search or filters to narrow the list to a provider, hostname, risk level, category, or status related to your test. Open a resource from a critical journey or a provider you flagged in the previous step.
- 3.
Read the observed behavior
Review the resource name and host, performance information, browser or API access, security score, and status. Treat these fields as observations from captured traffic, not as a complete description of everything the resource could ever do.
- 4.
Capture questions for the owner
Record resources with unexpected destinations, capabilities, execution cost, status, or purpose. Include the resource name, provider, affected page or journey, and observation time so another reviewer can reproduce the context.
4. Trace a relationship in the Exposure Map
- 1.
Open Exposure Map
Select Exposure Map in the left navigation. The map visualizes how the website, providers, resources, network destinations, and browser capabilities relate to one another.
- 2.
Find the provider or resource
Search for an item you reviewed earlier or use the available grouping control to reduce the graph. Start from the website or provider node and follow its connected path.
- 3.
Select a node
Choose a resource or destination to focus its connected relationships. Look for the upstream entity that introduced it and the downstream destinations or capabilities associated with it.
- 4.
Describe the complete path
Write the relationship as a short chain—for example: website → provider → resource → destination. This makes the observation easier to validate with the website or service owner.
5. Compare the sessions you generated
- 1.
Open Sessions
Select Sessions in the left navigation. A session groups activity observed during a browser visit or journey so you can review events in their runtime context.
- 2.
Match a session to the test window
Use the session time, page, and available context to find a visit created during your test. Open it and confirm that the journey matches what you performed.
- 3.
Compare two meaningful states
Review another session from a different page, user state, consent choice, or feature path. Note providers or resources that appear only under one condition.
- 4.
Identify missing coverage
If an expected conditional service does not appear, confirm that the journey actually triggered it. Record untested states rather than assuming that an absent observation means the resource can never load.
6. Triage issues and anomalies
- 1.
Review Issues
Open Issues under Monitoring. Start with records that affect important journeys or have the highest displayed severity. Open a record to understand the affected entity, detected condition, supporting context, and current status.
- 2.
Review Anomalies
Open Anomalies under Monitoring. Look for changes that coincide with your test or a known deployment, such as a newly observed provider, resource, destination, or behavior.
- 3.
Separate signals from conclusions
Determine whether each record is expected, needs technical investigation, or lacks enough context. Do not classify a provider as malicious or block it solely because the observation is new.
- 4.
Assign the next action
For every consequential finding, record an owner and a concrete follow-up: validate the business purpose, compare a deployment, reproduce a journey, inspect the resource, or prepare a reviewed control.
What to record before you finish
Use the following table to understand how each area supports the task.
| Record | Include |
|---|---|
| Expected baseline | Providers and resources that match the journeys you tested. |
| Ownership questions | Unfamiliar entities or purposes and the person responsible for validating them. |
| Important relationships | The page-to-provider-to-resource paths that support critical functionality. |
| Behavior questions | Unexpected capabilities, destinations, performance, or conditional loading. |
| Findings to investigate | Issue or anomaly, supporting context, owner, and next action. |
| Coverage gaps | Pages, user states, consent states, regions, devices, or features not yet tested. |